AWS Forward Deployed Engineering (FDE) embeds AI engineers directly inside strategic enterprise customers to design, build, and deploy production-grade AI systems. We are looking for a Senior Security Engineer to embed with FDE delivery teams and own the security posture of production AI systems deployed in customer environments.
You conduct security reviews, perform threat modeling, build security automation, and ensure every FDE-delivered system meets both AWS and customer security standards. You move at the speed of the FDE team: weeks, not quarters. You don't just flag risks and hand them back. You find the vulnerability, design the fix, and ship the control.
This role combines the depth of a senior application security engineer with the urgency and customer-facing presence of forward-deployed engineering. You secure AI/ML pipelines end-to-end, build reusable security tooling that scales the FDE practice, and operate with a production mindset from day one of deployment.
This position requires that the candidate selected be a US Citizen.
Key job responsibilities
- Conduct security design reviews, threat modeling, and architecture assessments for production AI systems (agentic workflows, RAG pipelines, orchestration layers, model integrations, customer data pipelines)
- Embed with FDE delivery teams in customer environments; assess infrastructure security posture, identify gaps, implement controls while maintaining delivery velocity
- Build security automation and tooling: scanning, testing, monitoring capabilities purpose-built for forward-deployed AI systems; create reusable security accelerators
- Implement controls for AI-specific threats: prompt injection, guardrail bypass, model endpoint hardening, training data protection, output filtering, data isolation
- Integrate security into FDE engineering workflows: CI/CD security gates, secrets management, dependency scanning, container security
- Triage and respond to security incidents in production AI systems; build monitoring and alerting for AI-specific security signals
- Document solutions as reusable patterns, playbooks, and architectural guidance
- Requires up to 25% travel
10047
A day in the life
You start the day reviewing a pull request from an FDE engineer building a multi-agent orchestration system for a healthcare customer, catching an authorization gap before it ships. Mid-morning you're on-site with the customer's security team walking through your threat model for their RAG pipeline. After lunch you're writing a reusable Terraform module that enforces data isolation for multi-tenant AI deployments. You close out the day running automated guardrail tests against a Bedrock-powered application before it goes live. Every week brings a different customer, a different architecture, and a new AI security challenge.
BASIC QUALIFICATIONS
- 5+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
- Experience with threat modeling and penetration testing, or experience that includes strong analytical skills, attention to detail, and effective communication abilities
PREFERRED QUALIFICATIONS
- Experience with security in service-oriented architectures/microservices and web services
- US government security clearance of top secret or above, or 7+ years of IT platform implementation in a technical and analytical role experience
- Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST
- Experience with AWS technologies
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, Mountain View - 183,000.00 - 247,600.00 USD annually
USA, MA, Boston - 178,400.00 - 226,700.00 USD annually
USA, NY, New York - 175,100.00 - 236,900.00 USD annually
USA, TX, Dallas - 178,400.00 - 226,700.00 USD annually
USA, VA, Arlington - 178,400.00 - 226,700.00 USD annually
USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually