Amazon Leo is a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world.
We are looking for an Applied Scientist to join the founding cohort of the Engineering and R\&D team within Leo Infrastructure and IP Security. The team defends the manufacturing lines, launch sites, and global ground infrastructure behind the constellation from the most sophisticated threat actors on the planet. The data is unlike anything you have worked with: badge and door-access events, asset movement, network telemetry, and industrial control signals from factories, ground stations, and launch facilities, all of which must be modeled, baselined, and defended. You will build the statistical and behavioral models that separate threat actor behavior from the noise of a global operation, and the privacy-preserving data representations that let detection science scale without exposing sensitive data. This is an R\&D role with a production mandate: every model you build becomes part of the system Leo's security teams use to protect the constellation.
#### Export Control Requirement
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Key job responsibilities
- Build behavioral and statistical models that baseline normal activity across heterogeneous security telemetry, including specialized industrial-control and factory-floor data sources, so detections extend to new environments with low false-positive rates.
- Design privacy-preserving representations of sensitive security data, and verify that models and detections tuned against them remain accurate against the real data — turning data-protection guarantees into measurable, provable properties rather than assertions.
- Define the methodology and own the analysis for difficult, loosely defined problems: gather complex data across domains, select the right techniques from a range of data science methods, and justify your approach with evidence.
- Develop the metrics and evaluation frameworks that measure model and detection performance against threat actor behavior before a model is trusted in production.
- Contribute to the team's neurosymbolic reasoning platform, adapting state-of-the-art techniques from the literature and shipping components at production quality.
- Document your work with the rigor of a peer-reviewed publication, and communicate results clearly to both scientific and security-operations audiences.
A day in the life
You will move between analysis and production in the same week: profiling a telemetry source the team has never modeled, establishing what normal looks like for it, and shipping the baseline as a component detections build on. Security engineers on your team translate threat intelligence into the adversary behaviors that matter; you build and tune the models that detect those behaviors and evaluate model performance against them. You might spend a morning chasing a false-positive pattern to its statistical root cause, and the afternoon verifying that an anonymized dataset still preserves the signal a detection depends on. You will work semi-autonomously with guidance from senior scientists, backtest candidate detections against retained telemetry, and deliver scientific artifacts that ship.
About the team
Leo Infrastructure and IP Security protects the people, facilities, hardware, and supply chain behind a global satellite constellation. The Engineering and R\&D team within this organization builds the platforms and tooling the security pillar teams operate on, moving security operations from manual triage to correlation-based detection, automated response, and agentic AI. The team is composed of applied scientists, software engineers, and security engineers working across physical and digital security domains.
#### Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
#### Training & Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
#### Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.