Applied Scientist, AGI/AI Security

Amazon
New York, NY, USA / Seattle, WA, USA2026-09-15ONSITE

About the job

We are seeking an Applied Scientist to contribute to research and development of novel security validation and monitoring techniques for AI systems at scale. You will own and contribute to four critical work-streams:

1. Real-Time Agent Monitoring

Design and implement scientific approaches for continuous behavioral analysis of AI agents in production—detecting anomalous actions, prompt injection exploitation, and policy violations in real time.

2. Protection & Automated Remediation

Invent and deliver novel protection technologies and automated remediation techniques building on research in security, cryptography, privacy, automated reasoning, and others domains, to enable safe and secure agentic AI models and AI applications.

3. AI Application and Capabilities Validation

Invent and deliver scalable methodologies for security testing of AI applications and AI capabilities (e.g. MCP, skills), including adversarial robustness evaluation, safety guardrail bypass detection, tool-use authorization boundaries, and trust boundary verification.

4. AI Asset Discovery & Inventory

Research and build scalable techniques to automatically discover, identify, and catalog all AI-enabled applications, services, and capabilities across the company—maintaining a comprehensive, continuously updated database of AI assets.

Responsibilities

Identify and frame new research challenges in AI security where problems are ill-defined and require novel scientific paradigms at the product level.

Contribute to the team's scientific agenda for agent monitoring, protection, remediation, validation research, and AI asset discovery.

Publish research results at peer-reviewed internal and external venues (e.g., USENIX Security, ACM CCS, IEEE S&P, NeurIPS, ICML security workshops, ICSE, PETS) when appropriate.

Articulate key scientific challenges of current and future AI security threats and deliver novel research to address them.

Design, implementation, and successful delivery of scientifically complex security solutions into production—both brand new systems and evolutions of existing ones.

Write significant portions of critical-path code for detection models, validation engines, protection technologies, and asset discovery / classification systems.

Assess and select appropriate technologies (e.g., data protection, private inference, graph-based anomaly detection, NLP-based service classification, code/traffic analysis for AI fingerprinting) for production systems.

Use best practices in scientific methodology and software engineering across the team; provide insightful peer reviews of code, design, and architecture artifacts.

Deliver solutions that are inventive, maintainable, scalable, and extensible.

Autonomously drive discussions with security engineers, software engineers, product managers, and scientist peers across multiple teams.

Build consensus on larger cross-team security initiatives and factor complex efforts into independent workstreams.

Identify and resolve endemic problems, including areas where current security tooling limits innovation of partner teams.

Contribute to the broader internal and external scientific communities as a subject matter expert in AI security.

Qualifications

Minimum

3+ years of building models for business application experience

PhD, or Master's degree and 4+ years of CS, CE, ML or related field experience

Experience in patents or publications at top-tier peer-reviewed conferences or journals

Experience programming in Java, C++, Python or related language

Experience in any of the following areas: algorithms and data structures, parsing, numerical optimization, data mining, parallel and distributed computing, high-performance computing

Preferred

Experience using Unix/Linux

Experience in professional software development