> Markdown version of [/jobs/ext/1419728-sr-security-engineer-leo-security](https://www.wearedevelopers.com/jobs/ext/1419728-sr-security-engineer-leo-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer, Leo Security - **Company:** Amazon.com, Inc. - **Location:** Redmond, WA, United States - **Experience:** Expert - **Salary:** $178,400.0 - $226,700.0 - **Contract:** Internship / Graduate position - **Skills:** Java (Programming Language), Software System Penetration Testing, Automation of Tests, Cloud Computing, Static Program Analysis, Code Review, Cyber Security, Computer Programming, Customer Data Management, Python (Programming Language), Software Systems, System Programming, Rust (Programming Language), Scripting, Technical Debt, Data Analytics, Build Process, Golang, Programming Languages - **Published:** July 24, 2026 - **Apply:** https://www.juju.com/job/00000000gj284f ## About the Role 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience - Experience as a mentor, tech lead or leading an engineering team - Bachelor's degree in CS, CE, or related field, or equivalent work experience - 8+ years delivering security assessments or reviews - 5+ years experience assessing the security of distributed software systems in Python, Java, Rust, GoLang or C/C+- 3+ years experience in delivering security for cloud-native environments and embedded environments Preferred Qualifications - Master's degree in Cybersecurity, Information Security, or a related field - Experience in performing and/or participating in technical security assessments, e.g. code level and design level assessments - Strong analytical and quantitative skills with the ability to use data and metrics to back up assumptions and recommendations that produce results - Familiarity with programming and scripting or experience developing security tools & processes that work at scale - Experience triaging security risks/vulnerabilities and ensuring that they are properly understood by the business and fixed and/or mitigated. - Hands-on experience with satellite communications and management software - Experience with low-level programming and embedded systems ## Description Project Leo is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world. Have you wanted an opportunity to secure an advanced satellite based broadband telecom service? The Leo Security team owns the security of product and operations of Project Leo end-to-end. We provide the necessary infrastructure and mechanisms to ensure the security of our satellite constellation and to protect the integrity and confidentiality of our customer data. Our team drives the research & development, deployment and operation of several mission-critical security systems and mechanisms. You will work in a start-up like environment, backed by Amazon's infrastructure to bootstrap security mechanisms, and help instill the security culture in the organization. Export Control Requirement Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. Key job responsibilities You will be responsible for establishing product-specific security bar, threat models, and security priorities. These will aide builders in ensuring consistent security execution across the business. You'll identify design & implementation defects. You'll support product development processes by providing consultation services on difficult security decisions. You will collaborate with business leaders to define security priorities. You will support product leaders by acting as a trusted advisor. You will support leaders by providing them with direction that makes security easy. You will help leaders measure their org's security execution. You'll guide teams towards outcomes that produce products that safely handle customer data. You will collaborate with builder teams to assess technical debt and risk. You will provide strategic direction that addresses vulnerabilities and fortifies our products. You will be a resource that leads the burn down of long-term risk. You will guide teams towards solutions that are secure by default. If secure-by-default solutions don't exist, you will invent & propose them. You will leverage support from automation teams that find discoverable vulnerabilities. You will advocate for the creation & deployment of new testing tools, and detection mechanisms. You will enable builder teams to become proactive & self-sufficient on security. You will work with builder teams to understand their build processes. You'll ensure that they use appropriate security linting & static analysis tools. You'll help our builders find security solutions that reduce security operations costs over time. You will instill a security culture in builder teams. You will mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours. You will assist Red Teams in identifying security testing priorities. You will assist in scoping penetration tests and help deep-dive on these engagements. You will investigate emerging security issue, root cause them, and devise mechanisms to prevent them. You will propose a security vision for the business that delivers security that protects our customers. And last of all, you will hack some really cool bleeding edge tech! A day in the life In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like "What's the right way to handle authentication tokens in service to service communications?" "We need to define security requirements for a confidential new product launch." "We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident." When you're not working on responding to the questions of your builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security initiatives to correct problems in the org. You will help Amazon maintain a high bar for customer security., Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company's reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)