Senior Security Engineer, AGI Security Engineering

Amazon
Bellevue, WA, United States
$247.6K a year
Full-time

DescriptionDo you enjoy finding unique security flaws in artificial intelligence and LLMs? Do you enjoy protecting customers by securing AI and Amazon services at scale?

Do you enjoy mentoring and leading engineers to solve complex security problems in cutting-edge technologies? On AGI security team, as a Senior Security Engineer you will be responsible for the delivery of continuous assessments.

You will be asked to solve complex technology problems, build tools to automate your way out of manual efforts, and influence the way Amazon services, primarily Gen AI services respond to and mitigate threats.

Our team is responsible for manually evaluating the security of all GenAI models released by AGI. We specialize in uncovering subtle vulnerabilities that automated tools miss, and develop custom tooling to scale our security efforts across Amazon's expanding GenAI landscape.

The AGI surface area is large and diverse, and we use insights from manual testing to continually improve our focused automation to proactively identify and fix potential issues before customers are impacted.

The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. In their communication, they will clearly articulate risks to technical and non-technical audiences alike.

Successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.

We are passionate problem solvers with deep security expertise. We’re working hard, having fun, and making history. Come join our team! You will partner with world-class technical leaders, security experts, developers, business teams, scientists and data analysts across the organization, spanning a wide range of disciplines.

Key job responsibilitiesPerform expert cybersecurity red-teaming on complex proprietary foundation models testing, threat model and pentest the services built by AGI.

Manually generate the novel prompts, jailbreaks to bypass the existing model guardrails authored in house by AGI and AWS Bedrock.

Write proof of concept code to demonstrate the severity of a potential security issue .Provide clear communication on risks to ML builders / scientists that suggest and mitigate the risk.

Partner with ML builders / scientists to drive improvement in FM models security as a result of security review engagements .

Provide actionable long-term risk mitigation guidance to internal and external stakeholder .Conduct independent vulnerability research pertaining to GenAI technologies.

A day in the lifeA Security Engineer should foster constructive dialogue and seek resolution when confronted with discordant views.

Engineers in this role are expected to participate fully in the planning of the security team's work and constantly seek opportunities for process improvement.

They should also have a deep understanding of at least one specialty for which they are a sought out resource (both within AGI and by groups throughout Amazon), while having an understanding of the application of information security in a broad range of technical areas.

About the teamWork / Life Balance : Our team puts a high value on work-life balance. It isn’t about how many hours you spend at home or at work;

it’s about the flow you establish that brings energy to both parts of your life. We believe striking the right balance between your personal and professional life is critical to life-long happiness and fulfillment.

We offer flexibility in working hours and encourage you to find your own balance between your work and personal lives.Basic QualificationsBachelor’s degree in Computer Science, Engineering, or a related field;

Master’s or Ph.D. preferredMinimum 2 years of experience in AI security, adversarial machine learning, or related fieldsMinimum of 5 years of experience in security testing (Penetration testing, Vulnerability testing, Red teaming, bug hunting, CTF experience, or related field)Minimum of 5 years of experience with manually auditing source code (One or more of : Java, Ruby, Python, JavaScript, Rust, C, others) to find security issuesMinimum of 5 years of experience scripting in Python or other equivalent interpreted languagesSolid understanding of machine learning techniques, deep learning architectures, and generative models (e.

g., GANs, VAEs)Familiarity with security frameworks, tools, and techniques for protecting AI systemsKnowledge of data privacy regulations (e.

