Sr Security Engineer, Network, Leo Security

Amazon.com, Inc.
Herndon, VA, United States
6 days ago
Apply on www.amazon.jobs
Prepare application

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$178,400.0 - $226,700.0
Working hours
Regular working hours

Tech stack

User Authentication Command-Line Interface Code Review Cyber Security Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Supervisory Control and Data Acquisition (SCADA) Identity and Access Management Internet Protocol Security (IP SEC) Network Security Network Architecture Network Protocols
+9 more
Secure Coding Service-Oriented Architecture Software Engineering TCP/IP Web Services Scripting Amazon Virtual Private Cloud (VPC) Programming Languages Microservices

Job description

Amazon Leo is a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world. We are looking for a senior security engineer to join the Leo Infrastructure and IP Security team. The team defends the manufacturing lines, launch sites, and global ground infrastructure behind the constellation from the most sophisticated threat actors on the planet. You will own network security across Leo’s heterogeneous environments - corporate IT, manufacturing OT/SCADA, lab, launch operations, and global ground stations - defining the security bar for every network deployment and driving detection coverage from concept to production.

Export Control Requirement

Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Key job responsibilities A Security Engineer in Amazon will be strong in multiple security domains and sought out for advice on technical issues. You will be on a team of security engineers focusing on the security of Leo’s networks.

Analyze and deploy detections to production networks, leveraging automation and tooling to identify vulnerabilities and surface security events.

Conduct threat modeling for network deployments across environments and locations, including OT/ICS topologies.

Build and maintain a network security assessment framework that holds each deployment type - including OT/SCADA environments - to a consistent bar.

Translate network and OT/ICS security risks into findings with clear severity and business impact; communicate them to security leadership and drive mitigations.

Develop and maintain security documentation: network security standards, assessment runbooks, and detection coverage maps.

Partner with infrastructure and site operations teams to implement network security mitigations and hardening measures.

Contribute to incident response when network-based threats are detected, including containment, investigation, and post-incident improvement.

A day in the life One morning you might be reviewing a network architecture proposal for a new ground station deployment, defining the segmentation and monitoring requirements before the first switch is racked. That afternoon, a detection fires on anomalous lateral movement in a manufacturing network - you triage it, determine whether it’s a misconfigured industrial controller or something worse, and drive the response. The next day you could be leading a threat model for a new OT protocol integration at a launch site. When you’re not responding to active events, you will be evaluating Leo’s network security posture end-to-end: identifying architectural weaknesses, proposing new detection initiatives, and driving cross-team programs that raise the bar across every site type.

You will have the freedom to prioritize as needed to balance your personal life, professional growth, and the delivery of your assigned projects.

About the team Leo Infrastructure and IP Security protects the people, facilities, hardware, and supply chain behind a global satellite constellation. The network security function within this team owns detection, assessment, and hardening of Leo’s IT and OT networks across lab, manufacturing, launch, and ground station environments. The team works with automation and tooling to move from reactive triage to proactive detection coverage and continuous posture measurement. You will work alongside security engineers, software engineers, and applied scientists who are building the platforms these capabilities run on.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Requirements

5+ years of scripting, programming, and security code review in a common programming language (non-internship) experience

  • 5+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Bachelor’s degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
  • Knowledge of industry-based security vulnerabilities and remediation techniques
  • Experience with network security, including one or more of: network architecture review, segmentation, firewall/ACL management, network detection, or network incident response, Experience with security in service-oriented architectures/microservices and web services
  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Experience in security operations, risk management, and incident response
  • Experience with OT/ICS/SCADA network security, including segmentation between IT and OT environments
  • Experience with network detection and response (NDR) tools, network telemetry analysis, or packet-level investigation
  • Experience with network security in manufacturing, critical infrastructure, or industrial environments
  • Experience with AWS networking and security services (VPC, Security Groups, Transit Gateway, GuardDuty, CloudTrail)

Benefits & conditions

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, VA, Arlington - 178,400.00 - 226,700.00 USD annually USA, VA, Herndon - 178,400.00 - 226,700.00 USD annually USA, WA, Bellevue - 178,400.00 - 226,700.00 USD annually USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.amazon.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all