Protect the HR and Legal applications millions of Amazonians trust with their most sensitive data. You will join a team that is replacing traditional security reviews with continuous automated evaluation and learning to secure a new generation of GenAI and agentic applications.
Key job responsibilities
● Execute security assessments and code reviews for HR and Legal applications using your team's established processes and tooling, primarily in Java, Python, and JavaScript.
● Contribute to threat models for the applications in your domain, learning to identify the risks that matter most to customers with guidance from senior engineers.
● Help author and refine automated detection rules that catch risks at code commit and give builders clear remediation guidance.
● Support builder teams in adopting secure-by-default infrastructure, learning how paved paths prevent entire categories of issues.
● Investigate security findings, confirm their impact, and work with builders to drive remediation while the code context is fresh.
● Contribute to security automation and tooling that reduces manual effort across the team.
● Document your work clearly so other engineers can understand and build on it.
● Communicate security risk for the problems you work on to your team and direct leadership, in writing and verbally.
A day in the life
On a given day you might review code for a new feature in an HR or Legal application, triage a security finding and walk a builder through the fix, contribute a detection rule that closes a gap the team identified, or pair with a senior engineer to threat model a service that uses GenAI. You will ask a lot of questions, and that is expected. The team values curiosity, clear communication, and a willingness to dig into unfamiliar problems.
About the team
SEALS is a team of security engineers and managers embedded with the development teams that build Amazon's HR and Legal applications. Your colleagues partner directly with builders, reviewing designs and writing detections so security feedback arrives while the code is still fresh. You will collaborate with peer security teams covering finance and communications technology when risks cross domain boundaries. The portfolio is adopting GenAI and agentic capabilities fast, so the security problems are changing in real time. We value clear thinking over heroics, sustainable pace over crunch, and invest equally in technical and management career paths.