Security Engineer, Security for Employee and Legal Systems (SEALS)

Amazon

Seattle (WA)

On-site

USD 159,000 - 202,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Amazon seeks a Security Engineer for the SEALS team to threat model GenAI-backed HR and Legal applications, build secure workflows, and write detection rules. You will embed with builder teams, own security outcomes, and drive risk reduction across the development lifecycle.

Strong candidates will have 3+ years in coding and security, plus experience with AWS, Python/Java/C++, and secure coding practices. This role is based in Seattle, WA, with a mature security-first culture.

Qualifications

  • 3+ years programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar OO language experience.
  • 2+ years scripting, programming, and security code review in a common language (non-internship).
  • 2+ years troubleshooting systems issues, analyzing logs, or automating basic tasks (non-internship).
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP.
  • Experience with AWS products and services.

Responsibilities

  • Own the security outcomes for SEALS builder teams and their HR/Legal apps.
  • Threat model GenAI and LLM-backed apps, covering prompt injection and data leakage.
  • Secure agentic workflows with transitive authentication and scoped authorization.
  • Author and refine automated detection rules for code commits.
  • Use GenAI to scale delivery, including AI-assisted code review and detection writing.
  • Drive secure CDK blueprints and standardized authorizations across domains.
  • Mentor peers and communicate risk clearly to leadership.

Skills

Threat modeling
Secure coding
Secure code review
Python
Java
C++

Education

Bachelor's degree in Computer Science or equivalent
Bachelor's degree in STEM or IT Security

Tools

AWS
Git
Docker
Kubernetes

Job description

The Security for Employee and Legal Systems (SEALS) team protects Amazon's enterprise HR and Legal applications. Millions of Amazonians use these systems to review their pay, manage their benefits, update their personal information, and handle confidential legal matters. Protecting that data is the core of what SEALS does, and the customers who depend on us are the people who work here.

The applications we protect are increasingly built with GenAI, and many of them now embed GenAI features and agentic workflows of their own. That shifts the security work. You will threat model LLM-backed applications, assess risks such as prompt injection, insecure model output handling, and over-broad agent permissions, and secure transitive authentication as agents act on behalf of users. You will also use GenAI to scale your own delivery, from automated code review to detection authoring.

SEALS delivers ambient security. Builders get security feedback while they write code, at commit time, so risks are caught and fixed during development. As a Security Engineer on SEALS, you will be an embedded partner to your builder teams and own the security outcomes for your domain.

Strong candidates bring depth in application security: threat modeling, architecture and design reviews, secure code review, and hands‑on remediation. You will contribute autonomously within the team, deliver risk reduction across the full lifecycle, and mentor peers, while seeking guidance from managers and technical leaders on the hardest tradeoffs.

Key job responsibilities
  • Own the security outcomes for your assigned SEALS builder teams and the HR and Legal applications they run.
  • Threat model GenAI and LLM‑backed applications, covering risks such as prompt injection, insecure output handling, data leakage through model context, and excessive agent authority.
  • Secure agentic workflows, including transitive authentication and scoped authorization as agents act on behalf of users.
  • Author and refine automated detection rules that catch risks at code commit and give builders a fix they can accept immediately.
  • Use GenAI to scale delivery across your domain, including AI‑assisted code review, detection authoring, and triage.
  • Drive paved‑path adoption (Secure CDK Blueprints, automated patching, standardized authorization, transitive authentication for agentic workflows) so preventable issues do not occur.
  • Hunt for risk the tooling missed through adversarial analysis and manual secure code review in Java, Python, and JavaScript, then turn each escape into a new detection.
  • Provide security architecture guidance and lead the security outcomes of design reviews for your team and customers.
  • Prioritize remediation by business impact, and elevate to leadership when a builder wants to accept a launch‑blocking risk.
  • Communicate security outcomes clearly, in writing and verbally, to security and service team leadership.
A day in the life

You are the security engineer your builder teams want in the room. On a given day you might threat model a new LLM feature for an HR application, write a detection rule that closes a gap a production finding revealed, pair with a builder to fix an authorization flaw while the code is fresh, or review the design of an agentic workflow before it ships. You articulate risk clearly to technical and non‑technical audiences, prioritize pragmatically, and guide partners toward secure solutions. You mentor other engineers on the team and raise the bar around you.

About the team

SEALS sits within Corporate Services Security (CPSS), the Amazon security team aligned with Finance & Global Business Services, People eXperience & Technology, Legal, and Global Communications and Community Impact. We engage development teams early so our stakeholders can build and scale securely.

  • - 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • - 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • - 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
  • - Bachelor's degree in computer science or equivalent
  • - Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
  • - Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
  • - Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • - Knowledge of industry-based security vulnerabilities and remediation techniques
  • - Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)
  • - Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)
  • - 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • - 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience
  • - Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
  • - Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
  • - Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP
  • - Experience with AWS products and services
  • - Experience with programming languages such as Python, Java, C++
  • - Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++
  • - Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • - 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • - 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience
  • - Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
  • - Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
  • - Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP
  • - Experience with AWS products and services
  • - Experience with programming languages such as Python, Java, C++
  • - Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Manager, Security Engineering, Corporate Services Security (CPSS)
Sr. Manager, Security Engineering, Corporate Services Security (CPSS)

Amazon • Arlington (VA)

On-site
USD 208,000 - 282,000
Senior Security Engineer, Corporate Services Security
Senior Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 178,400 - 226,700
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, Corporate Services Security
Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, Corporate Services Security
Security Engineer, Corporate Services Security

Socket.dev • Boston (MA)

On-site
USD 159,000 - 202,000
Senior Security Engineer, Corporate Services Security
Senior Security Engineer, Corporate Services Security

JobCubby • Boston (MA), Northern (KY)

Hybrid
USD 178,000 - 227,000
Health insurance
401(k) matching
Paid time off
+1
Application Security Engineer, Leo Proactive Security, Leo Security - METALS
Application Security Engineer, Leo Proactive Security, Leo Security - METALS

Socket.dev • Redmond (WA)

On-site
USD 159,000 - 202,000
Application Security Engineer, Leo Proactive Security, Leo Security - METALS
Application Security Engineer, Leo Proactive Security, Leo Security - METALS

Socket.dev • Redmond (WA)

On-site
USD 159,000 - 202,000
Security Engineer, AppSec, Stores Security
Security Engineer, AppSec, Stores Security

Socket.dev • Seattle (WA)

On-site
USD 136,000 - 184,000
Health insurance
RSUs (restricted stock units)
401(k) matching
+1
Senior Security Engineer, Proactive Security
Senior Security Engineer, Proactive Security

Amazon • Seattle (WA)

On-site
USD 178,000 - 227,000
Security Engineer, Leo Security
Security Engineer, Leo Security

Amazon • Redmond (WA)

On-site
USD 159,000 - 202,000
RSUs
Health insurance
401(k) matching