Senior Security Engineer, AI Platforms (DevSecOps)
Core
Design and build self-service CI/CD pipelines and AI platforms on AWS to secure agentic workloads, LLM applications, and infrastructure using DevSecOps and AI-DLC practices.
Role type
Senior Security Engineer (AI Platforms & DevSecOps)
Builds
Self-service delivery pipelines, AI Hub platforms on AWS (Bedrock/AgentCore), and automated security controls for agent workloads.
Domain
Cloud Security, AI/ML Security, DevSecOps
Deliverable
production ML models | infrastructure
Required skills
CI/CD pipeline design and ownership, Infrastructure as Code (Terraform/CDK), Threat modeling for LLMs and agents, Policy as code, AWS security services (IAM, SCPs, CloudTrail, Security Hub), AI coding agent usage and governance.
Preferred skills
Amazon Bedrock and AgentCore production experience, AI evals and red-teaming, MCP server development, AI governance frameworks (ISO/IEC 42001, NIST AI RMF), CSPM/CNAPP platforms (Wiz), Software supply chain security.
Technologies
GitHub Actions, GitLab CI, Harness, Terraform, AWS CDK, OPA/Rego, Checkov, cfn-guard, AWS Config, Cedar, CloudTrail, CloudTrail Lake, Security Hub, OIDC, KMS, Bedrock, AgentCore, Claude Code, Kiro, Amazon Q Developer, Cursor, Copilot.
Responsibilities
Design CI/CD pipelines with security scanning and approval gates; Write IaC for multi-account AWS environments with guardrails; Threat model LLM and agent applications; Enforce security policies via code; Map automated controls to compliance requirements; Build platform-level controls for logging and identity; Govern agent access to tools and data; Add AI release gates to pipelines; Detect agent misbehavior at runtime; Manage security exceptions process; Coach engineers on AI coding tool usage.
Seniority
Senior, hands-on IC