Senior Technical Program Mgr, Amazon Leo Trust Services

AmazonApplyPublished 20 hours agoFirst seen 1 hours ago
Apply
Project Leo is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world.

Amazon Leo Trust Services (ALTS) owns the cryptographic infrastructure that underpins Leo's satellite constellation, including certificate lifecycle management, key generation and provisioning, secure communications, and post-quantum cryptographic readiness. We are looking for a Technical Program Manager to own the certificate rotation and cryptographic algorithm migration program across Leo. As the constellation scales, the cryptographic foundation must evolve with it: enabling automated certificate rotation across dozens of integration points, migrating to next-generation algorithms including post-quantum cryptography, and ensuring devices designed to operate for 15+ years remain cryptographically current throughout their lifetime. This is a rare opportunity to shape how a global satellite network maintains cryptographic trust at scale.

Export Control Requirement

Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Key job responsibilities
You will own the end-to-end program for certificate rotation and cryptographic algorithm migration across Leo's constellation infrastructure. This means building a unified view of how certificates are consumed across 10+ integration points (from full certificate chain transmission to hard-coded serial numbers on devices), identifying and driving resolution of the constraints that prevent automated rotation (including a 1,200-byte MTU limit over UDP that blocks larger post-quantum material), and orchestrating the cross-team work required to deliver cryptographic agility. You will partner with hardware, firmware, ground systems, and network teams to define the out-of-band distribution workflows needed for next-generation certificate formats. You will manage program lifecycle from requirements through delivery, negotiate priorities across teams that do not share a reporting chain, drive crisp decisions in ambiguous technical territory, and communicate progress, risks, and tradeoffs to Directors and VPs. You will also contribute to broader ALTS programs including PKI infrastructure migration to AWS data centers, post-quantum readiness for upcoming tapeout deadlines, and deprecated service decommissions.

A day in the life
You will spend your time driving alignment across teams that each own a piece of the certificate puzzle but have never had a single orchestrator connecting their work. Some days that means facilitating a design review to define how a ground service will consume global certificates instead of regional ones. Other days it means tracking a deprecated key management service through its final migration milestones before its hard shutdown deadline. You will build and maintain the program plan that connects hardware tapeout dates, firmware release schedules, and service deployment timelines into a coherent delivery sequence. You will identify risks early, escalate effectively when teams are blocked, and write the narratives that help leadership understand why cryptographic agility matters for Leo's long-term operational security. The work is both strategic (shaping how Leo's PKI evolves over the next decade) and tactical (ensuring the next certificate rotation does not cause loss of satellite control).

About the team
The Leo Trust Services team owns the cryptographic foundation for Project Leo's satellite broadband service. We manage the keys, certificates, and secure communication protocols that protect everything from chip provisioning in manufacturing through satellite control in orbit. Our 2027 priorities center on post-quantum readiness, infrastructure resilience, and the cryptographic agility program this TPM will own.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.

Basic Qualifications

  • 5+ years of technical program management experience
  • 5+ years of work with software development lifecycle from conception to delivery experience
  • Bachelor's degree in Engineering, Computer Science, or a related technical field
  • Experience managing efforts in Unix/Linux environments, distributed systems or developing large-scale web applications
  • Knowledge of concepts like system architecture, optimization, system dynamics, system analysis, statistical analysis, reliability analysis, and decision making
  • Experience in identifying security issues and risks, and developing mitigation plans

Preferred Qualifications

  • Experience in security or compliance consulting or advisory work in support of a highly technical environment
  • Knowledge of the AWS product suite
  • Knowledge of cloud computing services/deployment architecture
  • Experience with cryptographic systems, PKI, certificate management, or security infrastructure programs
  • Experience managing programs with hardware and software co-dependencies (e.g., silicon tapeouts, firmware, embedded systems)
  • Experience in aerospace, satellite, IoT, or other environments where devices cannot be easily patched post-deployment
  • Familiarity with post-quantum cryptography, NIST standards, or compliance frameworks (NIST 800-53, CMMC)
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.


USA, WA, Redmond - 163,600.00 - 221,300.00 USD annually