Rodeo
ResourcesPartnersSign in

Amazon Web Services (AWS)

Sr. Sec & Compliance Engineer, AWS Security Assurance Services, LLC

London
Posted 1 day ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Description

AWS Security Assurance Services (SAS) is hiring a Senior Security & Compliance Engineer to lead the design, deployment, and implementation of complex AWS security and compliance solutions that accomplish customer-defined business and security outcomes, solving for new levels of scale, complexity, and performance. You will build custom security controls, AI-enabled automation and tooling that translate security and compliance frameworks into secure-by-design implementations on AWS. You will innovate on behalf of AWS’s most highly regulated customers, design and build controls, write code, lead reviews, automate remediations, and own security risk identification, mitigation, and engineering outcomes that span beyond a single team, leading development of the security and compliance solutions and products.

Key Job Responsibilities

  • Own design and architecture choices for security and compliance automation solutions for regulated customers and influence partner-org design and deliverables.
  • Engineer and lead AI-enabled automations, threat modeling, design reviews.
  • Build secure-by-design IaC modules for Landing Zones, Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
  • Lead the design, deployment, and implementation of AWS security controls, continuous compliance monitoring, evidence collection, and remediation of insecure configurations to scale with automation.
  • Architect custom preventive, detective, and proactive controls, SCPs, RCPs, policy-as-code (cfn-guard, OPA Rego, Cedar).
  • Set high bar for authentication and authorization, data protection, least privilege, encryption, micro-segmentation, tagging strategy, integrations via API and MCP, and secure AI agentic design.
  • Write and review scripts, and IaC (Python, Terraform, AWS CDK, CloudFormation, Rego).
  • Lead exploratory POCs on emerging technologies. Define the hypothesis, success criteria, and go/no-go gates.
  • Lead alignment, resolve escalations, troubleshooting, and root-cause analysis to closure.
  • Lead the development of technical content.
  • Communicate security risk and design decisions clearly verbally and in writing to technical, non-technical, and C-level audiences.
  • Identify and shape sales opportunities. Influence service-team roadmaps and SAS offering strategy.
  • Travel to customer sites as needed.

About The Team

The AWS Security Assurance Services team, within AWS Support, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world’s workloads and building a brighter future for humanity requires reliable delivery of bar-raising security outcomes and investment in security mechanisms and automation on behalf of our customers. AWS Security Assurance Services LLC, a PCI-QSAC (Payment Card Industry-Qualified Security Assessor company) and HITRUST External Assessor Firm, is a team of industry-certified assessors and Security and Compliance Engineers helping our customers achieve, maintain, and automate compliance in the cloud by tying applicable audit standards to AWS service features and functionality. The team works with AWS’s largest enterprise customers to operationalize the shared responsibility model as they migrate to the cloud.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Basic Qualifications

  • Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go.
  • Bachelor's degree or above in computer science, engineering, mathematics or equivalent, or experience working in Science, Technology, Engineering, or Mathematics (STEM).
  • Experience managing full application stacks from the OS up through custom applications, or experience working with REST API based services and experience with threat modeling and penetration testing.
  • 5+ years of work in identifying security issues and risks, and developing mitigation plans experience.
  • 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience.
  • 4+ years of cloud architecture and solution implementation experience, or US government security clearance of top secret or above.

Preferred Qualifications

  • Experience applying threat modeling or other risk identification techniques or equivalent.
  • Experience with security in service-oriented architectures/microservices and web services.
  • Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls.
  • Experience developing, deploying and managing AI products at scale.
  • Experience in security or compliance consulting or advisory work in support of a highly technical environment.
  • Experience designing or architecting (design patterns, reliability and scaling) of new and existing systems.
  • Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST.
  • Experience with security in service-oriented architectures/microservices and web services.
  • 8+ years as a technical specialist, including 5+ years in secure coding, software development, cloud security engineering or related work.
  • Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or.NET.
  • Advanced Infrastructure-as-Code proficiency in Terraform, AWS CDK, and/or CloudFormation.
  • Expert-level configuration and architectural experience with AWS security and governance services: Config, GuardDuty, Security Hub, Control Tower, Systems Manager, KMS, IAM, VPC, Lambda, CloudTrail, CloudWatch, EventBridge.
  • Track record of deploying SCPs and RCPs in multi-account AWS Organizations at enterprise scale.
  • Experience writing and deploying reusable policy-as-code patterns (cfn-guard, OPA Rego, Cedar, or equivalent).
  • Industry and AWS certifications: CISSP, GCIH (GIAC Certified Incident Handler), GSEC (GIAC Security Essentials), Security+, AWS Solutions Architect Professional, AWS Security Specialty strongly preferred; additional certifications are a plus.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy_page) to know more about how we collect, use and transfer the personal data of our candidates.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Company - AWS EMEA SARL (UK Branch)

Job ID: A10455265

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Security Engineering
Compliance Automation
Cloud Architecture
Python
Terraform
AWS CDK
CloudFormation
Infrastructure as Code
Threat Modeling
Policy as Code
Zero Trust Architecture
Identity and Access Management
Data Protection
AI Security
Incident Response
Penetration Testing

Location

London, England, United Kingdom

Sign up to applySee more jobs like this