Application Security Engineer, US Amazon Dedicated Cloud Security
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Amazon's Security team is looking for a Senior Application Security Engineer to lead application security for a U.S. Government program building a purpose-built AI Factory. We are a hands-on team that raises the security bar by baking it into how software is built, not bolting it on afterward. In this role you define the application-security acceptance criteria, scanning gates, and image-signing policy, own software supply-chain assurance standards, and ensure the platform build implements and validates against them.
You will work in the trenches with software engineers, ISSOs, and security testers to secure the pipeline that delivers AI capability to the mission. If you get excited about the challenge of securing software at scale in an environment with none of the usual conveniences, this role is for you. This position requires that the candidate selected be a US Citizen and must currently possess and maintain an active TS/SCI security clearance with polygraph.
job responsibilities
- Partner with platform software teams to secure CI/CD pipelines, conduct security code reviews, and drive remediation of identified vulnerabilities.
- Define application-security acceptance criteria, scanning gates, and image-signing policy for an AI platform serving U.S. Government customers.
- Own software supply-chain assurance standards — including artifact provenance, dependency validation, and image-signing policy — and ensure the platform build implements and validates against them.
- Collaborate directly with software engineers, Information System Security Officers (ISSOs), and security testers to ensure security is integrated throughout the development lifecycle.
- Communicate security risk and design decisions in writing to both technical and non-technical audiences, and mentor other security engineers through design reviews and career guidance.
You might start your morning defining a new scanning gate for a container image pipeline, working through acceptance criteria with the platform build team. Later you investigate a supply-chain validation result that flagged an unexpected dependency, then partner with an ISSO to confirm the remediation path meets compliance requirements. You close out the day pairing with a software engineer to harden a CI/CD stage, sharing patterns that the broader team can reuse.
AboutThe Team
Our team sits within Amazon's Security organization and supports U.S. Government customers by ensuring that AI workloads are built on a secure software foundation. We work shoulder-to-shoulder with platform software engineers, ISSOs, and security testers to integrate security into every phase of the build. We are investing in supply-chain assurance, automated scanning infrastructure, and secure delivery pipelines. If you want to solve hard problems that directly protect mission-critical capabilities, this is the team for you.
DiverseExperiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
InclusiveTeam Culture
In Amazon…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).