Amazon

Principal Product Manager, Technical, Amazon Security Vulnerability Management Service (AVMS)

Amazon Austin, Texas, United States · $180K–$243K/yr

Software Development · 10,001+ employees

Yesterday
product-manager Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will define and drive the multi-year product strategy for Amazon's Vulnerability Management Service, transitioning from manual processes to machine-speed automation. You will own the end-to-end product vision, roadmap, and stakeholder alignment across diverse business lines including AWS and retail.

What they look for

Product strategy Roadmap development Technical product management Stakeholder management Security engineering Vulnerability management Automation Risk modeling Cloud security Agentic evaluation Data analysis Process improvement Cross-functional leadership Strategic planning Security posture management

Requirements

Candidates must have a bachelor's degree and extensive experience in technical product management, roadmap strategy, and influencing senior stakeholders. Proven ability to lead engineering discussions regarding technology decisions and strategy is essential.

Benefits

Health insurance Dental insurance Vision insurance Prescription coverage Basic life and AD&D insurance Supplemental life plans Employee assistance program Mental health support Medical advice line Flexible spending accounts Adoption and surrogacy reimbursement 401(k) matching Paid time off Parental leave Restricted stock units Sign-on payments

Full description

Amazon Security's Vulnerability Management Service (AVMS) manages the entire vulnerability management (VM) program across Amazon’s retail business special teams, and AWS. AVMS operates at an unprecedented asset scale, as well as diversity of business lines ranging from Cloud, Health Care, Payments, Devices, Fulfillment, and even drones!

AVMS’s mission is to be Earth’s best VM team, keeping customers safe and enabling software teams to build cool new innovations securely. We are looking for a Senior Manager of Security Engineering to take on this mission and our scale to make a profound impact across Amazon and its external customers.

We're hiring a Principal Product Manager to own the end-to-end product strategy from vulnerability ingestion and agentic evaluation, through asset scanning and detection, to automated mitigation and remediation. This is not incremental product work. You will define how Amazon transitions from human-speed, ticket-driven vulnerability response to machine-speed, automation-first security posture management.

Key job responsibilities As a Principal Product Manager, you own the product from vision, strategy, roadmap, and outcomes. You will:

Define and drive the multi-year product strategy for AVMS, ensuring coherence across intake, scanning, detection, and remediation workstreams that today span multiple converging teams

Own the product vision for agentic vulnerability management, translating the shift from human-speed to machine-speed VM into concrete product requirements, milestones, and success metrics

Drive stakeholder alignment across Amazon Security, AWS, Stores, and subsidiary business lines, each with differentiated asset types, risk tolerances, and operational constraints Define the product framework for vulnerability prioritization in an era where AI-generated findings demand a fundamentally new risk model beyond CVSS and EPSS alone

Own the builder experience end-to-end, ensuring that automated mitigation and remediation solutions reduce builder toil rather than create new friction, and that the path to adoption is clear and low-effort

Partner with engineering leadership to make tradeoffs between operational load and investment in the agentic platform

Define success metrics

Engage directly with CISO stakeholders, remediation operations teams, and software builders to understand their needs and translate them into product direction

A day in the life What You'll Work On

Three forces define this problem space: AI is accelerating both attackers and defenders. Exploit chains are now quicker than ever, vulnerability volume is growing with no signs of slowing. The diversity of Amazon's asset footprint demands solutions that work across fundamentally different compute models. You will own the product vision that ties all of this together.

The scope spans: Intake & Orchestration — An agentic vulnerability evaluation framework that ingests signals beyond CVEs (threat intelligence, code commits, public PoCs, AI-generated findings) and processes them at machine speed

Asset Scanning Platform — 100% visibility across all Amazon assets including hosts, containers, client devices, and operational technology, modernized for context-aware, chain-aware detection

Detection Development — Scalable, automatically generated detections that account for multi-vulnerability exploit chains, not just single-issue pattern matching

Mitigation & Remediation — Automated patching triggered by update availability (not ticket creation), curated image vending, builder-facing agents that drive remediation without human intervention, and integration with partner mechanisms across Amazon Security

Stakeholder & Partner Integration — Product interfaces with software builder teams and security management systems

About the team AVMS is an international organization. We are the convergence of Amazon's vulnerability management organizations of security engineers, software engineers, data engineers, and product managers chartered together to solve machine-speed vulnerability management at Amazon scale.

Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications: - Bachelor's degree - Experience owning/driving roadmap strategy and definition - Experience technical product management - Experience working with and influencing senior level stakeholders - Experience leading engineering discussions around technology decisions and strategy related to a product

Preferred Qualifications: - Experience working directly with Engineers on product enhancements - Experience in project management methodologies, business analysis, or process improvement

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, TX, Austin - 179,900.00 - 243,400.00 USD annually

Similar roles