Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Listed on 2026-06-20
-
IT/Tech
Cybersecurity, Data Security, Security Manager
Overview
AWS Security Assurance Services (SAS) is hiring a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solutions for highly regulated customers. You will own engineering deliverables across the full lifecycle — secure design, implementation, testing, deployment, and maintenance — translating compliance frameworks (SOC2, HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work autonomously within your team, deliver cross-functional projects with partner teams, and drive measurable risk reduction for customers will write code, ship custom controls, run security investigations, lead design and code reviews, and mentor junior engineers.
You will identify systemic issues, propose pragmatic solutions, and improve the team’s mechanisms over time.
- Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.
- Design and implement custom preventive, detective, and proactive controls — Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard, OPA Rego, Cedar), and automated remediation workflows.
- Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
- Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration.
- Write and review IaC, scripts, enforcements and detections in Python, Terraform, AWS CDK, Cloud Formation, and Rego.
- Build continuous compliance monitoring, automated evidence collection, visualization, reporting, and remediation pipelines that hold up in audit.
- Integrate custom controls with AWS-native and third-party security and compliance tooling.
- Drive emerging-edge ideas into prototyping end-to-end to inform new security and compliance solutions and products.
- Identify risks and edge cases; propose implementation paths and go/no-go gates.
- Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn’t possible.
- Help develop technical content.
- Identify cross-team patterns, gaps, improvements.
- Travel to customer sites as needed.
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Bachelor’s degree in a STEM field or experience in IT Security
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Knowledge of industry-based security vulnerabilities and remediation techniques
- Experience conveying complex technical concepts to both technical and business audiences
- Experience that includes strong analytical skills, attention to detail, and effective communication abilities, or experience in Linux OS and network troubleshooting and experience with threat modeling and penetration testing
- Experience applying threat modeling or other risk identification techniques or equivalent
- 3+ years of security engineering or related security experience; demonstrated ability to deliver security solutions independently within a team scope, handling the full development lifecycle: design, implementation, testing, deployment, and maintenance.
- Demonstrated ability to write and review code, scripts, IaC, and detections in support of security defenses.
- Demonstrated ability to mentor peers, drive consensus on conflicting design or implementation feedback, and provide meaningful review feedback.
- 2+ years of any combination of threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience performing security activities across SDLC phases such as security design review, threat…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).