Amazon

Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon$159K — $202K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years programming experience in Python, Ruby, Go, Swift, Java, .Net, C++ or similar
  • 2+ years of security code review and scripting in a common programming language
  • 2+ years of troubleshooting systems and analyzing logs using command line tools
  • Bachelor's degree in a STEM field or relevant IT Security experience
  • Knowledge of networking protocols like HTTP, DNS, and TCP/IP
  • Experience in threat modeling, penetration testing, and security remediation techniques
  • Proven ability to mentor peers and lead security investigations

Responsibilities

  • Lead threat modeling and security design reviews to mitigate risks
  • Design and implement security controls like SCPs and policy-as-code
  • Build secure Infrastructure-as-Code controls for various AWS architectures
  • Apply AWS security best practices in authentication, encryption, and data handling
  • Develop continuous compliance monitoring and automated remediation pipelines
  • Integrate custom security controls with AWS and third-party tools
  • Drive prototyping of new security solutions and products

Benefits

  • Comprehensive health insurance including medical, dental, and vision
  • 401(k) matching and flexible spending accounts
  • Paid time off and parental leave
  • Adoption and surrogacy reimbursement coverage
  • Employee assistance program and mental health support
Full Job Description
AWS Security Assurance Services (SAS) is hiring a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solutions for highly regulated customers. You will own engineering deliverables across the full lifecycle - secure design, implementation, testing, deployment, and maintenance - translating compliance frameworks (SOC2, HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work autonomously within your team, deliver cross-functional projects with partner teams, and drive measurable risk reduction for customers at scale.

You'll write code, ship custom controls, run security investigations, lead design and code reviews on your team, and mentor junior engineers. You will identify systemic issues, propose pragmatic solutions, and improve the team's mechanisms over time.

Key job responsibilities

- Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.

- Design and implement custom preventive, detective, and proactive controls - Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard, OPA Rego, Cedar), and automated remediation workflows.

- Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.

- Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration.

- Write and review IaC, scripts, enforcements and detections in Python, Terraform, AWS CDK, CloudFormation, and Rego.

- Build continuous compliance monitoring, automated evidence collection, visualization, reporting, and remediation pipelines that hold up in audit.

- Integrate custom controls with AWS-native and third-party security and compliance tooling.

- Drive emerging-edge ideas into prototyping end-to-end to inform new security and compliance solutions and products.

- Identify risks and edge cases; propose implementation paths and go/no-go gates.

- Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn't possible.

- Help develop technical content

- Identify cross-team patterns, gaps, improvements.

- Travel to customer sites as needed.

About the team

The AWS Security Assurance Services team, within AWS Support, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world's workloads requires reliable delivery of bar-raising security outcomes and investment in security mechanisms and automation on behalf of our customers.

AWS Security Assurance Services LLC, a PCI-QSAC and HITRUST External Assessor Firm, is a team of industry-certified assessors and Compliance Engineers with DevOps and Cloud Infrastructure Architect backgrounds, helping our customers achieve, maintain, and automate compliance in the cloud by tying applicable audit standards to AWS service-specific features and functionality. The SAS team works with our largest enterprise customers to operationalize the shared responsibility model as they migrate to the cloud.

BASIC QUALIFICATIONS

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience

- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience

- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience

- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security

- Knowledge of networking protocols such as HTTP, DNS and TCP/IP

- Knowledge of industry-based security vulnerabilities and remediation techniques

- Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)

- 2+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience

- Experience with threat modeling and penetration testing, or experience that includes strong analytical skills, attention to detail, and effective communication abilities

- Experience conveying complex technical concepts to both technical and business audiences

- Experience in any combination of the following: application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development

- • Demonstrated ability to write and review code, scripts, IaC, and detections in support of security defenses.

- • Demonstrated ability to lead security investigations and resolve root causes of operational and security issues.

- • Demonstrated ability to mentor peers, drive consensus on conflicting design or implementation feedback, and provide meaningful review feedback.

PREFERRED QUALIFICATIONS

- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience

- Experience with AWS products and services

- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing

- Experience in supporting audit defense

- Experience in mentoring, leading, or managing more junior engineers

- Experience writing technical articles, speaking at technology conferences, and contributing to open source

- • 5+ years as a technical specialist, including 3+ years in secure coding, software development, cloud security engineering, or related work

- • Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or .NET.

