Amazon logo

Security & Compliance Engineer

Amazon

On-site
Singapore
Full-time
Mid Level
Senior
2+ yrs
Salary not listedPosted 16h ago

Real job — pulled straight from Amazon’s careers page · Verified October 2, 2026 · No reposts.

Job description

Amazon is hiring a Security & Compliance Engineer — a full-time, based in Singapore role. Apply directly on Amazon's careers page below.

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Experience applying threat modeling or other risk identification techniques or equivalent
- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
- Experience writing for developer and technical audiences: blog, product documentation, technical information
- • Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or .NET.
- • Hands-on Infrastructure-as-Code skills in Terraform, AWS CDK, or CloudFormation.
- • Hands-on experience with AWS security and governance services: Config, Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch/EventBridge.
- • Experience deploying SCPs and RCPs in multi-account AWS Organizations.
- • Experience writing and deploying policy-as-code (cfn-guard, OPA Rego, Cedar, or equivalent).
- • Experience designing CI/CD pipelines for security or compliance control deployment.
- • Experience with AWS Control Tower customizations, Landing Zones, or Zero-Trust architectures.
- • Working knowledge of at least one compliance framework: SOC2, HIPAA, PCI-DSS, CIS, or NIST.
- • Experience producing audit-ready evidence and working with third-party assessors.
- • Spec-driven development; AI agentic design and Model Context Protocol (MCP) experience.
- • Industry and AWS certifications: AWS Solutions Architect Associate or Professional, AWS Security Specialty, CISSP, or equivalent.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
AWS Applied AI Solutions (AAIS) is building toward a future where every business innovates with Amazon AI teammates. To get there, we build AI solutions that improve human capabilities and transform entire business functions. We create end-to-end products that surprise and delight out-of-the-box, making complex things easy and hard things possible, with no cloud experience required. We start with customers who embrace the future and build bridges to meet the rest where they are. We pursue ambitious opportunities with conviction, and we are looking for builders who share that mindset.

AWS Security Assurance Services (SAS) is hiring a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solutions for highly regulated customers. You will own engineering deliverables across the full lifecycle - secure design, implementation, testing, deployment, and maintenance - translating compliance frameworks (SOC2, HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work autonomously within your team deliver cross-functional projects with partner teams and drive measurable risk reduction for customers at scale. You'll write code ship custom controls run security investigations lead design and code reviews on your team and mentor junior engineers. You will identify systemic issues propose pragmatic solutions and improve the team's mechanisms over time.

Key job responsibilities
• Lead threat modeling security design reviews and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.
• Design and implement custom preventive, detective, and proactive controls - Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard, OPA, Rego, Cedar), and automated remediation workflows.
• Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
• Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration.
• Write and review IaC scripts enforcements and detections in Python, Terraform, AWS CDK, CloudFormation, and Rego.
• Build continuous compliance monitoring automated evidence collection visualization reporting and remediation pipelines that hold up in audit.
• Integrate custom controls with AWS-native and third-party security and compliance tooling.
• Drive emerging-edge ideas into prototyping end-to-end to inform new security and compliance solutions and products.
• Identify risks and edge cases; propose implementation paths and go/no-go gates.
• Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn't possible.
• Help develop technical content.
• Identify cross-team patterns, gaps, and improvements.
• Travel to customer sites as needed.

About the team
Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve in the cloud.

Here at AWS, it's in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity and AmazeCon conferences, inspire us to never stop embracing our uniqueness.

We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.

Get Security & Compliance Engineer jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Ochsner Health logo

Application Developer, Apex/BI

New Orleans, LA
✓ From careers page· 22h ago
Eurofins Scientific logo

Infrastructure Database Engineer

Bengaluru, KA
✓ From careers page· 23h ago
Eurofins Scientific logo

Software Engineer

Bengaluru, KA
✓ From careers page· 23h ago
Eurofins Scientific logo

IT Database Administrator

Belo Horizonte, MG
✓ From careers page· 23h ago

Frequently asked questions

What skills are required for Security & Compliance Engineer at Amazon?

The required skills for Security & Compliance Engineer at Amazon include: Python, Ruby, Go, Java, .NET, C++, TypeScript, Node.js, Terraform, CloudFormation, Lambda, SOC 2, HIPAA, PCI DSS, NIST, AWS Certified Solutions Architect, CISSP, HTTP, DNS, TCP/IP, CI/CD, AI, Machine Learning.

What is the seniority level for Security & Compliance Engineer at Amazon?

Security & Compliance Engineer at Amazon is a Mid Level / Senior level position.

How do I apply for Security & Compliance Engineer at Amazon?

You can view the full description and apply for Security & Compliance Engineer at Amazon on EchoJobs: https://echojobs.io/job/amazon-security-compliance-engineer-aws-security-assurance-services-llc-3vjl1.