Senior Security Engineer, AWS Security Verification & Validation Team
Amazon
- Location
- GB, Virtual Location - Uk
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Posted
- Sep 17, 2026
Skills
About this role
We are looking for a Senior Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will be a technical leader on a team, owning complex security testing engagements end-to-end, applying human judgment where it changes security outcomes and building automation for everything else. Amazon Web Services (AWS) is the leading cloud service provider, providing virtualized infrastructure, storage, networking, messaging, and many other services to customers all over the world, including government customers. AWS runs a globally distributed environment operating at massive scale, and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the security engagements where the architecture, threat model, or potential impact is complex enough that expert reasoning matters most. We start from the architecture and the risks rather than a generic checklist, think like an adversary, and demonstrate realistic impact. We build harnesses that steer agentic AI so experts have more time for the difficult problems, and we turn what we learn into shared methods, mechanisms, and detections for the rest of the team. As AWS ships agentic systems of its own, those same systems become targets we test. Our work is measured by how much difficult security uncertainty we resolve with the human time available to us, not by how many issues we find. In this role you will investigate high-consequence risks, which are specific, testable claims about how an adversary could cause harm, and take each one to a documented conclusion. You will either demonstrate the issue, rule out the attack path with enough evidence, or expose a weakness in a shared mechanism or detection. You must produce results in the face of ambiguity and imperfect knowledge, foster constructive dialogue, and drive resolution when faced with disagreement. You work efficiently and routinely deliver the right things with limited guidance. You take a long-term view of the team's methods and tooling, proactively fix architectural and mechanism deficiencies, and propose larger project scopes that you can split into parallel work for yourself and others and reassemble successfully. Amazon's Leadership Principles of "Dive Deep", "Earn Trust", "Deliver Results", and "Invent and Simplify" will be called upon daily. Above all, we earn trust by choosing carefully where humans spend time, testing those areas deeply, and being honest about what we know and what we do not. Key job responsibilities - Own security for a portfolio of testing engagements across your team and partner-orgs, as well as leading individual complex engagements. Set the testing strategy across interconnected microservice architectures, successive launch iterations, and cross-service campaigns, and decide where to spend expert effort across the whole service portfolio. - Perform penetration testing and AI-augmented source code review of complex proprietary AWS software, directing the tooling at trust boundaries, abuse cases, and attack paths it would not reach on its own, confirming what it reports, and setting the methodology your team follows when they do the same. - Take each agreed risk hypothesis to a documented conclusion, whether that means demonstrating the issue with proof-of-concept code, ruling out the attack path with sufficient evidence, or identifying a weakness in a shared mechanism or detection that affects services beyond the one under test. - Take on engagements where the customer case is understood but no security strategy exists yet, bring clarity to the ambiguity, and define the approach others will reuse. Challenge what a scope document assumes and identify what it misses, then keep the engagement moving when conditions change by building alternative test paths, re-scoping, and parallelizing work with