Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Core
Lead threat modeling, security design reviews, and architecture for customer engagements; design and implement custom preventive, detective, and proactive controls using policy-as-code and IaC.
Role type
Senior IC Security & Compliance Engineer (AWS)
Builds
Secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower, Zero-Trust architectures, and AI/ML workloads.
Domain
Cloud Security / Compliance / AWS
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Python, Terraform, AWS CDK, CloudFormation, Rego, cfn-guard, Cedar, threat modeling, security design reviews, IaC, policy-as-code, automated remediation, continuous compliance monitoring, audit evidence collection, risk identification, compensating controls.
Preferred skills
TypeScript, Node.js, Go, Java, .NET, AWS Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch, SOC2, HIPAA, PCI-DSS, CIS, NIST, AWS Control Tower, Zero-Trust, Model Context Protocol (MCP), AWS Solutions Architect, AWS Security Specialty, CISSP.
Technologies
Python, Terraform, AWS CDK, CloudFormation, Rego, cfn-guard, Cedar, AWS Control Tower, AWS Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch, EventBridge, MCP
Responsibilities
Lead threat modeling and security design reviews; Design and implement custom controls (SCPs, RCPs, policy-as-code); Build secure-by-design IaC controls; Write and review IaC, scripts, and detections; Build continuous compliance monitoring and automated evidence pipelines; Integrate custom controls with AWS-native and third-party tooling; Drive emerging-edge ideas into prototyping; Identify risks and propose implementation paths; Help develop technical content; Identify cross-team patterns and gaps.
Seniority
Senior, hands-on IC