Senior Security Engineer, AI Application Security, Leo Security
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
Requirements
- "we're integrating a third-party ai tool-what are the security, privacy, compliance and export control implications?"
- "we need to deploy an agentic system that invokes mcp tools-how do we define autonomy boundaries and prevent prompt injection?"
- "what's the right way to scope iam permissions for a bedrock inference endpoint with cross-partition data access?"
- "we've experienced an ai-related incident and need to perform root cause analysis to identify what security controls failed."
- "we want to build ai-powered security tooling (e.g., automated threat modeling, code scanning)-how do we do this securely?"
Additional Information
Amazon Leo is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world. Have you wanted an opportunity to secure an advanced satellite broadband telecom service? The Leo Security team owns the security of product and operations of Leo end-to-end. We provide the necessary infrastructure and mechanisms to ensure the security of our satellite constellation and to protect the integrity and confidentiality of our customer data. Our team drives the research & development, deployment and operation of several mission-critical security systems and mechanisms. You will work in a start-up like environment, backed by Amazon's infrastructure to bootstrap security mechanisms, and help instill the security culture in the organization. Export Control Requirement Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. Key job responsibilities Serve as the organization's AI security subject matter expert. Drive AI tool approval reviews, lead security reviews for AI-integrated systems, and make policy decisions on AI adoption. Represent security in cross-Amazon AI security working groups and drive cross-team alignment on AI policy direction. Mentor and backstop AI leads across teams on AI consultations and reviews. Define and drive implementation of proactive security controls for AI applications including GenAI-powered tools, agentic systems, and LLM-integrated services. Guide teams towards solutions that are secure by default; if secure-by-default solutions don't exist, invent and propose them. Develop and implement security controls for the AI software development lifecycle, ensuring builders build secure AI applications by default. Assess and drive mitigation of AI-specific security risks including prompt injection, model abuse, data exfiltration, unauthorized tool invocation, and autonomy boundary violations at scale. Establish environment-specific security bar, threat models, and defense priorities for AI systems. Construct security frameworks, rubrics, and runbooks for AI-related problem domains that enable others to apply your work in a repeatable way. Collaborate with builder teams to assess technical debt and risk in AI systems. Provide strategic direction that addresses vulnerabilities and fortifies our products. Lead the burn down of long-term AI security risk. Drive adoption of AI security guardrails, testing frameworks, and monitoring across the organization. Collaborate with business leaders to define AI security priorities. Support leaders by acting as a trusted advisor and providing direction that makes security easy. Help leaders measure their org's security execution. Work with builder teams to understand their build processes and ensure they use appropriate security linting, static analysis, and AI-specific testing tools. Instill a security culture in builder teams. Mentor builders who aspire to become security advocates and security engineers via 1-1 sessions and office hours. Assist Red Teams in identifying AI security testing priorities. Scope penetration tests for AI systems and help deep-dive on these engagements. Support security incident investigations related to AI systems, including prompt injection attacks, model misuse, and data exfiltration attempts. Investigate emerging AI security issues, root cause them, and devise mechanisms to prevent them. Propose a security vision for AI that delivers security and protects our customers. Leverage support from automation teams that find discoverable vulnerabilities. Advocate for the creation and deployment of new testing tools and detection mechanisms. And last of all-hack some really cool bleeding edge tech! A day in the life In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like: - "We're integrating a third-party AI tool-what are the security, privacy, compliance and export control implications?" - "We need to deploy an agentic system that invokes MCP tools-how do we define autonomy boundaries and prevent prompt injection?" - "What's the right way to scope IAM permissions for a Bedrock inference endpoint with cross-partition data access?" - "We've experienced an AI-related incident and need to perform root cause analysis to identify what security controls failed." - "We want to build AI-powered security tooling (e.g., automated threat modeling, code scanning)-how do we do this securely?" When you're not working on responding to the questions of your builder teams, you will be evalua
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at Amazon.com Services LLC? Share your experience