At a Glance
- Tasks: Lead the design and implementation of AWS security solutions for top-tier clients.
- Company: Join AWS Security Assurance Services, a leader in cloud security.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on cutting-edge technology and career advancement.
- Why this job: Make a real impact by innovating security solutions for highly regulated customers.
- Qualifications: Experience in programming, cloud architecture, and security risk management required.
The predicted salary is between 63000 - 77000 £ per year.
AWS Security Assurance Services (SAS) is hiring a Senior Security & Compliance Engineer to lead the design, deployment, and implementation of complex AWS security and compliance solutions that accomplish customer-defined business and security outcomes, solving for new levels of scale, complexity, and performance. You will build custom security controls, AI-enabled automation and tooling that translate security and compliance frameworks into secure-by-design implementations on AWS. You will innovate on behalf of AWS’s most highly regulated customers, design and build controls, write code, lead reviews, automate remediations, and own security risk identification, mitigation, and engineering outcomes that span beyond a single team, leading development of the security and compliance solutions and products.
Key job responsibilities:
- Own design and architecture choices for security and compliance automation solutions for regulated customers and influence partner-org design and deliverables.
- Engineer and lead AI-enabled automations, threat modeling, design reviews.
- Build secure-by-design IaC modules for Landing Zones, Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
- Lead the design, deployment, and implementation of AWS security controls, continuous compliance monitoring, evidence collection, and remediation of insecure configurations to scale with automation.
- Architect custom preventive, detective, and proactive controls, SCPs, RCPs, policy-as-code (cfn-guard, OPA Rego, Cedar).
- Set high bar for authentication and authorization, data protection, least privilege, encryption, micro-segmentation, tagging strategy, integrations via API and MCP, and secure AI agentic design.
- Write and review scripts, and IaC (Python, Terraform, AWS CDK, CloudFormation, Rego).
- Lead exploratory POCs on emerging technologies. Define the hypothesis, success criteria, and go/no-go gates.
- Lead alignment, resolve escalations, troubleshooting, and root-cause analysis to closure.
- Lead the development of technical content.
- Communicate security risk and design decisions clearly verbally and in writing to technical, non-technical, and C-level audiences.
- Identify and shape sales opportunities. Influence service-team roadmaps and SAS offering strategy.
- Travel to customer sites as needed.
About the team:
The AWS Security Assurance Services team, within AWS Support, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world’s workloads and building a brighter future for humanity requires reliable delivery of bar-raising security outcomes and investment in security mechanisms and automation on behalf of our customers. AWS Security Assurance Services LLC, a PCI-QSAC (Payment Card Industry-Qualified Security Assessor company) and HITRUST External Assessor Firm, is a team of industry-certified assessors and Security and Compliance Engineers helping our customers achieve, maintain, and automate compliance in the cloud by tying applicable audit standards to AWS service features and functionality. The team works with AWS’s largest enterprise customers to operationalize the shared responsibility model as they migrate to the cloud.
Basic qualifications:
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go.
- Bachelor's degree or above in computer science, engineering, mathematics or equivalent, or experience working in Science, Technology, Engineering, or Mathematics (STEM).
- Experience managing full application stacks from the OS up through custom applications, or experience working with REST API based services and experience with threat modeling and penetration testing.
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience.
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience.
- 4+ years of cloud architecture and solution implementation experience, or US government security clearance of top secret or above.
Preferred qualifications:
- Experience applying threat modeling or other risk identification techniques or equivalent.
- Experience with security in service-oriented architectures/microservices and web services.
- Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls.
- Experience developing, deploying and managing AI products at scale.
- Experience in security or compliance consulting or advisory work in support of a highly technical environment.
- Experience designing or architecting (design patterns, reliability and scaling) of new and existing systems.
- Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST.
- 8+ years as a technical specialist, including 5+ years in secure coding, software development, cloud security engineering or related work.
- Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or .NET.
- Advanced Infrastructure-as-Code proficiency in Terraform, AWS CDK, and/or CloudFormation.
- Expert-level configuration and architectural experience with AWS security and governance services: Config, GuardDuty, Security Hub, Control Tower, Systems Manager, KMS, IAM, VPC, Lambda, CloudTrail, CloudWatch, EventBridge.
- Track record of deploying SCPs and RCPs in multi-account AWS Organizations at enterprise scale.
- Experience writing and deploying reusable policy-as-code patterns (cfn-guard, OPA Rego, Cedar, or equivalent).
- Industry and AWS certifications: CISSP, GCIH (GIAC Certified Incident Handler), GSEC (GIAC Security Essentials), Security+, AWS Solutions Architect Professional, AWS Security Specialty strongly preferred; additional certifications are a plus.
Sr. Sec & Compliance Engineer, AWS Security Assurance Services, LLC in London employer: AmazonWebServices
At Amazon Web Services (AWS), we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. As a Senior Delivery Consultant (DevOps) in the UK, you'll have the opportunity to work closely with diverse clients, driving their cloud success while benefiting from extensive mentorship and professional growth opportunities. Our commitment to inclusion and employee empowerment ensures that every team member can thrive and contribute meaningfully to our mission of delivering cutting-edge cloud solutions.
StudySmarter Expert Advice🤫
We think this is how you could land Sr. Sec & Compliance Engineer, AWS Security Assurance Services, LLC in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including AmazonWebServices, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through AmazonWebServices
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at AmazonWebServices. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Sr. Sec & Compliance Engineer, AWS Security Assurance Services, LLC in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at AmazonWebServices insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to AmazonWebServices that you’re committed to staying ahead in the game.
How to prepare for a job interview at AmazonWebServices
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at AmazonWebServices to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at AmazonWebServices.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.