Senior Security Engineer, AI Platforms

Dx1 Au — Australia · Posted ~16 hours ago

Senior

Skills

Cloud security DevSecOps AWS Infrastructure as code CI/CD security Security automation AI security Access controls Security policies Amazon Bedrock Bedrock AgentCore CI/CD

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security engineer will secure cloud platforms and agentic AI workloads through DevSecOps practices. Responsibilities include building self-service delivery pipelines, enforcing security and policy checks, automated deployment with audit trails, and establishing access controls, guardrails, logging, and cost boundaries for AI workloads on AWS.

Highlights

Senior security engineering role focused on securing cloud platforms and AI workloads. The position combines DevSecOps, infrastructure as code, automated delivery, policy enforcement, auditability, access controls, guardrails, logging, and cost boundaries for modern AI systems.

Description

A security engineer who works within our FDE squads, securing platforms and agentic workloads using DevSecOps and AI-DLC practices. About The Role You will join a team of FDEs consisting of cloud, platform, DevSecOps and AI security engineers and focus on two areas of work. Path to production. Design and build self-service delivery: changes raised as pull requests, security and policy checks in the pipeline, peer approval, and automated deployment, with an audit record at every step. AI Hub and agentic foundations on AWS. Building platforms for AI workloads and agents on Amazon Bedrock and Bedrock AgentCore, covering model and tool access controls, guardrails, logging and cost boundaries. Delivery is infrastructure as code, with security controls in the platform layer and in the CI/CD that feeds it. AI-first ways of working. You use coding agents to write infrastructure, policies, tests and pipeline code, and follow AI-DLC practices: specs and plans before code, human approval at each gate, and a trace from each requirement to the control that enforces it. Working with AI squads. You sit inside squads of ML engineers, application developers and platform engineers. You threat model agent designs before the build starts, build the paved roads the squads deploy through, and approve new tools and data sources before agents can reach them. What You Will Do Design and build CI/CD pipelines (GitHub Actions, GitLab CI or Harness) with security scanning, policy checks and approval gates built in.Write Terraform or AWS CDK for multi-account AWS environments, including landing zone guardrails such as SCPs and permission boundaries.Threat model LLM and agent applications with the squads building them (STRIDE, MITRE ATLAS), and turn the findings into controls and tests.Turn written security policies into policy as code (OPA/Rego, Checkov, cfn-guard, AWS Config rules, Cedar) and enforce it in the pipeline and at runtime.Map each automated control to the requirement it satisfies, so risk and audit teams can trace coverage without asking you.Build platform-level controls: centralised logging and audit trails (CloudTrail, CloudTrail Lake, Security Hub), authenticated requests (OIDC federation, short-lived credentials) and source validation (branch protection, signed commits, artefact signing and provenance).Govern agent access to tools and data: least-privilege scopes, an approval path for new MCP servers and tools, AgentCore Identity, Gateway and Policy, and Bedrock Guardrails.Set data boundaries for AI workloads: PII handling in prompts and logs, VPC endpoints for Bedrock, KMS on invocation logs and classification of RAG sources.Add AI release gates to the pipeline: guardrail tests, prompt injection suites and eval regressions that block a release.Detect agent misbehaviour at runtime with alerts on policy denials and anomalous tool calls, and own the incident runbook for AI workloads.Run a security exceptions process where each exception has an owner, an expiry date and a record in code.Use AI coding agents and AI-assisted code review in your own work, and coach engineers to do the same with approval gates on agent output.Work with platform, security and architecture teams: run workshops, write handover material and explain trade-offs to engineers and security leads. Must have 5+ years in cloud, platform or DevSecOps engineering.CI/CD you designed and owned in production, with security scanning (SAST, SCA, secrets, container and IaC) and the decisions on what blocks a merge.Terraform or CDK across multiple AWS accounts, with hands-on IAM, Organizations and SCPs, networking, KMS, CloudTrail, Config and Security Hub.Threat modelling for LLM and agent applications: prompt injection, tool abuse and data exfiltration through tool calls.Least-privilege identity for agents and the tools they call, with authenticated requests, source validation and centralised audit trails.Policy as code, including turning written security policies or requirements into AWS automation.Mapping automated controls to security and governance requirements, or to a framework such as ISO 27001, Essential Eight, APRA CPS 234 or SOC 2.A self-service engineering model in production: engineers raise changes as GitHub pull requests, peers review and approve them, and automation deploys them with no manual ServiceNow step.Weekly use of AI coding tools (Claude Code, Kiro, Amazon Q Developer, Cursor or Copilot) on real delivery work, with a clear view of where they get things wrong. Good to have Amazon Bedrock and Bedrock AgentCore in a production environment.AI evals and red-teaming run as pipeline gates.Building agents or MCP servers yourself.AI governance frameworks: ISO/IEC 42001, NIST AI RMF or Australia's Voluntary AI Safety Standard.Cloud-native policy as code: Cedar, AWS Config conformance packs, SCP and RCP design.Wiz or another CSPM or CNAPP platform.Security exemption and exception management.AWS AI-DLC or another spec-driven way of working with coding agents.Software supply chain security: SBOMs, Sigstore or cosign, SLSA provenance.Consulting or other client-facing delivery.AWS Certified Security Specialty or DevOps Engineer Professional. Our strongest engineers combine cloud engineering, security and automation. You can read a control requirement from a client's risk team, write the policy that enforces it, ship it through a pipeline and show an auditor the evidence. Your first six months You have delivered a path to production uplift, with deployment live and policy checks blocking non-compliant changes.An agentic workload has gone live with a threat model you wrote alongside its squad, and the controls from it run in the pipeline.Part of an AI platform on AWS that you built is live, with identity, guardrails and audit logging in the first release.