Security & Compliance Engineer II, AWS Security Assurance Services, LLC
About the role
Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across systems and applications. Design and implement custom preventive, detective, and proactive controls — Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard, OPA Rego, Cedar), and automated remediation workflows. Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads. Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration. Write and review IaC, scripts, enforcements and detections in Python, Terraform, AWS CDK, CloudFormation, and Rego. Build continuous compliance monitoring, automated evidence collection, visualization, reporting, and remediation pipelines that hold up in audit. Integrate custom controls with AWS-native and third-party security and compliance tooling. Drive emerging-edge ideas into prototyping end-to-to end to inform new security and compliance solutions and products. Identify risks and edge cases; propose implementation paths and go/no-go gates. Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn’t possible. Help develop technical content Identify cross-team patterns, gaps, improvements.
Responsibilities
- Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.
- Design and implement custom preventive, detective, and proactive controls — Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard, OPA Rego, Cedar), and automated remediation workflows.
- Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
- Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration.
- Write and review IaC, scripts, enforcements and detections in Python, Terraform, AWS CDK, CloudFormation, and Rego.
- Build continuous compliance monitoring, automated evidence collection, visualization, reporting, and remediation pipelines that hold up in audit.
- Drive emerging-edge ideas into prototyping end-to-end to inform new security and compliance solutions and products.
- Identify risks and edge cases; propose implementation paths and go/no-go gates.
- Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn’t possible.
- Help develop technical content Identify cross-team patterns, gaps, improvements.
Requirements
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)
- Demonstrated ability to write and review code, scripts, IaC, and detections in support of security defenses.
- Demonstrated ability to lead security investigations and resolve root causes of operational and security issues.
Qualifications
- Basic Qualifications
- Preferred Qualifications