amazon

amazon

Posted via Amazon Jobs

Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Posted Aug 3, 2026

Role at a glance

Job function
Software Engineering & IT Cybersecurity
Salary
Not Disclosed
Location
Herndon, Virginia, United States Austin, Texas, United States
Work arrangement
On-site
Employment
Internship
Education
Bachelor's

Spotted an issue?

We’ll check it against the original posting.

Log in to report

Role Summary

AI-generated

The role supports customer engagements by reviewing security designs and architectures and identifying risks across systems and applications. It builds security controls, compliance monitoring, and remediation capabilities for AWS environments and related workloads.

What You'll Do

  • Lead threat modeling, security design, and architecture reviews for customer engagements.
  • Design and implement preventive, detective, and proactive controls, including policy-as-code and automated remediation workflows.
  • Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures,...
  • Develop continuous compliance monitoring, evidence collection, reporting, and remediation pipelines.
  • Integrate custom controls with AWS-native and third-party security and compliance tooling, and prototype ideas for security and...

Generated from the employer's posting. Verify important details before applying.

View full posting

Qualifications

Required

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)
  • • Demonstrated ability to write and review code, scripts, IaC, and detections in support of security defenses.
  • • Demonstrated ability to lead security investigations and resolve root causes of operational and security issues.

Preferred

  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • • 5+ years as a technical specialist, including 3+ years in secure coding, software development, cloud security engineering, or related work
  • • Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or .NET.
  • • Hands-on Infrastructure-as-Code skills in Terraform, AWS CDK, or CloudFormation.
  • • Hands-on experience with AWS security and governance services: Config, Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch/EventBridge.
  • • Experience deploying SCPs and RCPs in multi-account AWS Organizations.
  • • Experience writing and deploying policy-as-code (cfn-guard, OPA Rego, Cedar, or equivalent).
  • • Experience with AWS Control Tower customizations, Landing Zones, or Zero-Trust architectures.

Original job description

Content provided by the employer

AWS Applied AI Solutions (AAIS) is building toward a future where every business innovates with Amazon AI teammates. To get there, we build AI solutions that improve human capabilities and transform entire business functions. We create end-to-end products that surprise and delight out-of-the-box, making complex things easy and hard things possible, with no cloud experience required. We start with customers who embrace the future and build bridges to meet the rest where they are. We pursue ambitious opportunities with conviction, and we are looking for builders who share that mindset.

Key Responsibilities

• Lead threat modeling security design reviews and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.
• Design and implement custom preventive detective and proactive controls - Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard OPA Rego Cedar) and automated remediation workflows.
• Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
• Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration.
• Write and review IaC scripts enforcements and detections in Python Terraform AWS CDK CloudFormation and Rego.
• Build continuous compliance monitoring automated evidence collection visualization reporting and remediation pipelines that hold up in audit.
• Integrate custom controls with AWS-native and third-party security and compliance tooling.
• Drive emerging-edge ideas into prototyping end-to-end to inform new security and compliance solutions and products.
• Identify risks and edge cases; propose implementation paths and go/no-go gates.
• Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn't possible.
• Help develop technical content
• Identify cross-team patterns gaps improvements.
• Travel to customer sites as needed.

About the team
Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve in the cloud.

Here at AWS, it's in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity and AmazeCon conferences, inspire us to never stop embracing our uniqueness.

We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.

Basic Qualifications

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)
- • Demonstrated ability to write and review code, scripts, IaC, and detections in support of security defenses.
- • Demonstrated ability to lead security investigations and resolve root causes of operational and security issues.

Preferred Qualifications

- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- • 5+ years as a technical specialist, including 3+ years in secure coding, software development, cloud security engineering, or related work
- • Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or .NET.
- • Hands-on Infrastructure-as-Code skills in Terraform, AWS CDK, or CloudFormation.
- • Hands-on experience with AWS security and governance services: Config, Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch/EventBridge.
- • Experience deploying SCPs and RCPs in multi-account AWS Organizations.
- • Experience writing and deploying policy-as-code (cfn-guard, OPA Rego, Cedar, or equivalent).
- • Experience with AWS Control Tower customizations, Landing Zones, or Zero-Trust architectures.
- • Working knowledge of at least one compliance framework: SOC2, HIPAA, PCI-DSS, CIS, or NIST.
- • Experience producing audit-ready evidence and working with third-party assessors.
- • Spec-driven development; AI agentic design and Model Context Protocol (MCP) experience.
- • Industry and AWS certifications: AWS Solutions Architect Associate or Professional, AWS Security Specialty, CISSP, or equivalent.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.



USA, TN, Nashville - 137,600.00 - 184,000.00 USD annually
USA, TX, Austin - 159,300.00 - 202,400.00 USD annually
USA, TX, Dallas - 159,300.00 - 202,400.00 USD annually
USA, TX, Houston - 159,300.00 - 202,400.00 USD annually
USA, VA, Arlington - 159,300.00 - 202,400.00 USD annually
USA, VA, Herndon - 159,300.00 - 202,400.00 USD annually
USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually
amazon

About the company

amazon

Large Enterprise

Amazon is a global leader in e-commerce and cloud computing, founded in 1994 by Jeff Bezos. Initially starting as an online bookstore, it has since expanded its offerings to include a vast range of products and services, including electronics, fashion, and digital content. With Amazon Web Services (AWS), the company also provides powerful cloud solutions to businesses around the world. Known for its innovation, customer-centric approach, and commitment to operational efficiency, Amazon continues to shape the future of retail and technology, consistently seeking new ways to enhance customer experiences.