Sr. Security & Compliance Engineer, AWS Security Assurance Services, LLC
Amazon Web Services (AWS) · Nashville, TN · 2 days ago
EngineeringFull-time
About the role
AWS Security Assurance Services (SAS) is hiring a Senior Security & Compliance Engineer to lead the design, deployment, and implementation of complex AWS security and compliance solutions.
Responsibilities
- Own design and architecture choices for security and compliance automation solutions for regulated customers and influence partner-org design and deliverables.
- Engineer and lead AI-enabled automations, threat modeling, design reviews.
- Build secure-by-design IaC modules for Landing Zones, Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
- Lead the design, deployment, and implementation of AWS security controls, continuous compliance monitoring, evidence collection, and remediation of insecure configurations to scale with automation.
- Architect custom preventive, detective, and proactive controls, SCPs, RCPs, policy-as-code (cfn-guard, OPA Rego, Cedar).
- Set high bar for authentication and authorization, data protection, least privilege, encryption, micro-segmentation, tagging strategy, integrations via API and MCP, and secure AI agentic design.
- Write and review scripts, and IaC (Python, Terraform, AWS CDK, CloudFormation, Rego).
- Lead exploratory POCs on emerging technologies.
- Define the hypothesis, success criteria, and go/no-go gates.
- Lead alignment, resolve escalations, troubleshooting, and root-cause analysis to closure.
- Lead the development of technical content.
- Communicate security risk and design decisions clearly verbally and in writing to technical, non-technical, and C-level audiences.
- Identify and shape sales opportunities.
- Influence service-team roadmaps and SAS offering strategy.
- Travel to customer sites as needed.
Requirements
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience.
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience.
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go.
- Bachelor's degree or above in computer science, engineering, mathematics or equivalent, or experience working in Science, Technology, Engineering, or Mathematics (STEM).
- 4+ years of cloud architecture and solution implementation experience, or US government security clearance of top secret or above.
- Experience managing full application stacks from the OS up through custom applications, or experience working with REST API based services and experience with threat modeling and penetration testing.
- Experience handling ambiguous or undefined challenges through strong problem solving abilities.
- Experience managing conflict, escalations, negotiating compromise, influencing others and problem solving with engineering teams.
- Experience communicating across technical and non-technical audiences, including executive level stakeholders or clients.
Qualifications
- Experience with security in service-oriented architectures/microservices and web services.
- Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls.
- Experience developing, deploying and managing AI products at scale.
- Experience in security or compliance consulting or advisory work in support of a highly technical environment.
- Experience designing or architecting (design patterns, reliability and scaling) of new and existing systems.
- Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST.
- Industry and AWS certifications: CISSP, AWS Solutions Architect Professional, AWS Security Specialty strongly preferred; additional certifications a plus.