Level

Amazon

Sr. Security Engineer, Field Innovation, Security Search and Observability (SSO)

AI in this role

Build and operate AI-powered cloud security capabilities, detection systems, and agent-driven vulnerability management at AWS.

aws-security-hubaws-cloudtrailaws-guarddutyllmsrag
rag
The Field Innovation team is a Forward Deployed Engineering (FDE) group inside the AWS Security, Search, Observability, and Governance service team. We work directly with customers to build next-generation security capabilities that help the world's largest enterprises get faster return on value from security, search, observability, and governance services.

We are hiring a Senior Security Engineer to work at the intersection of customer impact and AI. Our team builds and operates the detection, correlation, and vulnerability-management capabilities behind security services such as AWS Security Hub, AWS CloudTrail, and AWS GuardDuty, as well as our newest AI-powered offering, AWS Continuum, which manages the full lifecycle of code vulnerabilities at machine speed. You'll work with customers to understand how they operate, then partner with service teams to design and ship commercial-grade security products powered by modern AI, including large language models, AI-assisted development tools, security agents, and emerging frameworks. Your code ships to real customers, and your architectural decisions will shape how Fortune 500 companies operate.

The Opportunity

Your impact here will be immediate and visible. You'll ship features that directly change how customers run their businesses, and you'll see the impact of your work in weeks, not years. The team is small enough that your decisions carry real weight and large enough that you'll always have someone to learn from.

This is a dual-facing role. On the field side, you'll work directly with customers to implement the latest features of our security services, leading threat-modeling sessions, performing vulnerability assessments with security agents, and guiding remediation. On the partner side, you'll work with leading third-party security providers to identify their highest-signal findings and turn them into correlated, high-fidelity detections. Across both, you'll design and implement detection content, reduce false positives at scale, and expand coverage across cloud resources, runtime, and AI/ML workloads. Everything you learn in the field feeds back into the product.
AI is not a side experiment on this team. It's a core part of the stack. You'll build with large language models, AI-assisted development tools, security agents, agent frameworks, and retrieval-augmented generation as everyday engineering primitives.


Key job responsibilities
• Run early-access and gated previews of our newest AI-powered capabilities with customers, including threat modeling, vulnerability assessment using security agents, and remediation guidance.
• Work backwards from customers to shape detection coverage and influence service roadmaps, feeding field and partner insights back to science and engineering teams.
• Drive detection engineering best practices, including security-value evaluation, false-positive reduction, and coverage measurement.
• Stay current with the evolving cloud security and threat landscape, including emerging threats targeting agentic AI and ML applications.
• Collaborate across science, engineering, partner, and field teams, operating with flexible hours to support global customers and distributed stakeholders.

Basic qualifications

- 5+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 5+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
- Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques
- Experience as a mentor, tech lead or leading an engineering team
- Bachelor's degree in Computer Science or a related field

Preferred qualifications

- 5+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience
- Experience architecting, securing, and operating Amazon Web Services
- Experience in the full secure software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations
- Experience working in a customer-facing role

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.



USA, CA, Santa Clara - 183,000.00 - 247,600.00 USD annually
USA, TX, Austin - 178,400.00 - 226,700.00 USD annually
USA, VA, Arlington - 178,400.00 - 226,700.00 USD annually
USA, WA, Bellevue - 178,400.00 - 226,700.00 USD annually
USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually

How we rate this

Sr. Security Engineer, Field Innovation, Security Search and Observability (SSO) at Amazon rates 85 out of 100 for how much of the daily work is AI. That makes it Builds AI (AI Level 4 of 4). The level is about AI in the job, not seniority.

Classification

Builds AI. The job is building AI systems.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

RAGAWS Security HubAWS CloudtrailAWS GuarddutyLLMs

Questions you could be asked

  1. How would you design a retrieval step so the model answers from real data instead of guessing?
  2. Walk me through how you've used AWS Security Hub in your day-to-day work.
  3. What are the limits of AWS Cloudtrail that you've run into, and how did you work around them?
  4. What's a project where you used AWS Guardduty hands-on?
  5. Walk me through how you've used LLMs in your day-to-day work.

Adapt your resume

  • List these exact terms on your resume: RAG, AWS Security Hub, AWS Cloudtrail, AWS Guardduty, and LLMs. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
  • Lead with what you built, trained or shipped — this role is judged on the AI system itself, not the tools around it.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new remote AI jobs (Builds AI ●●●●) by email

One email a week with the new remote AI jobs (Builds AI ●●●●), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that build AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Amazon

Related searches

Same AI level