Prepin
Log in
Amazon

engineering opportunity

Security Engineer, Forward Deployed Engineering, Forward Deployed Engineering

The Security Engineer will conduct security reviews, threat modeling, and penetration testing for production AI systems deployed in customer environments. They will also build security automation tools and implement controls to protect AI/ML pipelines and orchestration layers.

Dallas, Texas, United StateshybridFULL_TIME

Posted

About the role

What will you do at Amazon?

AWS Forward Deployed Engineering (FDE) embeds AI engineers directly inside

strategic enterprise customers to design, build, and deploy production-grade AI

systems. We are looking for a Security Engineer to join the FDE security team

and help secure production AI systems deployed in customer environments.

You will conduct security reviews, write security tooling, perform threat

modeling, and implement controls that protect AI systems built by FDE engineers.

You work alongside FDE delivery pods in customer environments, getting hands-on

with production code, cloud infrastructure, and AI/ML pipelines. You learn fast,

ship fast, and build security into the system rather than bolting it on after

the fact.

This is a hands-on security engineering role where you spend most of your time

writing code, reviewing architectures, and testing systems. You work with senior

security engineers who will mentor you, but you own real security deliverables

from your first engagement. If you want to learn AI security by doing it, in

production, at enterprise scale, this is the role.

This position requires that the candidate selected be a US Citizen.

Key job responsibilities

- Conduct security design reviews, code reviews, and architecture assessments

for production AI systems (agentic workflows, RAG pipelines, orchestration

layers, model integrations) under guidance from senior security engineers

- Perform threat modeling and penetration testing for AI/ML applications

deployed in customer environments; identify vulnerabilities and work with FDE

engineers to implement fixes before production release

- Build and maintain security automation: scanning tools, CI/CD security gates,

guardrail testing scripts, secrets detection, and dependency vulnerability

checks for forward-deployed AI systems

- Implement security controls for AI-specific threats: prompt injection

prevention, output filtering, data isolation, model API endpoint hardening, and

guardrail configuration

- Support security incident response for FDE-delivered production AI systems;

assist with triage, root cause analysis, and remediation under senior engineer

guidance

- Document security findings, patterns, and remediation guidance as reusable

playbooks and runbooks that benefit future FDE engagements

- Contribute to the FDE security accelerator library: reusable modules,

templates, and reference configurations that help FDE engineers build secure AI

systems faster

- Requires up to 25% travel

A day in the life

You start the morning running your automated security scan against a new

Bedrock-powered application an FDE pod shipped overnight, triaging the findings

and filing issues for two real vulnerabilities. Mid-morning you pair with an FDE

engineer to fix an IAM policy that's overly permissive for their multi-agent

orchestration system. After lunch you're writing a Python script that automates

guardrail bypass testing for the team's standard deployment pattern. You close

out the day joining a threat modeling session led by a senior security engineer,

where you learn how to assess data flow risks in a customer's RAG pipeline.

Every week you're working on a different AI architecture, building skills you

can't get anywhere else.

About the team

AWS Forward Deployed Engineering embeds AI engineers directly inside strategic

enterprise customers to build production AI systems. AWS invested $1B in this

initiative. We move at the speed of the customer: demonstrating ROI in weeks,

not quarters. We are customer-obsessed. We lead customers toward outcomes, build

together, and leave behind scalable patterns. Security is our enabling function:

without it, nothing goes to production. Our culture is people-first,

anti-burnout, bold, and engineering-excellence-driven.

ABOUT AWS:

Diverse Experiences

Amazon values diverse experiences. Even if you do not meet all of the preferred

qualifications and skills listed in the job description, we encourage candidates

to apply. If your career is just starting, hasn’t followed a traditional path,

or includes alternative experiences, don’t let it stop you from applying.

Why AWS

Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted

cloud platform. We pioneered cloud computing and never stopped innovating —

that’s why customers from the most successful startups to Global 500 companies

trust our robust suite of products and services to power their businesses.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the

expense of sacrifices at home, which is why we strive for flexibility as part of

our working culture. When we feel supported in the workplace and at home,

there’s nothing we can’t achieve in the cloud.

Inclusive Team Culture

AWS values curiosity and connection. Our employee-led and company-sponsored

affinity groups promote inclusion and empower our people to take pride in what

makes us unique. Our inclusion events foster stronger, more collaborative teams.

Our continual innovation is fueled by the bold ideas, fresh perspectives, and

passionate voices our teams bring to everything we do.

Mentorship and Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s

Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and

other career-advancing resources here to help you develop into a better-rounded

professional.

10047

Basic

Qualifications

  • - 2+ years of any combination of the following: threat
  • modeling experience, secure coding, identity management and authentication,
  • software development, cryptography, system administration and network security
  • experience
  • - 2+ years of troubleshooting systems issues, analyzing logs, or automating
  • basic tasks using command line tools (non-internship) experience
  • - Bachelor's degree in computer science or equivalent
  • - 2+ years of (non-internship) scripting, programming, and security code review
  • in common programming languages experience
  • - 2+ years of work in identifying security issues and risks, and developing
  • mitigation plans experience
  • - 2+ years hands on building AI/agentic systems

Preferred Qualifications

  • -
  • Experience with security in service-oriented architectures/microservices and web
  • services
  • - US government security clearance of top secret or above
  • - Experience with compliance & security standards including PCI DSS, ISO 27001,
  • HIPAA, and NIST
  • - Experience with AWS technologies
  • - Knowledge of at least two of the following programming languages: Scala, Java,
  • Python, C/C++, or Go
  • Amazon is an equal opportunity employer and does not discriminate on the basis
  • of protected veteran status, disability, or other legally protected status.
  • Our inclusive culture empowers Amazonians to deliver the best results for our
  • customers. If you have a disability and need a workplace accommodation or
  • adjustment during the application and hiring process, including support for the
  • interview or onboarding process, please visit
  • https://amazon.jobs/content/en/how-we-hire/accommodations
  • [https://amazon.jobs/content/en/how-we-hire/accommodations] for more
  • information. If the country/region you’re applying in isn’t listed, please
  • contact your Recruiting Partner.
  • The base salary range for this position is listed below. Your Amazon package
  • will include sign-on payments and restricted stock units (RSUs). Final
  • compensation will be determined based on factors including experience,
  • qualifications, and location. Amazon also offers comprehensive benefits
  • including health insurance (medical, dental, vision, prescription, Basic Life &
  • AD&D insurance and option for Supplemental life plans, EAP, Mental Health
  • Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy
  • Reimbursement coverage), 401(k) matching, paid time off, and parental leave.
  • Learn more about our benefits at https://amazon.jobs/en/benefits
  • [https://amazon.jobs/en/benefits].
  • USA, TX, Dallas - 159,300.00 - 202,400.00 USD annually

Which skills does this role require?

Security engineeringThreat modelingPythonCloud infrastructureAI/ML pipelinesPenetration testingSecurity automationCI/CD securityIdentity managementCryptographyNetwork securityPrompt injection preventionData isolationCode reviewArchitecture assessmentAIMachine LearningSecurity EngineeringThreat ModelingIAMCI/CDBedrockRAGOrchestrationPrompt InjectionMicroservicesNetwork SecurityAutomationSecurity ReviewsVulnerability AssessmentCompliancePCI DSSISO 27001HIPAANISTScalaJavaC/C++

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.