×
Register Here to Apply for Jobs or Post Jobs. X

Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Job in Herndon, Fairfax County, Virginia, 22070, USA
Listing for: Amazon Web Services (AWS)
Full Time position
Listed on 2026-07-25
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 159000 - 202400 USD Yearly USD 159000.00 202400.00 YEAR
Job Description & How to Apply Below

Description

AWS Security Assurance Services (SAS) is hiring a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solutions for highly regulated customers. You will own engineering deliverables across the full lifecycle—secure design, implementation, testing, deployment, and maintenance—translating compliance frameworks (SOC2, HIPAA, PCI‑DSS, CIS, NIST, FedRAMP) into secure‑by‑design AWS implementations. You will work autonomously within your team, deliver cross–functional projects with partner teams, and drive measurable risk reduction for customers at scale.

You’ll write code, ship custom controls, run security investigations, lead design and code reviews on your team, and mentor junior engineers. You will identify systemic issues, propose pragmatic solutions, and improve the team’s mechanisms over time.

Key Job Responsibilities
  • Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.
  • Design and implement custom preventive, detective, and proactive controls—Service Control Policies (SCPs), Resource Control Policies (RCPs), policy‑as‑code (cfn‑guard, OPA Rego, Cedar), and automated remediation workflows.
  • Build secure‑by‑design Infrastructure‑as‑Code controls for Landing Zones, AWS Control Tower customizations, Zero‑Trust architectures, and AI/ML workloads.
  • Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro‑segmentation, tagging strategy, and API/MCP integration.
  • Write and review IaC, scripts, enforcements, and detections in Python, Terraform, AWS CDK, Cloud Formation, and Rego.
  • Build continuous compliance monitoring, automated evidence collection, visualization, reporting, and remediation pipelines that hold up in audit.
  • Integrate custom controls with AWS‑native and third‑party security and compliance tooling.
  • Drive emerging‑edge ideas into prototyping end‑to‑end to inform new security and compliance solutions and products.
  • Identify risks and edge cases; propose implementation paths and go/no‑go gates.
  • Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn’t possible.
  • Help develop technical content.
  • Identify cross‑team patterns, gaps, improvements.
  • Travel to customer sites as needed.
About the Team

The AWS Security Assurance Services team, within AWS Support, leverages expertise and ingenuity to establish scalable security solutions for both internal and external customers that drive business outcomes. The team operates across a broad spectrum of compliance and security services, helping enterprise customers ope rationalise the shared responsibility model as they migrate to the cloud.

Basic Qualifications
  • 3+ years of programming experience in Python, Ruby, Go, Swift, Java, .NET, C++ or similar object‑oriented language.
  • 2+ years of scripting, programming, and security code review in a common programming language.
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools.
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics) or equivalent experience in IT security.
  • Knowledge of networking protocols such as HTTP, DNS, and TCP/IP.
  • Experience applying threat modeling or equivalent risk identification techniques.
  • Experience conveying complex technical concepts to both technical and business audiences.
  • Strong analytical skills, attention to detail, and effective communication abilities.
  • Experience mentoring, coaching, and influencing colleagues, collaborators, and stakeholders.
Preferred Qualifications
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing.
  • Experience with version control systems and CI/CD pipeline implementation.
  • Experience supporting audit defense.
  • Experience developing, deploying, and managing AI products at scale.
  • AWS certification (Solutions Architect, CISSP-ISSAP, CISSP-ISSEP) or similar cloud certification.
  • 5+ years as…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary