823,562open jobs
53,068companies
134,459added this week
Browse all
Salary
≈ $90k – $178k per year (Estimated)
Location
In office (United Kingdom)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 17, 2026.

Overview
Company
Impact
Profile match
Amazon is an American technology and retail conglomerate founded by Jeff Bezos in 1994 as an online bookstore and headquartered in Seattle, Washington. It operates the world's largest online marketplace together with a global logistics network, physical grocery stores and a third-party seller platform that accounts for most units sold. Amazon Web Services, launched in 2006, is the leading public cloud provider and generates the majority of the group's operating profit, while advertising, Prime Video, Alexa devices and Kuiper satellite broadband round out the business.

We are looking for a Senior Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will be a technical leader on a team, owning complex security testing engagements end-to-end, applying human judgment where it changes security outcomes and building automation for everything else.

Amazon Web Services (AWS) is the leading cloud service provider, providing virtualized infrastructure, storage, networking, messaging, and many other services to customers all over the world, including government customers. AWS runs a globally distributed environment operating at massive scale, and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the security engagements where the architecture, threat model, or potential impact is complex enough that expert reasoning matters most. We start from the architecture and the risks rather than a generic checklist, think like an adversary, and demonstrate realistic impact. We build harnesses that steer agentic AI so experts have more time for the difficult problems, and we turn what we learn into shared methods, mechanisms, and detections for the rest of the team. As AWS ships agentic systems of its own, those same systems become targets we test.

Our work is measured by how much difficult security uncertainty we resolve with the human time available to us, not by how many issues we find. In this role you will investigate high-consequence risks, which are specific, testable claims about how an adversary could cause harm, and take each one to a documented conclusion. You will either demonstrate the issue, rule out the attack path with enough evidence, or expose a weakness in a shared mechanism or detection.

You must produce results in the face of ambiguity and imperfect knowledge, foster constructive dialogue, and drive resolution when faced with disagreement. You work efficiently and routinely deliver the right things with limited guidance. You take a long-term view of the team's methods and tooling, proactively fix architectural and mechanism deficiencies, and propose larger project scopes that you can split into parallel work for yourself and others and reassemble successfully.

Amazon's Leadership Principles of "Dive Deep", "Earn Trust", "Deliver Results", and "Invent and Simplify" will be called upon daily. Above all, we earn trust by choosing carefully where humans spend time, testing those areas deeply, and being honest about what we know and what we do not.

Key job responsibilities

- Own security for a portfolio of testing engagements across your team and partner-orgs, as well as leading individual complex engagements. Set the testing strategy across interconnected microservice architectures, successive launch iterations, and cross-service campaigns, and decide where to spend expert effort across the whole service portfolio.

- Perform penetration testing and AI-augmented source code review of complex proprietary AWS software, directing the tooling at trust boundaries, abuse cases, and attack paths it would not reach on its own, confirming what it reports, and setting the methodology your team follows when they do the same.

- Take each agreed risk hypothesis to a documented conclusion, whether that means demonstrating the issue with proof-of-concept code, ruling out the attack path with sufficient evidence, or identifying a weakness in a shared mechanism or detection that affects services beyond the one under test.

- Take on engagements where the customer case is understood but no security strategy exists yet, bring clarity to the ambiguity, and define the approach others will reuse. Challenge what a scope document assumes and identify what it misses, then keep the engagement moving when conditions change by building alternative test paths, re-scoping, and parallelizing work with dependent teams.

- Trace attack paths across chained components and demonstrate compound risk that stays invisible when components are tested in isolation, including risk that crosses organizational and ownership boundaries.

- Produce clear engagement results that record what you tested, why you chose those tests, what you found or ruled out, the limitations of the work, and the risk that remains, and write for non-engineering audiences in your domain when the decision sits with them.

- Lead communication with developers, AppSec engineers, and other stakeholders when the scope is ambiguous or a fix is not straightforward, validate the fixes, work as an embedded security tester inside the development lifecycle when a launch calls for it, and lead escalations to closure with Senior Managers and Principal Engineers when a fix or a risk decision stalls.

- Build the frameworks, runbooks, and rubrics that let the whole team test a new problem domain repeatably, not only automation for a single harness. Tune the harnesses that raise the precision of the team's AI tooling, measure where they produce false positives or miss attack patterns, and generalize what works into a mechanism the team adopts.

