Amazon is seeking an experienced Senior Security Engineer to join their AI Red Team within Threat Operations. The role involves conducting offensive security operations targeting AI systems, performing security research, and collaborating with teams to enhance AI security posture.
Responsibilities:
- Conducting Red Team operations targeting AI assets including training pipelines, inference systems, model architectures, and supporting infrastructure
- Performing offensive security research focused on threats to AI systems, AI supply chain security, and AI-enabled threat actor tradecraft
- Discovering and exploiting vulnerabilities in AI infrastructure, applications, and supporting systems through hands-on security testing
- Developing automated tools and solutions for threat emulation and scaling offensive security capabilities
- Analyzing security findings and providing detailed technical recommendations to engineering teams for remediation
- Collaborating with security engineers and research scientists to advance AI security research and translate findings into practical risk insights
- Simulating sophisticated threat actor techniques to validate detection and response capabilities
- Contributing to the development of security metrics and reporting frameworks that demonstrate program effectiveness
- Supporting cross-organizational security initiatives to assess vulnerabilities introduced by growing reliance on AI
Requirements:
- Experience working in identifying security issues and risks, and developing mitigation plans
- Minimum 5+ years of experience in offensive security testing, penetration testing, or security research
- Hands-on experience with vulnerability discovery, exploitation, and lateral movement techniques
- Strong understanding of cloud security, network security, and application security principles
- Experience with scripting and automation using Python, Go, or similar languages
- 7+ years of experience in offensive security or related security engineering roles
- Experience with AI/ML security, including threats to AI systems, adversarial machine learning, or AI supply chain security
- Track record of building security tools or automation that scales across organizations
- Experience with Red Team operations, threat-based assessments, or security research programs
- Deep technical knowledge of cloud platforms (AWS, Azure, GCP) and container technologies
- Experience with distributed systems, training infrastructure, or inference optimization
- Demonstrated ability to translate complex technical findings into clear recommendations for diverse audiences
- Contributions to security research community through publications, presentations, or open-source tools
- Understanding of threat actor tradecraft and ability to emulate sophisticated attack techniques
- Experience working with cross-functional teams to drive security improvements