Sr Security Engineer, Leo Security

Amazon
Seattle, WA, USA2026-08-14ONSITE

About the job

We are looking for a senior security engineer to join the founding cohort of the Engineering and R&D team within Leo Infrastructure and IP Security. The team defends the manufacturing lines, launch sites, and global ground infrastructure behind the constellation from the most sophisticated threat actors on the planet. The team builds a neurosymbolic reasoning platform: large language model agents combined with a knowledge graph and real-time asset state store that ground every conclusion in verifiable fact, so every automated decision is auditable. You will be the security owner for that platform. A system that can triage security events, execute containment, and act on physical security is itself a high-value target, and this role exists so the team that secures Leo does not ship its own unowned risk. This is a hands-on role for a technical contributor with deep expertise in offensive security who understands how to use AI on both sides: directing agents to test Leo's defenses the way an adversary would, and hardening the platform's own agents against the same techniques.

Responsibilities

You will be the single accountable security owner for every system the team builds and operates, from the agent platform and detection pipeline to the data plane and self-service workflows.

You will lead threat modeling and secure-design review on each system before it takes autonomous action, thinking like an adversary to find the weaknesses in agent tool access, prompt and data injection paths, and containment authority before someone else does.

You will design the privileged-access and insider-risk controls for systems that hold the keys to Leo physical security: the who-watches-the-watchers guarantee.

You will translate threat intelligence into the adversary behaviors that drive the team's models and detections, partnering with applied scientists on what to detect and with software engineers on how the platform defends itself.

You will use AI to scale both offense and defense: directing the platform's agents to run offensive validation against Leo's infrastructure and against the platform itself, and turning what the offense finds into detections, guardrails, and controls.

You will drive every finding, whether from your own testing, penetration tests, or red-team engagements, to closure, with security gates built into the team's own delivery cadence rather than bolted on after.

Qualifications

Minimum

2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience

Experience in progressive work within a software security team or related operating environment

Experience architecting, securing, and operating Amazon Web Services

Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 5+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience

5+ years of non-internship experience in troubleshooting systems issues, analyzing logs, automating complex tasks using command line tools, and identifying security issues, risks, and developing mitigation plans

Experience with offensive security, including penetration testing, red teaming, or adversarial testing of production systems

Preferred

Experience conveying complex technical concepts to both technical and business audiences

Understanding of threat actor tradecraft and ability to emulate sophisticated attack techniques

Experience with AI/ML security, including threats to AI systems, adversarial machine learning, prompt injection, or AI supply chain security

Experience applying AI to security work, including agentic tooling for offensive testing, detection engineering, or automated response

Experience with Red Team operations, threat-based assessments, or security research programs

Track record of building security tools or automation that scales across organizations

Experience designing privileged-access and insider-risk controls for high-consequence systems

Experience with security in regulated or export-controlled environments, including data-handling boundaries and audit evidence

Experience translating threat intelligence into detections, adversary emulation, or threat hunting

Contributions to security research community through publications, presentations, or open-source tools