Full Job Description
How do you help every AWS customer understand who can access what, and why, across billions of resource configurations? That's the challenge at the core of this role.
As a Software Development Manager on the AWS IAM Access Analyzer team, you'll lead a team building the next-generation internal access analysis platform that evaluates IAM policies at massive scale to surface security findings for AWS customers. Your systems power automated reasoning about permissions, resource configurations, and access patterns, helping customers identify overly permissive access and unused credentials before they become security incidents.
This is a deeply technical team operating at the intersection of distributed systems, automated reasoning, and cloud security. The ideal candidate sets a high engineering bar, drives operational excellence across tier-0 infrastructure, and works backwards from customer needs to deliver meaningful security outcomes. If you're passionate about building systems that make the cloud more secure by default, this is the role for you.
Key job responsibilities
- Define and execute the product and architecture strategy for large-scale access analysis, including finding generation, resource configuration ingestion, and cost estimation
- Drive customer-facing impact by working backwards from enterprise customer needs (financial services, large tech companies) to simplify how they discover and remediate security risks
- Own system reliability, scalability, and operational metrics for services that process billions of policy evaluations across AWS accounts
- Build and maintain integrations with internal platforms (Trellis, EventBridge, Config) to expand coverage and deliver findings to customers through multiple channels
- Proactively identify risks, mitigate them before they become roadblocks, and exercise sound judgment on when and how to escalate to senior leadership
- Set team strategy and be accountable for team plans, execution, and deliverables, ensuring consistent, high-quality outcomes
- Collaborate cross-functionally with product management, solutions architects, and AWS service teams to align on priorities and drive adoption
- Leverage AI tooling to improve engineering productivity, automate workflows, and raise the bar on operational efficiency
- Grow and develop a strong, healthy, and diverse team through strategic hiring, mentoring, and coaching
About the team
The Citadel team sits within AWS Identity and Access Management (IAM), building the next-generation internal access analysis platform. We help AWS customers continuously evaluate their IAM policies and resource configurations to identify overly permissive access, unused credentials, and potential security risks at scale. Our work combines distributed systems engineering with automated reasoning to deliver security insights that protect millions of AWS accounts. We value strong ownership, operational rigor, and a culture of working backwards from customer outcomes.
BASIC QUALIFICATIONS
- 3+ years of engineering team management experience
- 7+ years of working directly within engineering teams experience
- 3+ years of designing or architecting (design patterns, reliability and scaling) of new and existing systems experience
- 8+ years of leading the definition and development of multi tier web services experience
- Knowledge of engineering practices and patterns for the full software/hardware/networks development life cycle, including coding standards, code reviews, source control management, build processes, testing, certification, and livesite operations
- Experience partnering with product or program management teams
PREFERRED QUALIFICATIONS
- Experience in communicating with users, other technical teams, and senior leadership to collect requirements, describe software product features, technical designs, and product strategy
- Experience in recruiting, hiring, mentoring/coaching and managing teams of Software Engineers to improve their skills, and make them more effective, product software engineers
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, Santa Clara - 212,700.00 - 287,700.00 USD annually