- Leave reusable mechanisms behind, such as fuzzers, integration security tests, detection rules, tooling, or documented methodology, track their adoption, and where the work depends on teams with their own priorities, build the mechanisms that get security outcomes prioritized and tracked to delivery.

- Set the peer-review bar for the team. Review test plans, scopes, runbooks, and reports from peers and other teams, question coverage gaps, add the missing test cases, and ensure the work fits into the bigger picture and stays extensible and low-cost to adopt.

- Lead multi-engineer engagements and mentor multiple engineers across your own and related teams, are sought out for your expertise, and participate in promotion assessments.

About the team

Why AWS Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience across cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Point-in-Time Security Testing sits within Proactive Security. While the wider organization builds the ability to find risk through signals, automation, AI, Bug Bounty, and continuous testing, our role is different. We take on the situations where expert reasoning matters most, and we make that expertise go further every year. Our vision is that every critical AWS launch receives the right depth of expert security testing, and every hour our team spends makes future testing more effective.

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed, we encourage you to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Inclusive Team Culture

In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to keep learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We're continuously raising our performance bar as we strive to become Earth's Best Employer. You'll find endless knowledge-sharing, mentorship, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture.

Basic qualifications

- Experience developing software code in one or more programming languages (java, python, etc.)

- Knowledge of information security technologies such as security design review, threat modeling, risk analysis, and software testing techniques

- Knowledge of security technology and concepts (Authentication, Authorization, Single sign-on, Cryptography, etc.)

- Experience in risk assessment and enabling organizations to make security decisions

- Experience working with operations and business teams to communicate problem impacts and understand business requirements

- Experience in enterprise software

- Bachelor's degree or above in Computer Science, Computer Engineering, Cybersecurity, or other related discipline

- 5+ years in professional penetration testing, source code auditing, bug hunting, or competitive CTF

- Demonstrated ability to find non-trivial vulnerabilities through offensive testing of web applications and services and through source code review

- Demonstrated mastery of two or more genuinely complex security domains such as networking, workload and tenant isolation, web application and API security, IAM, or cryptography, deep enough to find issues others miss and to encode that expertise into automation

- Experience building and steering AI agents to do useful security work, and reasoning about how those same agentic systems can be attacked

Preferred qualifications

- Experience building agentic AI harnesses, orchestrating agents through graphs or swarms, and working with agent-to-agent (A2A) protocols and the security properties of tool use, memory, and model context

- Experience assessing the security of LLM-based or agentic applications, including prompt injection, tool and plugin abuse, and trust boundaries between agents

- Experience performing or supporting Red Team engagements, with an understanding of holistic assessment

- Web service assessment experience across authentication controls, session management, access controls, logic flaws, injection vulnerabilities, request smuggling, cloud privilege escalation, and tenant isolation

- Experience with serverless architectures and common virtualization techniques (hypervisors, containers, jails), including escapes and exploits within those environments

- Experience with micro-service, API-based, or service-oriented architectures

- Experience with full-stack Linux or Unix software architectures from UI to infrastructure

- Operations experience with CI/CD or managing distributed systems

- Experience designing and implementing technical security controls at the business-division level

