Quantum key distribution and authentication: Separating facts from myths

Key exchange protocols and authentication mechanisms solve distinct problems and must be integrated in a secure communication system.

Quantum key distribution (QKD) is a technology that leverages the laws of quantum physics to securely share secret information between distant communicating parties. With QKD, quantum-mechanical properties ensure that if anyone tries to tamper with the secret-sharing process, the communicating parties will know. Keys established through QKD can then be used in traditional symmetric encryption or with other cryptographic technologies to secure communications.

“Record now, decrypt later" (RNDL) is a cybersecurity risk arising from advances in quantum computing. The term refers to the situation in which attackers record encrypted data today, even though they cannot decrypt it immediately. They store this data with the expectation that future quantum computers will be powerful enough to break the cryptographic algorithms currently securing it. Sensitive information such as financial records, healthcare data, or state secrets could be at risk, even years after it was transmitted.

Mitigating RNDL requires adopting quantum-resistant cryptographic methods, such as post-quantum cryptography (PQC) and/or quantum key distribution (QKD), to ensure confidentiality against future quantum advancements. AWS has invested in the migration to post-quantum cryptography to protect the confidentiality, integrity, and authenticity of customer data.

Quantum communication is important enough that in 2022, three of its pioneers won the Nobel Prize for physics. However, misconceptions about QKD’s role still persist. One of them is that QKD lacks practical value because it “doesn’t solve the authentication problem”. This view can obscure the broad benefits that QKD brings to secure communications when integrated properly into existing systems.

QKD should be viewed as a complement to — rather than a replacement for — existing cybersecurity frameworks. Functionally, QKD solves the same problem solved by other key establishment protocols, including the well-known Diffie-Hellman (DH) method and the module-lattice-based key encapsulation mechanism (ML-KEM), the standard recently ratified by the FIPS — but it does it in a fundamentally different way. Like those methods, QKD depends on strong authentication to defend against threats such as man-in-the-middle attacks, where an attacker poses as one of the communicating parties.

Related content
The head of Amazon Web Services’ quantum communication program on the Nobel winners’ influence on her field.

In short, key exchange protocols and authentication mechanisms are different security primitives for solving distinct problems and must be integrated together in a secure communication system.

The challenge, then, is not to give QKD an authentication mechanism but to understand how it can be integrated with other established mechanisms to strengthen the overall security infrastructure. As quantum technologies continue to evolve, it’s important to shift the conversation from skepticism about authentication to consideration of how QKD can be thoughtfully and practically implemented to address today’s and tomorrow’s cybersecurity needs — such as the need to mitigating the “record now, decrypt later” (RNDL) attack (see sidebar).

Understanding the role of authentication in QKD

When discussing authentication in the context of QKD, we focus on the classical digital channel that the parties use to exchange information about their activities on the quantum channel. This isn’t about user authentication methods, such as logging in with passwords or biometrics, but rather about authenticating the communicating entities and the data exchanged. Entity authentication ensures that the parties are who they claim to be; data authentication guarantees that the information received is the same as what was sent by the claimed source. QKD protocols include a classical-communication component that uses both authentication methods to assure the overall security of the interaction.

Entity authentication

Entity authentication is the process by which one party (the "prover") asserts its identity, and another party (the "verifier") validates that assertion. This typically involves a registration step, in which the verifier obtains reliable identification information about the prover, as a prelude to any further authentication activity. The purpose of this step is to establish a “root of trust” or “trust anchor”, ensuring that the verifier has a trusted baseline for future authentications.

Related content
Collaboration will seek to advance the development of a quantum internet.

Several entity authentication methods are in common use, each based on a different type of trust anchor:

  • Public-key-infrastructure (PKI) authentication: In this method, a prover’s certificate is issued by a trusted certificate authority (CA). The verifier relies on this CA, or the root CA in a certificate chain, to establish trust. The certificate acts as the trust anchor that links the prover’s identity to its public key.
  • PGP-/GPG-based (web of trust) authentication: Here, trust is decentralized. A prover’s public key is trusted if it has been vouched for by one or more trusted third parties, such as a mutual acquaintance or a public-key directory. These third parties serve as the trust anchors.
  • Pre-shared-key-based (PSK) authentication: In this case, both the prover and the verifier share a secret key that was exchanged via an offline or other secure out-of-band method. The trust anchor is the method of securely sharing this key a priori, such as a secure courier or another trusted channel.

These trust anchors form the technical backbones of all authentication systems. However, all entity authentication methods are based on a fundamental assumption: the prover is either the only party that holds the critical secret data (e.g., the prover’s private key in PKI or PGP) or the only other party that shares the secret with the verifier (PSK). If this assumption is broken — e.g., the prover's private key is stolen or compromised, or the PSK is leaked — the entire authentication process can fail.

Data authentication

Data authentication, also known as message authentication, ensures both the integrity and authenticity of the transmitted data. This means the data received by the verifier is exactly what the sender sent, and it came from a trusted source. As with entity authentication, the foundation of data authentication is the secure management of secret information shared by the communicating parties.

Related content
Among the ‘first wave’ of scientists to gain a PhD in quantum technology, the senior manager of research science discusses her two-decade-long career journey.

The most common approach to data authentication is symmetric cryptography, where both parties share a secret key. A keyed message authentication code (MAC), such as HMAC or GMAC, is used to compute a unique tag for the transmitted data. This tag allows the receiver to verify that the data hasn’t been altered during transit. The security of this method depends on the collision resistance of the chosen MAC algorithm — that is, the computational infeasibility of finding two or more plaintexts that could yield the same tag — and the confidentiality of the shared key. The authentication tag ensures data integrity, while the secret key guarantees the authenticity of the data origin.

