Amazon
Posted 5d ago

Sr Security Engineer, Leo Security

Amazon
Seattle, Washington, United States
$178k-$227k/yrOnsiteFull Time
Responsibilities
  • modeling threats
  • testing defenses
  • designing controls
Requirements
  • Requires security experience in threat modeling
  • Secure coding
  • Identity management
  • Software development
  • Cryptography
  • Systems or network security, AWS
  • Troubleshooting
  • Scripting
  • Penetration testing, or red teaming
Technical tools mentioned
Amazon Web ServicesPythonJavaC++

Job description

Description

Amazon Leo is a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world.

We are looking for a senior security engineer to join the founding cohort of the Engineering and R\&D team within Leo Infrastructure and IP Security. The team defends the manufacturing lines, launch sites, and global ground infrastructure behind the constellation from the most sophisticated threat actors on the planet. The team builds a neurosymbolic reasoning platform: large language model agents combined with a knowledge graph and real-time asset state store that ground every conclusion in verifiable fact, so every automated decision is auditable. You will be the security owner for that platform. A system that can triage security events, execute containment, and act on physical security is itself a high-value target, and this role exists so the team that secures Leo does not ship its own unowned risk. This is a hands-on role for a technical contributor with deep expertise in offensive security who understands how to use AI on both sides: directing agents to test Leo's defenses the way an adversary would, and hardening the platform's own agents against the same techniques.

#### Export Control Requirement

Due to applicable export control laws and regulations, candidates must be a U.S. citizen.


Key job responsibilities
You will be the single accountable security owner for every system the team builds and operates, from the agent platform and detection pipeline to the data plane and self-service workflows. You will lead threat modeling and secure-design review on each system before it takes autonomous action, thinking like an adversary to find the weaknesses in agent tool access, prompt and data injection paths, and containment authority before someone else does. You will design the privileged-access and insider-risk controls for systems that hold the keys to Leo physical security: the who-watches-the-watchers guarantee. You will translate threat intelligence into the adversary behaviors that drive the team's models and detections, partnering with applied scientists on what to detect and with software engineers on how the platform defends itself. You will use AI to scale both offense and defense: directing the platform's agents to run offensive validation against Leo's infrastructure and against the platform itself, and turning what the offense finds into detections, guardrails, and controls. You will drive every finding, whether from your own testing, penetration tests, or red-team engagements, to closure, with security gates built into the team's own delivery cadence rather than bolted on after.


A day in the life
One morning you might threat model a new agent capability before it graduates to automated execution, mapping what an adversary could do with its tools and where its authority must be constrained. That afternoon you could be red-teaming the platform's reasoning layer, crafting inputs that try to steer an agent into an action it should refuse. The next day you might take fresh threat intelligence, distill it into the adversary behaviors the scientists should model next, then review the access boundaries and audit evidence on a new data source before it is ingested. You will communicate security posture, risks, and strategic priorities to senior leadership with clarity and precision. You will question every trust relationship the platform depends on, hold the security bar steady against delivery pressure, and treat the team's own systems with the same adversarial rigor the team applies to everything else.


About the team
Leo Infrastructure and IP Security protects the people, facilities, hardware, and supply chain behind a global satellite constellation. The Engineering and R\&D team within this organization builds the platforms and tooling the security pillar teams operate on, moving security operations from manual triage to correlation-based detection, automated response, and agentic AI. The team is composed of applied scientists, software engineers, and security engineers working across physical and digital security domains.

#### Inclusive Team Culture

In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

#### Training & Career Growth

We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

#### Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.

Basic Qualifications

- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience in progressive work within a software security team or related operating environment
- Experience architecting, securing, and operating Amazon Web Services
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 5+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience
- - 5+ years of non-internship experience in troubleshooting systems issues, analyzing logs, automating complex tasks using command line tools, and identifying security issues, risks, and developing mitigation plans
- - Experience with offensive security, including penetration testing, red teaming, or adversarial testing of production systems

Preferred Qualifications

- Experience conveying complex technical concepts to both technical and business audiences
- - Understanding of threat actor tradecraft and ability to emulate sophisticated attack techniques
- - Experience with AI/ML security, including threats to AI systems, adversarial machine learning, prompt injection, or AI supply chain security
- - Experience applying AI to security work, including agentic tooling for offensive testing, detection engineering, or automated response
- - Experience with Red Team operations, threat-based assessments, or security research programs
- - Track record of building security tools or automation that scales across organizations
- - Experience designing privileged-access and insider-risk controls for high-consequence systems
- - Experience with security in regulated or export-controlled environments, including data-handling boundaries and audit evidence
- - Experience translating threat intelligence into detections, adversary emulation, or threat hunting
- - Contributions to security research community through publications, presentations, or open-source tools

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.



USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually

About Amazon

Global online retail and cloud computing technology provider.

Similar jobs

Security Engineer roles near Seattle, Washington
13h
Save
Mark Applied
Hide
Security Engineer II, Hybrid Cloud Guidelines
Seattle or Kirkland or San Jose or New York City
$123k-$174k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
1+ YOEBachelor's degree or equivalent experience, 1+ year coding in a general-purpose language, 1+ year in security assessments, design reviews, or threat modeling, and security engineering experience.
Terraform, Google Cloud Platform (GCP), VPC service controls (VPC-SC), IAM, AI assistants
1d
Save
Mark Applied
Hide
Security Engineer - Incident response
Seattle or Poland
$132k-$198k/yr HybridFull Time
F5
F5NASDAQ: FFIV: Provides application delivery networking and multi-cloud security solutions.
5+ YOERequires 5+ years of cybersecurity experience, hands-on incident response, cloud and customer-facing environment expertise, modern attack knowledge, technical communication, and cross-functional coordination skills.
F5 BIG-IP, NGINX, Distributed Cloud, WAAP, API, DDoS, Kubernetes, AWS, CrowdStrike, EDR, SIEM, WAF, DLP, NIST, ISO, SOC, PCI, GDPR
2d
Save
Mark Applied
Hide
Lead Security Engineer - Confidential Computing
Plano or Seattle or Seattle
$157k-$215k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOERequires security engineering training or certification, 5+ years applied experience, 3+ years designing Confidential Computing with Azure, GCP, or AWS, programming expertise, SDLC, agile security, testing, and threat modeling.
Azure, GCP, AWS, CI/CD, Software Development Life Cycle (SDLC)
1w
Save
Mark Applied
Hide
Security Engineer
Bellevue, Washington, United States
OnsiteFull Time
Golden Analytics
Golden Analytics: AI-native business intelligence platform for interactive data analysis.
3+ YOERequires 3+ years in security detection and remediation, security-focused product roles, full-stack development, AI technologies, and securing customer-facing products.
Vite, Node, TypeScript, React, Postgres, Vercel, Supabase
1w
Save
Mark Applied
Hide
Senior Security Engineer, AI Incident Response
Menlo Park or Bellevue
$176k-$253k/yr HybridFull Time
Snowflake
SnowflakeNYSE: SNOW: Cloud-based platform for data storage, processing, and analytics.
5+ YOE5+ years in information security, incident response, security or product/application engineering; AI/ML security experience; cloud knowledge; SQL and Python; bachelor's degree or equivalent experience.
Cortex AI, Cortex Agents, Snowflake Intelligence, Snowpark ML, Cortex Search, AWS, Azure, GCP, SQL, Python, CI/CD, RAG
1w
Save
Mark Applied
Hide
Senior Security Engineer, RTOS and Virtualization
Santa Clara or Austin or Hillsboro or United States or Redmond
$184k-$357k/yr RemoteFull Time
NVIDIA
NVIDIANASDAQ: NVDA: Designs GPU-accelerated computing and artificial intelligence hardware.
8+ YOE8+ years in systems, embedded, platform, product, or automotive security; BSEE/BSCS or equivalent; RTOS or privileged software security; strong C/C++; threat modeling, fuzzing, vulnerability analysis, and automotive security standards.
C, C++, RTOS, Hypervisor, Rust, Ada, SPARK, MMU, SMMU, IOMMU, DMA, ISO/SAE 21434, UN R155, ISO 26262, Automotive SPICE
1w
Save
Mark Applied
Hide
Senior Security Engineer, RTOS and Virtualization
Santa Clara or Austin or Hillsboro or United States or Redmond
$184k-$357k/yr RemoteFull Time
NVIDIA
NVIDIANASDAQ: NVDA: Designs graphics processing units and artificial intelligence hardware.
8+ YOE8+ years in systems, embedded, platform, product, or automotive security; bachelor's in electrical engineering or computer science; C/C++; RTOS, hypervisor, kernel, firmware, or privileged software security experience.
C, C++, RTOS, Hypervisor, CPU, SoC, MMU, SMMU, IOMMU, DMA, Rust, Ada/SPARK, ISO/SAE 21434, UN R155, ISO 26262, Automotive SPICE
2w
Save
Mark Applied
Hide
Senior Security Engineer
Seattle, Washington, United States
OnsiteFull Time
Apple
AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Partners with engineering teams to secure complex services and platforms through threat modeling, security guidance, and collaboration across security, privacy, and offensive security teams.