Principal Product Manager, Technical, Amazon Security Vulnerability Management Service (AVMS)
NewBe an early applicantAVMS’s mission is to be Earth’s best VM team, keeping customers safe and enabling software teams to build cool new innovations securely. We are looking for a Senior Manager of Security Engineering to take on this mission and our scale to make a profound impact across Amazon and its external customers.
We're hiring a Principal Product Manager to own the end-to-end product strategy from vulnerability ingestion and agentic evaluation, through asset scanning and detection, to automated mitigation and remediation. This is not incremental product work. You will define how Amazon transitions from human-speed, ticket-driven vulnerability response to machine-speed, automation-first security posture management.
Key job responsibilities
As a Principal Product Manager, you own the product from vision, strategy, roadmap, and outcomes. You will:
Define and drive the multi-year product strategy for AVMS, ensuring coherence across intake, scanning, detection, and remediation workstreams that today span multiple converging teams
Own the product vision for agentic vulnerability management, translating the shift from human-speed to machine-speed VM into concrete product requirements, milestones, and success metrics
Drive stakeholder alignment across Amazon Security, AWS, Stores, and subsidiary business lines, each with differentiated asset types, risk tolerances, and operational constraints
Define the product framework for vulnerability prioritization in an era where AI-generated findings demand a fundamentally new risk model beyond CVSS and EPSS alone
Own the builder experience end-to-end, ensuring that automated mitigation and remediation solutions reduce builder toil rather than create new friction, and that the path to adoption is clear and low-effort
Partner with engineering leadership to make tradeoffs between operational load and investment in the agentic platform
Define success metrics
Engage directly with CISO stakeholders, remediation operations teams, and software builders to understand their needs and translate them into product direction
A day in the life
What You'll Work On
Three forces define this problem space: AI is accelerating both attackers and defenders. Exploit chains are now quicker than ever, vulnerability volume is growing with no signs of slowing. The diversity of Amazon's asset footprint demands solutions that work across fundamentally different compute models. You will own the product vision that ties all of this together.
The scope spans:
Intake & Orchestration — An agentic vulnerability evaluation framework that ingests signals beyond CVEs (threat intelligence, code commits, public PoCs, AI-generated findings) and processes them at machine speed
Asset Scanning Platform — 100% visibility across all Amazon assets including hosts, containers, client devices, and operational technology, modernized for context-aware, chain-aware detection
Detection Development — Scalable, automatically generated detections that account for multi-vulnerability exploit chains, not just single-issue pattern matching
Mitigation & Remediation — Automated patching triggered by update availability (not ticket creation), curated image vending, builder-facing agents that drive remediation without human intervention, and integration with partner mechanisms across Amazon Security
Stakeholder & Partner Integration — Product interfaces with software builder teams and security management systems
About the team
AVMS is an international organization. We are the convergence of Amazon's vulnerability management organizations of security engineers, software engineers, data engineers, and product managers chartered together to solve machine-speed vulnerability management at Amazon scale.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.