g., GDPR, CCPA) and their implications on AI systems is a plusExperience with AWS AI technologies and services (e.g. SageMaker, Code Whisperer, Bedrock, etc)Preferred QualificationsCCSP (Certified Cloud Security Professional) or CEH (Certified Ethical Hacker) or CFR (CyberSec First Responder) or Cloud+ or CySA+ (CompTIA Cybersecurity Analyst) or GCED (GIAC Certified Enterprise Defender) or GICSP (Global Industrial Cyber Security Professional) or PenTest- Experience with the architecture of GenAI models, platforms, and applicationsKnowledge of common AI / ML attack techniques such as prompt injection and ability to automate testing for these vulnerabilitiesAbility to identify vulnerabilities and threats specific to GenAI and other AI / ML systemsBackground in adversarial machine learning and emerging attacks like data poisoning, model extraction, membership inference, etcExperience with languages commonly used in AI / ML like Python, R, Java, C+- Meets / exceeds Amazon’s leadership principles for this roleMeets / exceeds Amazon’s functional / technical depth and complexity expectations for this roleExcellent communication skills to collaborate with cross-functional teams and present complex security concepts to non-technical stakeholderAmazon is committed to a diverse and inclusive workplace.

Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

For individuals with disabilities who would like to request an accommodation, please visit Our compensation reflects the cost of labor across several US geographic markets.

The base pay for this position ranges from $143,300 / year in our lowest geographic market up to $247,600 / year in our highest geographic market.

Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.

Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and / or other benefits.

For more information, please visit This position will remain posted until filled. Applicants should apply via our internal or external career site.

1 day ago
Related jobs
Promoted
Grange Insurance Association
Seattle, Washington

As a Senior Network & Security Engineer, you will be responsible for maintaining and supporting the company's infrastructure, systems, security and data communications. As a Senior Network & Security Engineer, you will be responsible for maintaining and supporting the company's infrastructure, syste...

Promoted
Grange Insurance Association
Lynnwood, Washington

As a Senior Network & Security Engineer, you will be responsible for maintaining and supporting the company's infrastructure, systems, security and data communications. As a Senior Network & Security Engineer, you will be responsible for maintaining and supporting the company's infrastructure, syste...

Promoted
Gusto
Seattle, Washington

We are looking for a senior software engineer to join our Product Security Engineering team. We help developers ship secure code by building security tools and services, providing security training and expertise, and advocating for best practices in authorization and safe data handling across the co...

Promoted
MongoDB
Seattle, Washington

The MongoDB Security organization is a diverse collection of individuals working together to scale MongoDB's security, both security of the products themselves and the security features we offer to customers. At least eight years of experience in managing security engineering programs. With a strong...

Promoted
Highwire Public Relations
Seattle, Washington

M in account revenue as most senior, strategic client counsel. Maintain account group revenue by managing the ebb and flow of accounts and budgets. Minimum 15 years experience in communications either in-house or with an agency with at least 5 years in a senior leadership capacity. Demonstrated expe...

Promoted
Microsoft
Redmond, Washington

Are you an experienced Security Data Analyst with a passion for unlocking security value from data? Do you want to influence the direction and outcome of a cloud security monitoring program through critical data insights? Do you thrive on solving complex and ambiguous challenges that will significan...

Promoted
Apex Fintech Solutions LLC
Seattle, Washington

This position will report to our CISO and will be responsible for our Information Security Architecture with functions including, but not limited to, security architecture and engineering, application security, cloud security, security strategy and building security control requirements. The Senior ...

Promoted
Amazon
Seattle, Washington

Principal, Hardware Engineering Services Security, AWS Hardware Engineering Core Fleet. AWS Hardware Engineering Services designs and delivers all of the servers in AWS. We are currently looking for AN ORCHESTRATOR OF INCREDIBLE FEATS OF STRENGTH AND TEAMWORK to drive security programs at all phases...

TikTok
Seattle, Washington

Our platform is built to help imaginations thrive. We are adding privacy features to Apache's big data ecosystem (Spark, Hive Presto), and building world-class data security & privacy framework for big data tech stack. Establish solid design and best engineering practices. ...

MongoDB
Seattle, Washington

The MongoDB Security organization is a diverse collection of individuals working together to scale MongoDB’s security, both security of the products themselves and the security features we offer to customers. At least eight years of experience in managing security engineering programs. With a strong...