- • Hands-on Infrastructure-as-Code skills in Terraform, AWS CDK, or CloudFormation.

- • Hands-on experience with AWS security and governance services: Config, Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch/EventBridge.

- • Experience deploying SCPs and RCPs in multi-account AWS Organizations.

- • Experience writing and deploying policy-as-code (cfn-guard, OPA Rego, Cedar, or equivalent).

- • Experience designing CI/CD pipelines for security or compliance control deployment.

- • Experience with AWS Control Tower customizations, Landing Zones, or Zero-Trust architectures.

- • Working knowledge of at least one compliance framework: SOC2, HIPAA, PCI-DSS, CIS, or NIST.

- • Spec-driven development; AI agentic design and Model Context Protocol (MCP) experience.

- • Industry and AWS certifications: AWS Solutions Architect Associate or Professional, AWS Security Specialty, CISSP, or equivalent.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, TN, Nashville - 137,600.00 - 184,000.00 USD annually

USA, TX, Austin - 159,300.00 - 202,400.00 USD annually

USA, TX, Dallas - 159,300.00 - 202,400.00 USD annually

USA, TX, Houston - 159,300.00 - 202,400.00 USD annually

USA, VA, Arlington - 159,300.00 - 202,400.00 USD annually

USA, VA, Herndon - 159,300.00 - 202,400.00 USD annually

USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually

About Amazon

Audible is a provider of spoken audio information and entertainment , on the Internet. They provide premium spoken audio content, such as audio versions of books and newspapers and radio programs, that is delivered over the Internet and played back on personal computers and hand-held electronic devices. The Audible service allows consumers to purchase and download their content from their Website, store it in digital files and play it back on personal computers and electronic devices. More than 15,000 hours of audio content are available on their Web site, including audio versions of books, periodicals and radio programs. Several manufacturers have agreed to support and promote the playback of their content on their hand-held audio-enabled electronic devices.

Amazon Careers

Joining Amazon presents an unparalleled opportunity to become part of a vibrant team pushing the boundaries of innovation and growth in the global marketplace. As a leader in e-commerce, technology, and logistics, Amazon offers a variety of job opportunities that cater to a range of skills and professional interests. Work You’ll Do At Amazon, every day is an opportunity to collaborate with the brightest minds in technology and business to redefine what’s possible. Whether you’re interested in software development, marketing, human resources, or customer service, Amazon has a position waiting for you. Transform the way the world shops and innovates with our diverse and inclusive team. Amazon is not just a company; it’s a community where you can drive real change and contribute to projects impacting millions globally. Lead with Innovation and Leadership Amazon is the perfect place to enhance your leadership and innovation skills. Our culture encourages pushing the envelope and imagining the unimaginable. Here, you will lead projects that challenge the status quo and define new industry standards. Work with a team that values diversity and is committed to creating an inclusive environment. Our leadership is focused on harnessing the collective power of unique perspectives to foster growth and innovation. Explore Amazon’s Employment Benefits Amazon’s commitment to its employees extends beyond just career growth. We offer competitive benefits, including health care, parental leave, and diversity training, ensuring that our team not only excels professionally but also enjoys well-being and security. Internship and Networking Opportunities Start your career with an Amazon internship and gain hands-on experience that matters. Our internships provide a gateway to full-time employment and an opportunity to network with professionals across various sectors of the company. Future-Proof Your Career With Amazon, your career path is filled with numerous opportunities for advancement. Our learning and development programs are designed to nurture your professional growth and keep you at the forefront of industry trends. Stay Connected Join Our Team Discover the job opportunities at Amazon that match your skills and interests. We are constantly on the lookout for passionate, curious, and innovative team players ready to make a difference. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding career opportunities that await at Amazon. Amazon is more than just a company—it’s a platform for building a promising future. Whether you’re starting or looking to advance your career, Amazon offers the resources, support, and network you need to succeed. Join us, and be a part of our continuing mission to be Earth's most customer-centric company.
Learn more about Amazon
Size
1,608 employees
Market Cap
$832.6 billion
Industry
Net Income
$21.3 billion
Founded
1994
5 Year Trend
+28.1%
Revenue
$386 billion
NASDAQ

Similar Jobs

More Jobs at Amazon

More Information Technology Jobs

Find similar Security & Compliance Engineer II, AWS Security Assurance Services, LLC jobs: