About the job
AWS Forward Deployed Engineering (FDE) embeds AI engineers directly inside strategic enterprise customers to design, build, and deploy production-grade AI systems. We are looking for a Security Engineer to join the FDE security team and help secure production AI systems deployed in customer environments.
You will conduct security reviews, write security tooling, perform threat modeling, and implement controls that protect AI systems built by FDE engineers. You work alongside FDE delivery pods in customer environments, getting hands-on with production code, cloud infrastructure, and AI/ML pipelines. You learn fast, ship fast, and build security into the system rather than bolting it on after the fact.
This is a hands-on security engineering role where you spend most of your time writing code, reviewing architectures, and testing systems. You work with senior security engineers who will mentor you, but you own real security deliverables from your first engagement. If you want to learn AI security by doing it, in production, at enterprise scale, this is the role.
This position requires that the candidate selected be a US Citizen.
Responsibilities
- Conduct security design reviews, code reviews, and architecture assessments for production AI systems (agentic workflows, RAG pipelines, orchestration layers, model integrations) under guidance from senior security engineers
- Perform threat modeling and penetration testing for AI/ML applications deployed in customer environments; identify vulnerabilities and work with FDE engineers to implement fixes before production release
- Build and maintain security automation: scanning tools, CI/CD security gates, guardrail testing scripts, secrets detection, and dependency vulnerability checks for forward-deployed AI systems
- Implement security controls for AI-specific threats: prompt injection prevention, output filtering, data isolation, model API endpoint hardening, and guardrail configuration
- Support security incident response for FDE-delivered production AI systems; assist with triage, root cause analysis, and remediation under senior engineer guidance
- Document security findings, patterns, and remediation guidance as reusable playbooks and runbooks that benefit future FDE engagements
- Contribute to the FDE security accelerator library: reusable modules, templates, and reference configurations that help FDE engineers build secure AI systems faster
- Requires up to 25% travel
Qualifications
Minimum
- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Bachelor's degree in computer science or equivalent
- 2+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- 2+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 2+ years hands on building AI/agentic systems
Preferred
- Experience with security in service-oriented architectures/microservices and web services
- US government security clearance of top secret or above
- Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST
- Experience with AWS technologies
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go