About this role
Salary: £60,000 - 110,000 per year
Requirements: Experience developing software code in one or more programming languages, such as Java or PythonKnowledge of information security technologies, including security design review, threat modeling, risk analysis, and software testing techniquesKnowledge of security technologies and concepts, including authentication, authorization, single sign-on, and cryptographyExperience in risk assessment and enabling organizations to make security decisionsExperience working with operations and business teams to communicate problem impacts and understand business requirementsExperience in enterprise softwareBachelors degree or above in Computer Science, Computer Engineering, Cybersecurity, or a related discipline5+ years of professional penetration testing, source code auditing, bug hunting, or competitive CTF experienceDemonstrated ability to find non-trivial vulnerabilities through offensive testing of web applications and services and source code reviewDemonstrated mastery of at least two complex security domains, such as networking, workload and tenant isolation, web application and API security, IAM, or cryptography, with the depth to find issues others miss and encode that expertise into automationExperience building and steering AI agents for security work and reasoning about how agentic systems can be attackedPreferred: Experience building agentic AI harnesses, orchestrating agents through graphs or swarms, and working with agent-to-agent (A2A) protocols and the security properties of tool use, memory, and model contextPreferred: Experience assessing LLM-based or agentic application security, including prompt injection, tool and plugin abuse, and trust boundaries between agentsPreferred: Experience performing or supporting Red Team engagements and understanding holistic assessmentPreferred: Web service assessment experience across authentication controls, session management, access controls, logic flaws, injection vulnerabilities, request smuggling, cloud privilege escalation, and tenant isolationPreferred: Experience with serverless architectures and virtualization techniques such as hypervisors, containers, and jails, including escapes and exploits in those environmentsPreferred: Experience with microservice, API-based, or service-oriented architecturesPreferred: Experience with full-stack Linux or Unix software architectures, from UI to infrastructurePreferred: Operations experience with CI/CD or managing distributed systemsPreferred: Experience designing and implementing technical security controls at the business-division level Responsibilities: Own security for a portfolio of testing engagements across the team and partner organizations, and lead complex engagements individuallySet testing strategy across interconnected microservice architectures, successive launch iterations, and cross-service campaigns; prioritize expert effort across the service portfolioConduct penetration testing and AI-augmented source code review of complex proprietary AWS software, focusing tools on trust boundaries, abuse cases, and attack paths, validating reported findings, and setting team methodologyTake each agreed risk hypothesis to a documented conclusion by demonstrating the issue, ruling out the attack path with sufficient evidence, or identifying weaknesses in shared mechanisms or detectionsClarify ambiguous engagements where no security strategy exists, define reusable approaches, challenge scope assumptions, and adapt through alternative test paths, rescoping, and parallel work with dependent teamsTrace attack paths across chained components and demonstrate compound risks, including those crossing organizational and ownership boundariesProduce clear engagement results documenting tests, rationale, findings or conclusions, limitations, and remaining risks; communicate effectively with non-engineering audiences when they make relevant decisionsLead communication with developers, AppSec engineers, and other stakeholders; validate fixes, embed security testing in development when needed, and drive stalled fixes or risk decisions to closure with senior leaders and principal engineersBuild frameworks, runbooks, and rubrics for repeatable testing of new problem domains; tune AI tooling harnesses, measure false positives and missed attack patterns, and generalize effective approaches into team mechanismsCreate reusable mechanisms such as fuzzers, integration security tests, detection rules, tooling, and documented methodology; track adoption and help ensure security outcomes are prioritized and deliveredSet the teams peer-review bar by reviewing test plans, scopes, runbooks, and reports; identify coverage gaps, add missing test cases, and ensure work is extensible and economical to adoptLead multi-engineer engagements, mentor engineers across teams, serve as a sought-out expert, and participate in promotion assessments Technologies: Agentic AIAIAI AgentsAPIAWSCI/CDCloudCryptographyIAMJavaLLMLinuxPythonSecurityServerlessUnixWebUX UI DesignEmbeddedSupportREST More:
We are hiring a Senior Security Engineer for Point-in-Time Security Testing, AWSs expert security assurance function for complex launches and architectures where automation alone is not enough. AWS provides cloud services to customers worldwide, including government customers, and operates a globally distributed environment at massive scale. Our team works within Proactive Security, focusing expert reasoning on high-consequence security risks and turning findings into shared methods, mechanisms, and detections. We aim to ensure critical AWS launches receive appropriate expert testing and that each teams effort makes future testing more effective. At Amazon, security is central to customer trust, and our security organization works across products and services. We offer opportunities to gain experience across cloud, devices, retail, entertainment, healthcare, operations, and physical stores, along with knowledge-sharing, mentorship, training, and career-development resources. We value diverse experiences and perspectives, inclusive team culture, and work-life harmony.
last updated 40 week of 2026