> Markdown version of [/jobs/ext/2151902-director-ai-security-platform-engineer](https://www.wearedevelopers.com/jobs/ext/2151902-director-ai-security-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, AI Security Platform Engineer - **Company:** Amazon.com, Inc. - **Location:** Bethesda, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Data Analysis, Applications Architecture, Computing Platforms, Application Portfolio Management, Automation of Tests, Cloud Computing, Cloud Computing Security, Configuration Management Databases, Cyber Security, Computer Programming, Continuous Integration, Data Architecture, Data Structures, Software Debugging, Distributed Systems, Data Flow Control, Python (Programming Language), Key Management, OAuth, Open Source Technology, Program Design Languages, Role-Based Access Control, Zero Trust Network Access, Software Engineering, Data Streaming, Systems Integration, TypeScript, Parquet, Information Security Management System, Istio, Multi-Agent Systems, Software Security, Core Api, Backend, Rate Limiting, Event Driven Architecture, Build Management, Data Lakes, Kubernetes, Information Technology, Data Lineage, Production Code, Enterprise Integration, Graphql, Virtual Agents, Api Design, Plan of Action and Milestones - **Published:** August 20, 2026 - **Apply:** https://www.careerjet.com/jobad/us46f13dc91250564a6b9ede734ee98103 ## About the Role * Master's degree in Computer Science, Cybersecurity, or a related STEM field, or commensurate experience in the role. * 8+ years of experience in software engineering or architecture, including production distributed systems at enterprise scale. * 5+ years of experience in security engineering, compliance automation, or platform development. * Demonstrated experience designing and shipping platforms consumed by other engineering teams and multiple customer personas. * Proven experience leading a small engineering team as a hands-on player-coach, including hiring, mentoring, and growing engineers while remaining a strong individual contributor. * Track record of cross-organizational technical leadership, influencing architecture decisions across team boundaries through design quality and stakeholder alignment, including without direct authority. * Experience implementing regulatory compliance frameworks such as: * NIST * ISO 27001 * EU AI Act * Strong communication skills with the ability to: * Brief senior leadership * Draft Architectural Decision Records (ADRs) * Coordinate across security, engineering, privacy, and governance teams Preferred Experience * Experience defining and operating a NIST OSCAL-native compliance system of record across multiple OSCAL models, including: * Catalog * Profile * Component Definition * System Security Plan (SSP) * Assessment Results * POA&M * Experience building agent-native API surfaces, including MCP or equivalent, consumed by AI systems rather than only human clients. * Prior success establishing an inner-source platform with an active contributor community across multiple engineering teams. * OSCAL experience is preferred but not mandatory., Candidates do not need to be specialists in every area, but must be capable of understanding and troubleshooting the entire ecosystem. Programming * Python - required * At least one additional systems language for production platform development: * Go * TypeScript * Rust API & Application Architecture * REST * GraphQL * Streaming/SSE * API design for platform consumers * Protocol selection and trade-offs * Agent-native API patterns Security Architecture * Security frameworks * Security scoring platforms * Large distributed security applications * Access-control models * RBAC implementation * Security architecture * Enterprise deployment models * Secure platform engineering * mTLS * OAuth2 client credentials * Service identity * Zero-trust networking * API security patterns Cloud & Infrastructure * Kubernetes * Cloud infrastructure architecture * AWS preferred * Service mesh * Secrets management * Multi-environment deployment AI / ML & Agentic Systems * AI/ML agent frameworks * Agentic system design * Multi-agent orchestration * Tool libraries * Model Context Protocol (MCP) or similar agent-native API patterns * Ability to debug, troubleshoot, maintain, and improve AI-powered platform environments, Ideal profile: A senior engineering leader who is still a strong individual contributor, has built enterprise-scale distributed platforms, understands security and compliance technically, can work with AI/agentic systems, and has demonstrated success leading a lean engineering team across organizational boundaries. ## Description We are seeking a Director, AI Security Platform Engineer to serve as a hands-on engineering leader responsible for defining, building, and evolving a multi-service security compliance platform that serves as the connective tissue across an enterprise AI security program. This platform will bring together capabilities spanning agent governance, edge defense, continuous testing, compliance evidence, and security operations, creating a unified technical architecture for evidence collection, control management, risk scoring, and compliance reporting. This is a player-coach leadership role. You will lead and grow a small, nimble engineering team while remaining the platform's strongest individual contributor. The role is approximately 60% hands-on engineering and architecture and 40% people leadership and cross-organizational coordination. You will be expected to write production code, own architecture and technology decisions, establish integration contracts, mentor engineers, and influence technical direction across security, engineering, privacy, governance, and