Demo

Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon Web Services (AWS)
Herndon, VA Full Time
POSTED ON 6/17/2026
AVAILABLE BEFORE 7/16/2026
Description

AWS Security Assurance Services (SAS) is hiring a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solutions for highly regulated customers. You will own engineering deliverables across the full lifecycle — secure design, implementation, testing, deployment, and maintenance — translating compliance frameworks (SOC2, HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work autonomously within your team, deliver cross-functional projects with partner teams, and drive measurable risk reduction for customers at scale.

You’ll write code, ship custom controls, run security investigations, lead design and code reviews on your team, and mentor junior engineers. You will identify systemic issues, propose pragmatic solutions, and improve the team’s mechanisms over time.

Key job responsibilities

  • Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.
  • Design and implement custom preventive, detective, and proactive controls — Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard, OPA Rego, Cedar), and automated remediation workflows.
  • Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
  • Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration.
  • Write and review IaC, scripts, enforcements and detections in Python, Terraform, AWS CDK, CloudFormation, and Rego.
  • Build continuous compliance monitoring, automated evidence collection, visualization, reporting, and remediation pipelines that hold up in audit.
  • Integrate custom controls with AWS-native and third-party security and compliance tooling.
  • Drive emerging-edge ideas into prototyping end-to-end to inform new security and compliance solutions and products.
  • Identify risks and edge cases; propose implementation paths and go/no-go gates.
  • Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn’t possible.
  • Help develop technical content
  • Identify cross-team patterns, gaps, improvements.
  • Travel to customer sites as needed.

About The Team

The AWS Security Assurance Services team, within AWS Support, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world’s workloads requires reliable delivery of bar-raising security outcomes and investment in security mechanisms and automation on behalf of our customers.

AWS Security Assurance Services LLC, a PCI-QSAC and HITRUST External Assessor Firm, is a team of industry-certified assessors and Compliance Engineers with DevOps and Cloud Infrastructure Architect backgrounds, helping our customers achieve, maintain, and automate compliance in the cloud by tying applicable audit standards to AWS service-specific features and functionality. The SAS team works with our largest enterprise customers to operationalize the shared responsibility model as they migrate to the cloud.

Basic Qualifications

  • 3 years of programming in Python, Ruby, Go, Swift, Java, .Net, C or similar object oriented language experience
  • 2 years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • 2 years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Knowledge of industry-based security vulnerabilities and remediation techniques
  • Experience conveying complex technical concepts to both technical and business audiences
  • Experience that includes strong analytical skills, attention to detail, and effective communication abilities, or experience in Linux OS and network troubleshooting and experience with threat modeling and penetration testing
  • Experience applying threat modeling or other risk identification techniques or equivalent
  • 3 years of security engineering or related security experience; Demonstrated ability to deliver security solutions independently within a team scope, handling the full development lifecycle: design, implementation, testing, deployment, and maintenance.
  • Demonstrated ability to write and review code, scripts, IaC, and detections in support of security defenses.
  • Demonstrated ability to mentor peers, drive consensus on conflicting design or implementation feedback, and provide meaningful review feedback.

Preferred Qualifications

  • 2 years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • 3 years of cloud based solution (AWS or equivalent), system, network and operating system experience, or AWS Professional level certification
  • Experience scripting languages and coding skills for one (1) or more of the following: Ruby, C/C /C#, Node.JS, Java, Python, and PHP
  • Experience with AWS technologies like Redshift, S3, AWS Glue, EMR, Kinesis, FireHose, Lambda, and IAM roles and permissions
  • Experience writing technical articles, speaking at technology conferences, and contributing to open source
  • Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST
  • Familiarity with AWS core services and at least one Infrastructure-as-Code tool (Terraform, AWS CDK, or CloudFormation).
  • Exposure to policy-as-code tools (cfn-guard, OPA Rego, Cedar, or equivalent).
  • Internships, projects, or coursework in cloud security, application security, or compliance automation.
  • Familiarity with multi-account AWS Organizations and Service Control Policies.
  • Industry or AWS certifications: AWS Certified AI Practitioner, AWS Solutions Architect Associate, AWS Security Specialty, or equivalent (or willingness to earn within the first year).

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, TN, Nashville - 137,600.00 - 184,000.00 USD annually

USA, TX, Austin - 159,300.00 - 202,400.00 USD annually

USA, TX, Dallas - 159,300.00 - 202,400.00 USD annually

USA, TX, Houston - 159,300.00 - 202,400.00 USD annually

USA, VA, Arlington - 159,300.00 - 202,400.00 USD annually

USA, VA, Herndon - 159,300.00 - 202,400.00 USD annually

USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually


Company - AWS Security Assurance Services LLC

Job ID: A10449506

Salary.com Estimation for Security & Compliance Engineer II, AWS Security Assurance Services, LLC in Herndon, VA
$94,737 to $118,341
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security & Compliance Engineer II, AWS Security Assurance Services, LLC?

Sign up to receive alerts about other jobs on the Security & Compliance Engineer II, AWS Security Assurance Services, LLC career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$83,089 - $102,314
Income Estimation: 
$109,654 - $138,234
Income Estimation: 
$104,823 - $128,381
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Amazon Web Services (AWS)

  • Amazon Web Services (AWS) Las Vegas, NV
  • DESCRIPTION The United States Air Force is at an inflection point. As it modernizes warfighting capabilities, accelerates data-driven decision-making, and ... more
  • 9 Days Ago

  • Amazon Web Services (AWS) Canton, MS
  • Description AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the peop... more
  • 9 Days Ago

  • Amazon Web Services (AWS) Canton, MS
  • Description This position involves leading teams in hardware and network diagnostics followed by physical repair and includes participation in an on-call r... more
  • 9 Days Ago

  • Amazon Web Services (AWS) Boardman, OR
  • Description Join our dynamic team and become a critical guardian of technological infrastructure! As a Data Center Engineering Technician, you'll play a pi... more
  • 9 Days Ago


Not the job you're looking for? Here are some other Security & Compliance Engineer II, AWS Security Assurance Services, LLC jobs in the Herndon, VA area that may be a better fit.

  • Amazon Web Services (AWS) Herndon, VA
  • Description AWS Security Assurance Services (SAS) is hiring an Associate Security & Compliance Engineer to help build and operate AWS security and complian... more
  • 1 Day Ago

  • Amazon Web Services (AWS) Herndon, VA
  • Description AWS Security Assurance Services (SAS) is hiring a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solut... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!