Amazon

Amazon

united kingdom, London

Senior Security Engineer, AWS Security V&V Team

Full-Time£60,000 - 110,000 per yeargisterenUnited Kingdom
IT

Job Description

Salary: £60,000 - 110,000 per year

Requirements:
  • Experience developing software code in one or more programming languages, such as Java or Python
  • Knowledge of information security technologies, including security design review, threat modeling, risk analysis, and software testing techniques
  • Knowledge of security technologies and concepts, including authentication, authorization, single sign-on, and cryptography
  • Experience in risk assessment and enabling organizations to make security decisions
  • Experience working with operations and business teams to communicate problem impacts and understand business requirements
  • Experience in enterprise software
  • Bachelors degree or above in Computer Science, Computer Engineering, Cybersecurity, or a related discipline
  • 5+ years of professional penetration testing, source code auditing, bug hunting, or competitive CTF experience
  • Demonstrated ability to find non-trivial vulnerabilities through offensive testing of web applications and services and source code review
  • Demonstrated mastery of at least two complex security domains, such as networking, workload and tenant isolation, web application and API security, IAM, or cryptography, with the depth to find issues others miss and encode that expertise into automation
  • Experience building and steering AI agents for security work and reasoning about how agentic systems can be attacked
  • Preferred: Experience building agentic AI harnesses, orchestrating agents through graphs or swarms, and working with agent-to-agent (A2A) protocols and the security properties of tool use, memory, and model context
  • Preferred: Experience assessing LLM-based or agentic application security, including prompt injection, tool and plugin abuse, and trust boundaries between agents
  • Preferred: Experience performing or supporting Red Team engagements and understanding holistic assessment
  • Preferred: Web service assessment experience across authentication controls, session management, access controls, logic flaws, injection vulnerabilities, request smuggling, cloud privilege escalation, and tenant isolation
  • Preferred: Experience with serverless architectures and virtualization techniques such as hypervisors, containers, and jails, including escapes and exploits in those environments
  • Preferred: Experience with microservice, API-based, or service-oriented architectures
  • Preferred: Experience with full-stack Linux or Unix software architectures, from UI to infrastructure
  • Preferred: Operations experience with CI/CD or managing distributed systems
  • Preferred: Experience designing and implementing technical security controls at the business-division level
Responsibilities:
  • Own security for a portfolio of testing engagements across the team and partner organizations, and lead complex engagements individually
  • Set testing strategy across interconnected microservice architectures, successive launch iterations, and cross-service campaigns; prioritize expert effort across the service portfolio
  • Conduct penetration testing and AI-augmented source code review of complex proprietary AWS software, focusing tools on trust boundaries, abuse cases, and attack paths, validating reported findings, and setting team methodology
  • Take each agreed risk hypothesis to a documented conclusion by demonstrating the issue, ruling out the attack path with sufficient evidence, or identifying weaknesses in shared mechanisms or detections
  • Clarify ambiguous engagements where no security strategy exists, define reusable approaches, challenge scope assumptions, and adapt through alternative test paths, rescoping, and parallel work with dependent teams
  • Trace attack paths across chained components and demonstrate compound risks, including those crossing organizational and ownership boundaries
  • Produce clear engagement results documenting tests, rationale, findings or conclusions, limitations, and remaining risks; communicate effectively with non-engineering audiences when they make relevant decisions
  • Lead communication with developers, AppSec engineers, and other stakeholders; validate fixes, embed security testing in development when needed, and drive stalled fixes or risk decisions to closure with senior leaders and principal engineers
  • Build frameworks, runbooks, and rubrics for repeatable testing of new problem domains; tune AI tooling harnesses, measure false positives and missed attack patterns, and generalize effective approaches into team mechanisms
  • Create reusable mechanisms such as fuzzers, integration security tests, detection rules, tooling, and documented methodology; track adoption and help ensure security outcomes are prioritized and delivered
  • Set the teams peer-review bar by reviewing test plans, scopes, runbooks, and reports; identify coverage gaps, add missing test cases, and ensure work is extensible and economical to adopt
  • Lead multi-engineer engagements, mentor engineers across teams, serve as a sought-out expert, and participate in promotion assessments
Technologies:
  • Agentic AI
  • AI
  • AI Agents
  • API
  • AWS
  • CI/CD
  • Cloud
  • Cryptography
  • IAM
  • Java
  • LLM
  • Linux
  • Python
  • Security
  • Serverless
  • Unix
  • Web
  • UX UI Design
  • Embedded
  • Support
  • REST

More:

We are hiring a Senior Security Engineer for Point-in-Time Security Testing, AWSs expert security assurance function for complex launches and architectures where automation alone is not enough. AWS provides cloud services to customers worldwide, including government customers, and operates a globally distributed environment at massive scale. Our team works within Proactive Security, focusing expert reasoning on high-consequence security risks and turning findings into shared methods, mechanisms, and detections. We aim to ensure critical AWS launches receive appropriate expert testing and that each teams effort makes future testing more effective. At Amazon, security is central to customer trust, and our security organization works across products and services. We offer opportunities to gain experience across cloud, devices, retail, entertainment, healthcare, operations, and physical stores, along with knowledge-sharing, mentorship, training, and career-development resources. We value diverse experiences and perspectives, inclusive team culture, and work-life harmony.

last updated 40 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Amazon

Amazon

Amazon

united kingdom

IT

Skills & Technologies

PythonJavaGoRustScalaAWSLinuxCI/CDRESTAILLMUX

Inferred from job description

Salary Insight

£85,000

This role

£75,000

UK median

This salary is 13% above the UK median for Senior roles (£75,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom