Description
Amazon GuardDuty is a threat detection service that continuously monitors, analyzes, and processes AWS data sources and logs to identify unexpected, potentially unauthorized, and malicious activity within customer AWS environments. GuardDuty combines machine learning, anomaly detection, and malicious file discovery, using both AWS and third-party sources to help protect workloads and data across AWS accounts.
Amazon GuardDuty is seeking talented Software Development Engineers to join a team in our Los Angeles office!. In this role, you will design, build, and operate highly available, scalable distributed systems that power GuardDuty’s Malware protection and Runtime Monitoring products. You will work on challenging problems at the intersection of cloud security, distributed systems, and customer experience — building platforms that serve both internal teams and millions of external AWS customers.
You will be a hands-on engineer contributing to the full software development lifecycle — from requirements gathering and system design through implementation, testing, deployment, and operations. You will collaborate closely with security engineers, applied scientists, and product managers to deliver features that protect millions of AWS customers. This is a high-impact role where your work directly contributes to the security posture of AWS customers worldwide.
Key job responsibilities
– Design, develop, and maintain highly available, scalable distributed systems for GuardDuty’s Malware Protection and Runtime Monitoring services
– Build and operate metadata services that enrich data for internal GuardDuty teams
– Own and evolve the runtime agent provisioning and agent coverage platform across AWS compute services
– Own features end-to-end across the full software development lifecycle — from design through deployment and operations
– Effectively leverage AI-assisted development tooling to accelerate design, coding, testing, code review, and operational workflows while maintaining a high quality bar
– Write high-quality, testable code and participate in design and code reviews, using AI tooling to improve velocity and consistency without compromising correctness or security
– Troubleshoot and resolve complex production issues, driving root cause analysis and operational excellence — including using AI tooling to accelerate log analysis, hypothesis generation, and runbook execution
– Collaborate with security engineers, applied scientists, and product managers to define technical solutions
– Mentor junior engineers on engineering best practices, including responsible and effective use of AI tooling, and contribute to team-wide standards
– Contribute to operational excellence through on-call rotations, runbook development, and system monitoring
A day in the life
As an SDE II on this team, you spend your time designing, building, and operating distributed systems that protect AWS customers from runtime threats at massive scale.
On any given day, you might be drafting a design document for a new feature, diving deep into code, reviewing a teammate’s pull request, or debugging a production issue – using AI tooling along the way to move faster without cutting corners on quality.
You collaborate with security engineers, applied scientists, and product managers to understand their needs and build the right solutions. You participate in operational reviews, contribute to sprint planning, and mentor teammates as part of how the team operates.
The work is varied, fast-paced, and high-impact – every line of code you ship helps protect AWS customers.
About the team
Our team owns two of GuardDuty’s core threat detection products: Malware Protection, which scans EC2 workloads, S3 objects for malicious files and supporting AWS Backup and Runtime Monitoring, which uses an eBPF agent to detect threats in real time across EC2, ECS, Fargate, and EKS.
We work at the intersection of security research, distributed systems, and operating system internals – protecting AWS customers from the threats that target their compute and data.





