> Markdown version of [/jobs/ext/3040190-security-engineering-lead-aws-security](https://www.wearedevelopers.com/jobs/ext/3040190-security-engineering-lead-aws-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineering Lead, AWS Security - **Company:** Amazon.com, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cyber Security, Cloud Services, Splunk - **Published:** September 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9184424/security-engineering-lead-aws-security ## About the Role Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance with the ability to successfully complete an Organisational Suitability Assessment. For more information regarding security clearances please visit (https://www.agsva.gov.au/)., Minimum 7+ years of experience in delivering cyber security solution to large enterprises or to Government customers. - Efficient time management skills are required along with the ability to deliver results in the face of uncertainty. - Proven ability to provide technical and strategic oversight for a high-performing team of security professionals. - Demonstrated experience creating effective security strategies that balance prevention and detection, drive risk reduction and mitigation. Preferred Qualifications - Masters' degree or PhD in Cybersecurity or related domain. - Worked on large-scale cloud programs to deliver security outcomes. ## Description AWS Security is looking for a Security Engineering Lead to join the team. You will be on a team responsible for conducting both pre and post launch testing, offensive campaigns, emergent threat modeling/testing, creating/maintaining automated threat emulation solutions, and helping security and service teams add offensive insight to their development, deployment, monitoring, and response processes. This team partners with the larger Security organisation and Service teams to continuously validate security throughout the service/system lifecycle. You will be an expert across multiple domains such as cyber security; threat, vulnerability and risk assessments (TVRA), security tools (e.g. Splunk, Crowdstrike, etc.), application of security frameworks (e.g. PSPF, ISM, NIST, etc.) and/or implementation and monitoring of cyber security controls (i.e. detection, protection, alerting, etc.) and will be sought out for advice on a range of technical and business related issues. Your role will help ensure that our systems and processes are secured against the latest threats and you will lead security testing of large Amazon projects while setting standards and defining best practices for the AWS Security team. You will proactively share knowledge across the Amazon community and will be a critical member of the organisation in one or more of the core areas of security. You will be expected to partner and align with other technical leaders and Principal Security Engineers from other geographic jurisdictions to leverage, extend and adapt critical security solution for the Australian region. You will collaborate closely with peers and other experts to deliver a sovereign security solution for Australia to address our country specific security controls., * Offering recommendations and fine-tuning findings to enhance threat mitigations, ensuring robust security measures are in place. * Setting a high standard and generating high-quality testing plans and reports, striving for excellence in security testing procedures. * Conducting offensive security testing and engaging in ongoing vulnerability research to proactively identify potential risks. * Systematically identifying vulnerabilities and meticulously tracking them to facilitate timely remediation efforts. * Staying ahead of emerging threats by continuously testing systems and applications for vulnerabilities that may arise. * Developing and maintaining automated solutions for emulating threats, enhancing efficiency and accuracy in threat detection. * Providing security training and conducting outreach sessions with internal development teams to raise awareness and foster a security-conscious culture. * Developing comprehensive security guidance documentation, including policies, procedures, and best practices, to serve as a reference for the organization. * Designing and building security tools tailored to the organization's needs, enhancing the overall security posture. * Delivering meaningful security metrics to stakeholders and continuously improving the metrics for better insight into the security landscape. A day in the life Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Conflicts should be addressed by listening, finding the best way forward and persuading one's colleagues. Successful engineers in this role will regularly analyze their own performance with a critical eye. A broad understanding of the AWS business and its interconnections is required. This position will also provide training, advice, and mentorship to other engineers throughout AWS. About the team Why Amazon Security At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores. The team is comprised of security professionals with a cross section of national security and private sector experience, providing a range of perspectives required for creative problem solving. We value diversity of thought, creativity, and a strong Bias for Action and Earn Trust. We believe that there are no "perfect" security solutions and we develop and iterate using a continuous improvement process. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)