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy_page) to know more about how we collect, use and transfer the personal data of our candidates.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
823,562 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
United Kingdom
≈ $20k – $45k per year (Estimated) • In office • Full-Time • Manila
AI/ML
Copilot
DevOps
Splunk
Azure
Cybersecurity
SIEM
Apply
Penetration Tester 2 days ago
≈ $17k – $45k per year (Estimated) • In office • Full-Time • Manila
AI/ML
Copilot
Red Teaming
DevOps
Windows Server
Windows
Cybersecurity
Metasploit
Nmap
Impacket
BloodHound
Mimikatz
Responder
Active Directory
OWASP
Apply
≈ $81k – $168k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Houston
DevOps
TCP/IP
Cybersecurity
Defense in Depth
SIEM
Apply
≈ $110k – $239k per year (Estimated) • Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Chicago
DevOps
GCP
Azure
CI/CD
AWS
IAM
Linux
Windows
Cybersecurity
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Least Privilege
Microsoft Defender for Cloud
Microsoft Entra ID
Ping Identity
Active Directory
SIEM
DLP
OWASP
Apply
$50k – $59k per year • Remote (Portugal) • Full-Time • Lisbon
Python
DevOps
Splunk
Windows
Cybersecurity
IBM QRadar
SIEM
Apply
$104k – $166k per year • In office • TS/SCI • 2+ years exp • Bachelor's Degree • Laurel
Python
JavaScript
Ruby
C++
Perl
Databases
HBase
ElasticSearch
OpenSearch
AI/ML
Hadoop
AI Agents
LLM
RAG
Agentic Workflows
Machine Learning
DevOps
Terraform
CloudFormation
CI/CD
AWS
Kubernetes
Linux
Management
Agile
Apply
$146k – $234k per year • In office • TS/SCI • 1+ year exp • Bachelor's Degree • Laurel
Python
Java
Ruby
Bash
Perl
Databases
ElasticSearch
AI/ML
Hadoop
AI Agents
LLM
RAG
Machine Learning
DevOps
Puppet
Logstash
HAProxy
AWS
Docker
Kubernetes
Nginx
Grafana
Configuration Management
Linux
DNS
DHCP
Apache HTTP Server
Cybersecurity
LDAP
Cryptography
OpenSSL
Management
Agile
Apply
$104k – $166k per year • Hybrid • Top Secret • 8+ years exp • Bachelor's Degree • United States
Python
PowerShell
C#
C#
.NET
Databases
Databricks
AI/ML
AWS Bedrock
DevOps
Terraform
CloudFormation
Azure
CI/CD
AWS
AWS Fargate
AWS Lambda
Amazon EC2
FinOps
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
API Gateway
VPN
Cybersecurity
NIST 800-53
NIST 800-171
FedRAMP
Microsoft Entra ID
Apply
$146k – $234k per year • In office • TS/SCI • 5+ years exp • Bachelor's Degree • Laurel
Python
Java
Ruby
C++
Perl
Databases
HBase
ElasticSearch
OpenSearch
AI/ML
Hadoop
AI Agents
LLM
RAG
Agentic Workflows
Machine Learning
DevOps
Terraform
Red Hat
CloudFormation
CI/CD
AWS
Kubernetes
Linux
Unix
Management
Agile
Apply
$176k – $282k per year • In office • TS/SCI • 8+ years exp • Bachelor's Degree • Laurel
Python
Java
Ruby
Perl
AI/ML
RAG
DevOps
Terraform
CloudFormation
CI/CD
AWS
Kubernetes
Linux
Management
Agile
Scrum
Apply
$178k – $227k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Seattle
Python
Java
C++
Scala
DevOps
AWS
Wi-Fi
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$159k – $202k per year • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Seattle
Python
Java
C++
DevOps
AWS
TCP/IP
DNS
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$159k – $202k per year • Equity • Hybrid • 3+ years exp • Bachelor's Degree • New York
Python
Go
Java
C++
AI/ML
LLM
DevOps
AWS
TCP/IP
DNS
Cybersecurity
OWASP Top 10
PCI DSS
GDPR
OWASP ASVS
Threat Modeling
OWASP
Apply
$250k – $338k per year • Equity • Hybrid • 15+ years exp • Bachelor's Degree • Herndon
Apply
≈ $95k – $213k per year (Estimated) • In office • Full-Time • 7+ years exp • Sydney
DevOps
AWS
Apply
≈ $83k – $163k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • United Kingdom
DevOps
GCP
Linux
Unix
Apply
≈ $92k – $187k per year (Estimated) • In office • Bachelor's Degree • United Kingdom
Python
DevOps
CI/CD
Jenkins
Git
Linux
Management
Jira
Apply
Training Coordinator 10 hours ago
≈ $69k – $182k per year (Estimated) • In office • United Kingdom
Apply
Product Designer 11 hours ago
Hybrid • Full-Time • 2+ years exp • United Kingdom
Mobile
Lottie
Design
Figma
Adobe After Effects
Rive
Apply
In office • 5+ years exp • Bachelor's Degree • United Kingdom
Analytics
Microsoft Excel
Apply
See all jobs
This is one of many
823,562 more open roles from verified company boards, updated every day.