Security Engineer: GenAI Risk & HR/Legal Apps

Amazon

Arlington (VA)

On-site

USD 159,000 - 202,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Amazon seeks a Security Engineer for the SEALS team to own security outcomes for HR and Legal applications used by millions of Amazonians. You will threat model GenAI/LLM-backed apps, implement automated detection rules, and secure agentic workflows as supporters to development teams.

You will work hands-on with code reviews, security design, and risk remediation across Java, Python, and JavaScript, mentoring peers and driving cross-functional risk reduction.

Qualifications

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience.
  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience.
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience.
  • Bachelor's degree in computer science or equivalent
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Knowledge of industry-based security vulnerabilities and remediation techniques
  • Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)
  • Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)

Responsibilities

  • Own the security outcomes for your assigned SEALS builder teams and the HR and Legal applications they run.
  • Threat model GenAI and LLM-backed applications, covering risks such as prompt injection, insecure output handling, data leakage through model context, and excessive agent authority.
  • Secure agentic workflows, including transitive authentication and scoped authorization as agents act on behalf of users.
  • Author and refine automated detection rules that catch risks at code commit and give builders a fix they can accept immediately.
  • Use GenAI to scale delivery across your domain, including AI-assisted code review, detection authoring, and triage.
  • Drive paved-path adoption (Secure CDK Blueprints, automated patching, standardized authorization, transitive authentication for agentic workflows) so preventable issues do not occur.
  • Hunt for risk the tooling missed through adversarial analysis and manual secure code review in Java, Python, and JavaScript, then turn each escape into a new detection.
  • Provide security architecture guidance and lead the security outcomes of design reviews for your team and customers.
  • Prioritize remediation by business impact, and elevate to leadership when a builder wants to accept a launch-blocking risk.
  • Coach peers through peer review, training, and outreach, and drive cross-functional risk reduction that spans partner teams.
  • Communicate security outcomes clearly, in writing and verbally, to security and service team leadership.

Skills

Python
Java
C++
Go
Swift
Ruby
DotNet
Security code review
Troubleshooting

Education

Bachelor's degree in Computer Science
Bachelor's degree in STEM field

Tools

AWS

Job description

Amazon seeks a Security Engineer for the SEALS team to own security outcomes for HR and Legal applications used by millions of Amazonians. You will threat model GenAI/LLM-backed apps, implement automated detection rules, and secure agentic workflows as supporters to development teams.

You will work hands-on with code reviews, security design, and risk remediation across Java, Python, and JavaScript, mentoring peers and driving cross-functional risk reduction.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer: GenAI for HR & Legal Apps
Security Engineer: GenAI for HR & Legal Apps

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Senior Security Engineering Leader for GenAI & HR/Legal
Senior Security Engineering Leader for GenAI & HR/Legal

Amazon • Arlington (VA)

On-site
USD 208,000 - 282,000
Security Engineer, Security for Employee and Legal Systems (SEALS)
Security Engineer, Security for Employee and Legal Systems (SEALS)

Amazon • Arlington (VA)

On-site
USD 159,000 - 202,000
Security Engineer, Security for Employee and Legal Systems (SEALS)
Security Engineer, Security for Employee and Legal Systems (SEALS)

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
GenAI Security Engineer, App and Architecture
GenAI Security Engineer, App and Architecture

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Sr. Manager, Security Engineering, Corporate Services Security (CPSS)
Sr. Manager, Security Engineering, Corporate Services Security (CPSS)

Socket.dev • Arlington (VA), Northern (KY)

Hybrid
USD 208,000 - 282,000
Health insurance
RSUs
401(k) matching
+1
Sr. Manager, Security Engineering, Corporate Services Security (CPSS)
Sr. Manager, Security Engineering, Corporate Services Security (CPSS)

Amazon • Arlington (VA)

On-site
USD 208,000 - 282,000
GenAI & App Security Engineer
GenAI & App Security Engineer

Amazon • Boston (MA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, Corporate Services Security
Security Engineer, Corporate Services Security

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Senior Security Engineer: AI-Driven Threat Modeling & Automation
Senior Security Engineer: AI-Driven Threat Modeling & Automation

Amazon • Boston (MA)

On-site
USD 178,400 - 226,700
Health insurance
401(k) matching
Paid time off
+1