Sr. Software Development Engineer , Leo Asset Tracker
Software Engineering · Full-time
Redmond, WA, USA
Description
Amazon LEO is an initiative to increase global broadband access through a constellation of 3,236 satellites in low Earth orbit (LEO). Its mission is to bring fast, affordable broadband to unserved and underserved communities around the world. Amazon LEO will help close the digital divide by delivering fast, affordable broadband to a wide range of customers, including consumers, businesses, government agencies, and other organizations operating in places without reliable connectivity.
Leo Asset Tracker (LAT) is an internal Amazon application that gives Leo teams real-time visibility into their physical assets — antennas, test equipment, and Hubble trackers — across facilities. It replaces spreadsheets and manual audits with a program-scoped system of record covering device management, live location and geofencing, calibration tracking, device transfers, and built-in audit trails.
The backend is a serverless AWS platform: Python Lambda functions built on aws-lambda-powertools and pydantic, DynamoDB and OpenSearch for storage and search, and a TypeScript AWS CDK package that defines the infrastructure and CI/CD pipeline. The service is secured by a V3 role-based access-control model with per-program scoping. As a backend engineer you will own and extend the APIs, data model, and infrastructure that power the product.
Export Control Requirement
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Key job responsibilities
- Design, build, and operate Python (AWS Lambda) API domains and event-driven workers, following the domain layer pattern (routes, models, store, permissions) used across the service.
- Own the DynamoDB data model and OpenSearch indexing paths — designing keys, GSIs, and cursor-paginated queries that scale.
- Extend the V3 RBAC security model (roles, permissions, and per-program authorization), guard every endpoint through centralized permission predicates, and manage IAM roles, policies, Bindle-based access controls, and permission boundaries to ensure least-privilege compliance across all services and environments.
- Wire backend changes end-to-end through the TypeScript CDK package: Lambda definitions, IAM grants, environment variables, API Gateway routes, and pipeline stages — owning the security posture of all provisioned AWS resources.
- Lead and participate in security reviews, ensuring alignment with organizational security standards and best practices across infrastructure and application layers.
- Write unit and integration tests, uphold code quality (black, isort, flake8, mypy), and participate in code reviews (CRUX).
- Support the alpha → beta → gamma → prod deployment pipeline, monitoring, and on-call operational excellence for the service.
- Collaborate with frontend (React/Cloudscape) and infrastructure partners to deliver features such as location tracking, geofencing, and device transfers.