Sr. Sec & Compliance Engineer, AWS Security Assurance Services, LLC
Indexed description
Key job responsibilities
- Own design and architecture choices for security and compliance automation solutions for regulated customers and influence partner-org design and deliverables.
- Engineer and lead AI-enabled automations, threat modeling, design reviews.
- Build secure-by-design IaC modules for Landing Zones, Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
- Lead the design, deployment, and implementation of AWS security controls, continuous compliance monitoring, evidence collection, and remediation of insecure configurations to scale with automation.
- Architect custom preventive, detective, and proactive controls, SCPs, RCPs, policy-as-code (cfn-guard, OPA Rego, Cedar).
- Set high bar for authentication and authorization, data protection, least privilege, encryption, micro-segmentation, tagging strategy, integrations via API and MCP, and secure AI agentic design.
- Write and review scripts, and IaC (Python, Terraform, AWS CDK, CloudFormation, Rego).
- Lead exploratory POCs on emerging technologies. Define the hypothesis, success criteria, and go/no-go gates.
- Lead alignment, resolve escalations, troubleshooting, and root-cause analysis to closure
- Lead the development of technical content
- Communicate security risk and design decisions clearly verbally and in writing to technical, non-technical, and C-level audiences.
- Identify and shape sales opportunities. influence service-team roadmaps and SAS offering strategy.
- Travel to customer sites as needed.
Basic Qualifications
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
- Bachelor's degree or above in computer science, engineering, mathematics or equivalent, or experience working in Science, Technology, Engineering, or Mathematics (STEM)
- Experience managing full application stacks from the OS up through custom applications, or experience working with REST API based services and experience with threat modeling and penetration testing
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- 4+ years of cloud architecture and solution implementation experience, or US government security clearance of top secret or above
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with security in service-oriented architectures/microservices and web services
- Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls
- Experience developing, deploying and managing AI products at scale
- Experience in security or compliance consulting or advisory work in support of a highly technical environment
- Experience designing or architecting (design patterns, reliability and scaling) of new and existing systems
- Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST
- Experience with security in service-oriented architectures/microservices and web services
- 8+ years as a technical specialist, including 5+ years in secure coding, software development, cloud security engineering or related work;
- Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or .NET.
- Advanced Infrastructure-as-Code proficiency in Terraform, AWS CDK, and/or CloudFormation.
- Expert-level configuration and architectural experience with AWS security and governance services: Config, GuardDuty, Security Hub, Control Tower, Systems Manager, KMS, IAM, VPC, Lambda, CloudTrail, CloudWatch, EventBridge.
- Track record of deploying SCPs and RCPs in multi-account AWS Organizations at enterprise scale.
- Experience writing and deploying reusable policy-as-code patterns (cfn-guard, OPA Rego, Cedar, or equivalent).
- Industry and AWS certifications: CISSP, GCIH (GIAC Certified Incident Handler), GSEC (GIAC Security Essentials), Security+, AWS Solutions Architect Professional, AWS Security Specialty strongly preferred; additional certifications are a plus.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Company - AWS EMEA SARL (UK Branch)
Job ID: A10455265
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search