enterprise architecture teams. The ideal candidate combines senior-level distributed systems engineering, security platform expertise, AI/agentic system knowledge, and hands-on technical leadership. You should be comfortable resolving an architectural or protocol decision, implementing the service that proves it out, mentoring an engineer, and aligning multiple teams on an integration contract., Platform Architecture & Core Development * Define the end-to-end architecture for a multi-service security compliance platform covering evidence collection, controls system of record, and risk scoring. * Build the platform's core services and remain accountable for production implementation. * Own technology selection, protocol decisions, data model design, and architectural direction. * Design solutions capable of supporting enterprise-scale production adoption. Team Leadership & Mentorship * Lead, grow, and mentor a small, nimble engineering team. * Set technical direction and drive code and design reviews. * Unblock engineers and provide hands-on technical guidance. * Own hiring, delivery planning, and performance development. * Maintain a high-leverage, lean engineering team without unnecessary process overhead. * Lead as a player-coach, shipping alongside the team rather than managing exclusively from above. AI & Agent-Native Platform Engineering * Design and build the agent consumption layer that enables AI agents across the security organization to access, query, and reason about compliance state. * Define authentication models, rate limiting, and consumption patterns optimized for AI agent workloads. * Design and troubleshoot agentic systems and AI-powered platform environments. * Build and maintain agent-native APIs and integrations. Compliance Data & Security Modeling * Design and implement how security controls decompose from policy to implementation. * Define how evidence maps to compliance verdicts. * Ensure audit trails remain immutable, versioned, and OSCAL-aligned. * Build schemas, migrations, and query interfaces supporting compliance and audit requirements. * Develop data structures supporting control hierarchies, compliance relationships, lineage, and risk scoring. Enterprise Integration Engineering * Build integration services connecting: * Enterprise architecture platforms * ITSM systems * Cloud security tooling * Security data lakes * Create a coherent application identity and compliance graph across enterprise systems. * Develop and operate reconciliation logic to resolve competing data sources. Architecture & Technical Decision Ownership * Own Architectural Decision Records (ADRs) and technology selection. * Make and document decisions involving: * Protocols * Storage engines * Data formats * Deployment topology * Clearly document technical rationale for engineering teams and platform consumers. Inner-Source Platform Engineering * Design and implement contribution models that allow other security engineering teams to extend the platform. * Enable teams to add: * Evidence adapters * Control domains * Consumer integrations * Maintain architectural consistency and prevent platform drift. * Support developer experience, API documentation, and platform onboarding. Cross-Organizational Technical Leadership * Coordinate with: * Enterprise Architecture * Security Governance * Security Operations * Compliance * Define integration contracts, data-flow agreements, and adoption roadmaps. * Influence technical decisions through working code and design quality, not presentations alone. Scale & Performance Engineering * Design and implement multi-tenant consumption patterns. * Support high concurrency and low-latency query paths for AI agent consumers. * Ensure the platform can support production-scale enterprise adoption. Technical Skills & Expertise Distributed Systems & Platform Architecture * Enterprise-scale distributed systems architecture * High-availability patterns * Service mesh * Event-driven architectures * Multi-service coordination * Platform architecture * Infrastructure integration * Full-stack understanding across front-end and back-end development, Compliance & Data Architecture * NIST OSCAL, including experience across: * Catalog * Profile * Component Definition * SSP * Assessment Plan * Assessment Results * POA&M * Equivalent structured compliance standards * Immutable stores * Versioned records * Lineage tracking * Temporal queries Data Lake & Analytics * Object storage * Columnar formats such as Parquet/Iceberg * Query engines * Telemetry pipelines * Data lake architecture * Analytics architecture Graph & Compliance Modeling * Labeled property graphs * Ontology design * Lineage traversal * Control hierarchies * Compliance relationships Enterprise Integration * Enterprise architecture integration patterns * Application portfolio management platforms * CMDB reconciliation * Cross-system identity resolution * Application identity and compliance graph integration Inner-Source & Engineering Practices * Inner-source or open-source program design * Contribution models * Developer experience * API documentation * Platform onboarding * Architectural Decision Records (ADRs) * Cross-team technical communication, The role is best suited for an engineering leader who can operate across the full platform ecosystem - application development, distributed systems, infrastructure, security architecture, compliance, cloud, data, APIs, and AI/agentic systems - and can translate that breadth into a production-grade enterprise platform. ## Related Videos - [AI Won't Fix Your Engineering Culture](https://www.wearedevelopers.com/videos/100266-ai-won-t-fix-your-engineering-culture) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care)