Stand out for this role — generate a tailored resume and cover letter in about a minute.
Amazon Leo security team seeks a skilled security engineer to own the design, testing, and operation of the Leo platform. You will model threats, review secure designs, and implement guardrails to deter adversaries across the agent, detection, and data-plane layers.
You will drive findings to closure through the delivery cadence and partner with scientists and engineers to harden the system. As part of a leading security organization, you will work with cutting-edge AI, threat intelligence, and
Amazon Leo is a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world.
Amazon Leo is a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world.
Due to applicable export control laws and regulations, candidates must be a U.S. citizen.
You will be the single accountable security owner for every system the team builds and operates, from the agent platform and detection pipeline to the data plane and self-service workflows. You will lead threat modeling and secure-design review on each system before it takes autonomous action, thinking like an adversary to find the weaknesses in agent tool access, prompt and data injection paths, and containment authority before someone else does. You will design the privileged-access and insider-risk controls for systems that hold the keys to Leo physical security: the who-watches-the-watchers guarantee. You will translate threat intelligence into the adversary behaviors that drive the team's models and detections, partnering with applied scientists on what to detect and with software engineers on how the platform defends itself. You will use AI to scale both offense and defense: directing the platform's agents to run offensive validation against Leo's infrastructure and against the platform itself, and turning what the offense finds into detections, guardrails, and controls. You will drive every finding, whether from your own testing, penetration tests, or red-team engagements, to closure, with security gates built into the team's own delivery cadence rather than bolted on after.
One morning you might threat model a new agent capability before it graduates to automated execution, mapping what an adversary could do with its tools and where its authority must be constrained. That afternoon you could be red-teaming the platform's reasoning layer, crafting inputs that try to steer an agent into an action it should refuse. The next day you might take fresh threat intelligence, distill it into the adversary behaviors the scientists should model next, then review the access boundaries and audit evidence on a new data source before it is ingested. You will communicate security posture, risks, and strategic priorities to senior leadership with clarity and precision. You will question every trust relationship the platform depends on, hold the security bar steady against delivery pressure, and treat the team's own systems with the same adversarial rigor the team applies to everything else.
Leo Infrastructure and IP Security protects the people, facilities, hardware, and supply chain behind a global satellite constellation. The Engineering and R&D team within this organization builds the platforms and tooling the security pillar teams operate on, moving security operations from manual triage to correlation-based detection, automated response, and agentic AI. The team is composed of applied scientists, software engineers, and security engineers working across physical and digital security domains.
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, VA, Arlington - 178,400.00 - 226,700.00 USD annually
USA, VA, Herndon - 178,400.00 - 226,700.00 USD annually
USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually
Amazon.com Services LLC - A57
Job ID: A10502692