CybersecurityJobs.io
← Back to all jobs

Job Description

The Security Engineer role in AWS Forward Deployed Engineering (FDE) supports the secure delivery of production AI systems in customer environments. The work focuses on security design reviews, threat modeling and testing, security automation, and implementation of controls tailored to AI-specific risks.

Role Overview

As part of FDE security, you help secure production AI deployments by reviewing security designs and code, identifying vulnerabilities before release, and building repeatable security practices that accelerate secure AI delivery. This includes work across agentic workflows, RAG pipelines, orchestration layers, and model integrations deployed in customer environments.

Responsibilities

  • Conduct security design reviews, code reviews, and architecture assessments for production AI systems, including agentic workflows, RAG pipelines, orchestration layers, and model integrations, with guidance from senior security engineers
  • Perform threat modeling and penetration testing for AI/ML applications deployed in customer environments; identify vulnerabilities and coordinate with FDE engineers to implement fixes prior to production release
  • Build and maintain security automation, including scanning tools, CI/CD security gates, guardrail testing scripts, secrets detection, and dependency vulnerability checks
  • Implement security controls for AI-specific threats, such as prompt injection prevention, output filtering, data isolation, model API endpoint hardening, and guardrail configuration
  • Support security incident response for FDE-delivered production AI systems, assisting with triage, root cause analysis, and remediation under senior engineer guidance
  • Document security findings, patterns, and remediation guidance as reusable playbooks and runbooks for future FDE engagements
  • Contribute to the FDE security accelerator library, including reusable modules, templates, and reference configurations to help FDE engineers build secure AI systems faster
  • Travel up to 25%

Key Skills and Technologies

  • Technologies: Python, CI/CD, Bedrock, IAM, RAG, AI/ML, agentic workflows

Required Qualifications

  • 2+ years of any combination of: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security (non-internship)
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship)
  • Bachelor’s degree in computer science or equivalent
  • 2+ years of (non-internship) scripting, programming, and security code review in common programming languages
  • 2+ years of identifying security issues and risks and developing mitigation plans
  • 2+ years of hands-on building AI/agentic systems
  • Citizenship: US Citizen

Preferred Qualifications

  • Experience with security in service-oriented architectures/microservices and web services
  • US government security clearance of top secret or above
  • Experience with compliance and security standards including PCI DSS, ISO 27001, HIPAA, and NIST
  • Experience with AWS technologies
  • Knowledge of at least two of: Scala, Java, Python, C/C++, or Go

Work Schedule and Location

  • Location: Dallas, TX (onsite)
  • Salary: USD 159,300 - 202,400 per year

Benefits

  • Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, and option for Supplemental life plans)
  • EAP
  • Mental Health Support
  • Medical Advice Line
  • Flexible Spending Accounts
  • Adoption and Surrogacy Reimbursement coverage
  • 401(k) matching
  • Paid time off
  • Parental leave
  • Sign-on payments and restricted stock units (RSUs)

A Day in the Life

  • Start the morning by running automated security scans against a new Bedrock-powered application delivered by an FDE pod overnight, triaging findings and filing issues for vulnerabilities
  • Pair with an FDE engineer to resolve an IAM policy that is overly permissive for multi-agent orchestration systems
  • Write a Python script to automate guardrail bypass testing for a standard deployment pattern
  • Join a threat modeling session led by a senior security engineer to assess data flow risks in a customer RAG pipeline
  • Work each week on a different AI architecture, expanding skills across varied customer deployments

About the Team

AWS Forward Deployed Engineering embeds AI engineers directly inside strategic enterprise customers to build production AI systems. AWS invested $1B in this initiative, and security is positioned as an enabling function for production readiness. The culture emphasizes people-first values, anti-burnout practices, bold execution, and engineering-excellence-driven delivery.

Similar Jobs