Applied Scientist, Secure 3p Tools

Amazon Amazon · Big Tech · Austin, TX · Applied Science

Applied Scientist role focused on leveraging GenAI and agentic AI to enhance third-party security risk management. The role involves building agentic frameworks, RAG pipelines, and ML-powered risk intelligence capabilities to automate vendor assessments and improve threat detection. Collaboration with Software and Data Engineering is required for production deployment.

What you'd actually do

  1. Own and drive end-to-end technical delivery for scoped science initiatives focused on third-party security risk management, independently defining research agendas, success metrics, and multi-quarter roadmaps with minimal oversight.
  2. Understanding approaches to automate third-party security review processes using state-of-the-art large language models, development intelligent systems for vendor assessment document analysis, security questionnaire automation, risk signal extraction, and compliance decision support.
  3. Build advanced GenAI and agentic frameworks including multi-agent orchestration, RAG pipelines, and autonomous workflows purpose-built for third-party risk evaluation, security documentation processing, and scalable vendor assessment at enterprise scale.
  4. Build ML-powered risk intelligence capabilities that enhance third-party threat detection, vulnerability classification, and continuous monitoring throughout the vendor lifecycle.
  5. Coordinate with Software Engineering and Data Engineering to deploy production-grade ML solutions that integrate seamlessly with existing third-party risk management workflows and scale across the organization.

Skills

Required

  • Experience programming in Java, C++, Python or related language
  • Experience with SQL and an RDBMS (e.g., Oracle) or Data Warehouse

Nice to have

  • Experience implementing algorithms using both toolkits and self-developed code
  • Have publications at top-tier peer-reviewed conferences or journals

What the JD emphasized

  • minimal oversight
  • enterprise scale

Other signals

  • Leveraging large language models and agentic AI to transform third-party security risk management
  • Automate complex vendor assessments, streamline controllership processes, and dramatically reduce assessment cycle times
  • Build advanced GenAI and agentic frameworks including multi-agent orchestration, RAG pipelines, and autonomous workflows
  • Build ML-powered risk intelligence capabilities that enhance third-party threat detection, vulnerability classification, and continuous monitoring