Security Engineer, Field Innovation, Security Search and Observability (SSO)
AI in this role
Design and ship AI-powered commercial security products and work directly with customers on security solutions.
We are hiring a Senior Security Engineer to work at the intersection of customer impact and AI. Our team builds and operates the detection, correlation, and vulnerability-management capabilities behind security services such as AWS Security Hub, AWS CloudTrail, and AWS GuardDuty, as well as our newest AI-powered offering, AWS Continuum, which manages the full lifecycle of code vulnerabilities at machine speed. You'll work with customers to understand how they operate, then partner with service teams to design and ship commercial-grade security products powered by modern AI, including large language models, AI-assisted development tools, security agents, and emerging frameworks. Your code ships to real customers, and your architectural decisions will shape how Fortune 500 companies operate.
The Opportunity
Your impact here will be immediate and visible. You'll ship features that directly change how customers run their businesses, and you'll see the impact of your work in weeks, not years. The team is small enough that your decisions carry real weight and large enough that you'll always have someone to learn from.
This is a dual-facing role. On the field side, you'll work directly with customers to implement the latest features of our security services, leading threat-modeling sessions, performing vulnerability assessments with security agents, and guiding remediation. On the partner side, you'll work with leading third-party security providers to identify their highest-signal findings and turn them into correlated, high-fidelity detections. Across both, you'll design and implement detection content, reduce false positives at scale, and expand coverage across cloud resources, runtime, and AI/ML workloads. Everything you learn in the field feeds back into the product.
AI is not a side experiment on this team. It's a core part of the stack. You'll build with large language models, AI-assisted development tools, security agents, agent frameworks, and retrieval-augmented generation as everyday engineering primitives.
Key job responsibilities
• Run early-access and gated previews of our newest AI-powered capabilities with customers, including threat modeling, vulnerability assessment using security agents, and remediation guidance.
• Work backwards from customers to shape detection coverage and influence service roadmaps, feeding field and partner insights back to science and engineering teams.
• Drive detection engineering best practices, including security-value evaluation, false-positive reduction, and coverage measurement.
• Stay current with the evolving cloud security and threat landscape, including emerging threats targeting agentic AI and ML applications.
• Collaborate across science, engineering, partner, and field teams, operating with flexible hours to support global customers and distributed stakeholders.
Basic qualifications
- 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- 3+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 3+ years of IT Security experience
- Knowledge of industry-based security vulnerabilities and remediation techniques
- Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)
- Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)
Preferred qualifications
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience with AWS products and services
- Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++
- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
- Experience working in a customer-facing role
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, Santa Clara - 166,600.00 - 212,800.00 USD annually
USA, TX, Austin - 159,300.00 - 202,400.00 USD annually
USA, VA, Arlington - 159,300.00 - 202,400.00 USD annually
USA, WA, Bellevue - 159,300.00 - 202,400.00 USD annually
USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually
How we rate this
Security Engineer, Field Innovation, Security Search and Observability (SSO) at Amazon rates 75 out of 100 for how much of the daily work is AI. That makes it Works on AI (AI Level 3 of 4). The level is about AI in the job, not seniority.
Works on AI. The daily work is on AI products, without building the model.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- How would you design a retrieval step so the model answers from real data instead of guessing?
- Tell me about a project where security engineering was part of your work. What did you do?
- Tell me about a project where artificial intelligence was part of your work. What did you do?
- Tell me about a project where threat modeling was part of your work. What did you do?
- Tell me about a project where vulnerability management was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: RAG, Security Engineering, Artificial Intelligence, Threat Modeling, and Vulnerability Management. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
- Show where AI is part of your daily process, not a one-off project — this role expects it to be a running habit.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new AI jobs (Works on AI ●●●○ or higher) by email
One email a week with the new AI jobs (Works on AI ●●●○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that work on AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step