Amazon Route 53 has an open position for a Software Development Engineer in Arlington, VA to join the team that designs, builds and operates Route 53 Resolver DNS Firewall and Route 53 Profiles.
We're looking for a mid-level Software Development Engineer to join our team. The team manages cloud-native DNS security and DNS resource management services that protect millions of VPCs from malicious domain activity and enable customers to centrally manage DNS configurations across their multi-account environments. You will be part of the team that ensures that DNS traffic is inspected, filtered, and governed securely, reliably, and at scale for enterprise customers running workloads across VPCs, hybrid networks, and multi-account organizations. Along with the team you will design and build new solutions for the services, models for detecting new threats and attacks by working with stakeholders across the company and with our external partners.
Key job responsibilities
As an SDE, you will work across the entire stack—control plane, data plane, API surfaces, and deep integrations with Route 53 Resolver, VPC networking, Private Link, AWS RAM, AWS Firewall Manager, and AWS Organizations. You will design and build advanced detection features, enhance configurability for customers, and help architect next-generation protections including agentic attack prevention capabilities. You will also help drive system architecture, spearhead best practices that enable a quality product, and help coach and develop junior engineers. A successful candidate will have an established background in engineering large-scale distributed systems or networking software, great communication skills, and a motivation to achieve results in a fast-paced environment.
A day in the life
At Amazon Web Services, we like to "work backwards": we start by understanding what customers need and use that to guide our software engineering. We're looking for a software engineer who is experienced in listening to customers, synthesizing their needs, and rapidly iterating our services to quickly put features into customers' hands. Our best ideas become even better when we get feedback from real customer use. The sooner we can get that feedback, the more quickly we can grow.
On a typical day, you might investigate a DNS threat pattern to improve detection accuracy, prototype a new filtering capability, instrument code to report security metrics, collaborate with partner teams on integration designs, code up a feature for centralized profile management, or draft a proposal for a new agentic protection capability.
About the team
This team designs, builds and operates the high availability enterprise scale DNS Firewall service along with Route 53 Profiles. DNS Firewall provides DNS-layer protection natively using models designed and built by the team and through partnerships with major DNS security providers. Route 53 Profiles enables customers to apply DNS-related configurations—including Resolver rules, DNS Firewall rule groups, and private hosted zone associations—across multiple VPCs with a single, shareable configuration. Together, these services form a critical part of AWS's network security and governance story, serving customers ranging from startups to the largest enterprises.