Senior Security Engineer, Forward Deployed Engineering, AWS Forward Deployed Engineering
AI in this role
Senior Security Engineer embedding with forward-deployed AI engineering teams to secure production AI systems, RAG pipelines, and agentic workflows.
You conduct security reviews, perform threat modeling, build security automation, and ensure every FDE-delivered system meets both AWS and customer security standards. You move at the speed of the FDE team: weeks, not quarters. You don't just flag risks and hand them back. You find the vulnerability, design the fix, and ship the control.
This role combines the depth of a senior application security engineer with the urgency and customer-facing presence of forward-deployed engineering. You secure AI/ML pipelines end-to-end, build reusable security tooling that scales the FDE practice, and operate with a production mindset from day one of deployment.
This position requires that the candidate selected be a US Citizen.
Key job responsibilities
- Conduct security design reviews, threat modeling, and architecture assessments for production AI systems (agentic workflows, RAG pipelines, orchestration layers, model integrations, customer data pipelines)
- Embed with FDE delivery teams in customer environments; assess infrastructure security posture, identify gaps, implement controls while maintaining delivery velocity
- Build security automation and tooling: scanning, testing, monitoring capabilities purpose-built for forward-deployed AI systems; create reusable security accelerators
- Implement controls for AI-specific threats: prompt injection, guardrail bypass, model endpoint hardening, training data protection, output filtering, data isolation
- Integrate security into FDE engineering workflows: CI/CD security gates, secrets management, dependency scanning, container security
- Triage and respond to security incidents in production AI systems; build monitoring and alerting for AI-specific security signals
- Document solutions as reusable patterns, playbooks, and architectural guidance
- Requires up to 25% travel
10047
A day in the life
You start the day reviewing a pull request from an FDE engineer building a multi-agent orchestration system for a healthcare customer, catching an authorization gap before it ships. Mid-morning you're on-site with the customer's security team walking through your threat model for their RAG pipeline. After lunch you're writing a reusable Terraform module that enforces data isolation for multi-tenant AI deployments. You close out the day running automated guardrail tests against a Bedrock-powered application before it goes live. Every week brings a different customer, a different architecture, and a new AI security challenge.
About the team
AWS Forward Deployed Engineering embeds AI engineers directly inside strategic enterprise customers to build production AI systems. AWS invested $1B in this initiative. We move at the speed of the customer: demonstrating ROI in weeks, not quarters. We are customer-obsessed. We lead customers toward outcomes, build together, and leave behind scalable patterns. Security is our enabling function: without it, nothing goes to production. Our culture is people-first, anti-burnout, bold, and engineering-excellence-driven.
ABOUT AWS:
Diverse Experiences
Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why AWS
Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.
Inclusive Team Culture
AWS values curiosity and connection. Our employee-led and company-sponsored affinity groups promote inclusion and empower our people to take pride in what makes us unique. Our inclusion events foster stronger, more collaborative teams. Our continual innovation is fueled by the bold ideas, fresh perspectives, and passionate voices our teams bring to everything we do.
Mentorship and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
Basic qualifications
- 5+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
- Experience with threat modeling and penetration testing, or experience that includes strong analytical skills, attention to detail, and effective communication abilities
Preferred qualifications
- Experience with security in service-oriented architectures/microservices and web services
- US government security clearance of top secret or above, or 7+ years of IT platform implementation in a technical and analytical role experience
- Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST
- Experience with AWS technologies
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, Mountain View - 183,000.00 - 247,600.00 USD annually
USA, MA, Boston - 178,400.00 - 226,700.00 USD annually
USA, NY, New York - 175,100.00 - 236,900.00 USD annually
USA, TX, Dallas - 178,400.00 - 226,700.00 USD annually
USA, VA, Arlington - 178,400.00 - 226,700.00 USD annually
USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually
How we rate this
Senior Security Engineer, Forward Deployed Engineering, AWS Forward Deployed Engineering at Amazon rates 70 out of 100 for how much of the daily work is AI. That makes it Works on AI (AI Level 3 of 4). The level is about AI in the job, not seniority.
Works on AI. The daily work is on AI products, without building the model.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- How would you design a retrieval step so the model answers from real data instead of guessing?
- How do you decide when an AI agent can act on its own versus asking for approval first?
- Tell me about a project where security engineering was part of your work. What did you do?
- Tell me about a project where threat modeling was part of your work. What did you do?
- Tell me about a project where ai security was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: RAG, AI Agents, Security Engineering, Threat Modeling, and AI Security. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
- Show where AI is part of your daily process, not a one-off project — this role expects it to be a running habit.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new forward deployed engineer jobs (Works on AI ●●●○ or higher) by email
One email a week with the new forward deployed engineer jobs (Works on AI ●●●○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that work on AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step