Manager III, SecEng, AppSec AI
Job Description
Lead Application Security for Amazon Generative AI services by setting strategy, scaling secure review processes, and guiding a team focused on LLM-integrated application risks.
Responsibilities
- Lead, manage, and develop a team of Security Engineers and Technical Program Managers responsible for Application Security (AppSec) across Amazon’s Generative AI services and AI-powered applications.
- Set the strategic direction for GenAI Application Security review processes, including goal-setting and prioritization for securing LLM integrations, prompt engineering workflows, and AI model deployments.
- Drive AI security initiatives and influence leadership and key stakeholders through close partnership with AI/ML teams across Amazon.
- Build a collaborative culture that helps the team deliver outcomes in a rapidly changing GenAI security environment.
- Coordinate effective cross-team execution and communication across multiple groups with competing priorities, including data science, ML engineering, and product teams.
- Improve internal programs and processes for GenAI security reviews, including threat modeling for AI systems, secure prompt design, and model security assessments.
- Create and deliver high-quality documentation for both technical and non-technical audiences covering complex GenAI security topics.
- Advance adoption of GenAI-specific security processes, automation, and tooling to increase operational efficiency and scale security reviews for AI applications.
- Stay current on emerging GenAI security threats and vulnerabilities, with expertise in areas such as prompt injection prevention, model security, RAG security, and AI supply chain security.
- Mentor and develop individual contributors, strengthening technical depth and leadership capabilities.
Requirements
- 5+ years of experience managing and developing teams.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- Knowledge of security practices for web services, video content protection technologies, cryptography, network security protocols, and operating system security.
- Experience applying threat modeling or other risk identification techniques to both traditional and AI-powered applications.
- Understanding of Generative AI technologies, large language models, and AI application architectures.
Technologies
- Generative AI
- Large language models (LLMs)
- LLM integrations
- Prompt engineering
- AI model deployments
- Threat modeling
- RAG security
- AI supply chain security
- Adversarial machine learning
- AI/ML frameworks
- LLM APIs
- RAG architectures
- AI model deployment pipelines
- Cryptography
- Network security protocols
Benefits
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage)
- 401(k) matching
- Paid time off
- Parental leave
- Sign-on payments
- Restricted stock units (RSUs)
Preferred Qualifications
- Knowledge of information security technologies such as security design review, threat modeling, risk analysis, and software testing techniques.
- Experience with GenAI security challenges including prompt injection, model security, data privacy in AI systems, and adversarial machine learning.
- Familiarity with AI/ML frameworks, LLM APIs, RAG architectures, and AI model deployment pipelines.
Location: Seattle, WA (onsite)
Salary: USD 175,100 - 236,900 per year