An alternative method uses asymmetric cryptography with digital signatures. In this approach, the sender generates a signature using a private key and the data itself. The receiver, or anyone else, can verify the signature’s authenticity using the sender’s public key. This method provides data integrity through the signature algorithm, and it assures data origin authenticity as long as only the sender holds the private key. In this case, the public key serves as a verifiable link to the sender, ensuring that the signature is valid.

In both the symmetric and the asymmetric approaches, successful data authentication depends on effective entity authentication. Without knowing and trusting the identity of the sender, the verification of the data’s authenticity is compromised. Therefore, the strength of data authentication is closely tied to the integrity of the underlying entity authentication process.

Authentication in QKD

The first quantum cryptography protocol, known as BB84, was developed by Bennett and Brassard in 1984. It remains foundational to many modern QKD technologies, although notable advancements have been made since then.

Related content
New method enables entanglement between vacancy centers tuned to different wavelengths of light.

QKD protocols are unique because they rely on the fundamental principles of quantum physics, which allow for “information-theoretic security.” This is distinct from the security provided by computational complexity. In the quantum model, any attempt to eavesdrop on the key exchange is detectable, providing a layer of security that classical cryptography cannot offer.

QKD relies on an authenticated classical communication channel to ensure the integrity of the data exchanged between parties, but it does not depend on the confidentiality of that classical channel. (This is why RNDL is not an effective attack against QKD). Authentication just guarantees that the entities establishing keys are legitimate, protecting against man-in-the-middle attacks.

Currently, several commercial QKD products are available, many of which implement the original BB84 protocol and its variants. These solutions offer secure key distribution in real-world applications, and they all pair with strong authentication processes to ensure the communication remains secure from start to finish. By integrating both technologies, organizations can build communication infrastructures capable of withstanding both classical and quantum threats.

Authentication in QKD bootstrap: A manageable issue

During the initial bootstrap phase of a QKD system, the authentic classical channel is established using traditional authentication methods based on PKI or PSK. As discussed earlier, all of these methods ultimately rely on the establishment of a trust anchor.

Related content
Automated reasoning and optimizations specific to CPU microarchitectures improve both performance and assurance of correct implementation.

While confidentiality may need to be maintained for an extended period (sometimes decades), authentication is a real-time process. It verifies identity claims and checks data integrity in the moment. Compromising an authentication mechanism at some future point will not affect past verifications. Once an authentication process is successfully completed, the opportunity for an adversary to tamper with it has passed. That is, even if, in the future, a specific authentication mechanism used in QKD is broken by a new technology, QKD keys generated prior to that point are still safe to use, because no adversary can go back in time to compromise past QKD key generation.

This means that the reliance on traditional, non-QKD authentication methods presents an attack opportunity only during the bootstrap phase, which typically lasts just a few minutes. Given that this phase is so short compared to the overall life cycle of a QKD deployment, the potential risks posed by using authentication mechanisms are relatively minor.

Authentication after QKD bootstrap: Not a new issue

Once the bootstrap phase is complete, the QKD devices will have securely established shared keys. These keys can then be used for PSK-based authentication in future communications. In essence, QKD systems can maintain the authenticated classical communication channel by utilizing a small portion of the very keys they generate, ensuring continued secure communication beyond the initial setup phase.

It is important to note that if one of the QKD devices is compromised locally for whatever reason, the entire system’s security could be at risk. However, this is not a unique vulnerability introduced by QKD. Any cryptographic system faces similar challenges when the integrity of an endpoint is compromised. In this respect, QKD is no more susceptible to it than any other cryptographic system.

Overcoming key challenges to QKD’s role in cybersecurity

Up to now we have focused on clarifying the myths about authentication needs in QKD. Next we will discuss several other challenges in using QKD in practice.

Bridging the gap between QKD theory and implementation

While QKD protocols are theoretically secure, there remains a significant gap between theory and real-world implementations. Unlike traditional cryptographic methods, which rely on well-understood algorithms that can be thoroughly reviewed and certified, QKD systems depend on specialized hardware. This introduces complexity, as the process of reviewing and certifying QKD hardware is not yet mature.

Related content
Using time to last byte — rather than time to first byte — to assess the effects of data-heavy TLS 1.3 on real-world connections yields more encouraging results.

In conventional cryptography, risks like side-channel attacks — which use runtime clues such as memory access patterns or data retrieval times to deduce secrets — are well understood and mitigated through certification processes. QKD systems are following a similar path. The European Telecommunications Standards Institute (ETSI) has made a significant move by introducing the Common Criteria Protection Profile for QKD, the first international effort to create a standardized certification framework for these systems. ISO/IEC has also published standards on security requirements and test and evaluation methods for QKD. These represent crucial steps in building the same level of trust that traditional cryptography enjoys.

Once the certification process is fully established, confidence in QKD’s hardware implementations will continue to grow, enabling the cybersecurity community to embrace QKD as a reliable, cutting-edge solution for secure communication. Until then, the focus remains on advancing the review and certification processes to ensure that these systems meet the highest security standards.

QKD deployment considerations

One of the key challenges in the practical deployment of QKD is securely transporting the keys generated by QKD devices to their intended users. While it’s accepted that QKD is a robust mechanism for distributing keys to the QKD devices themselves, it does not cover the secure delivery of keys from the QKD device to the end user (or key consumer).

QKD diagram.png
A schematic representation of two endpoints — site A and site B — that want to communicate safely. The top line represents the user traffic being protected, and the bottom lines are the channels required to establish secure communication. An important practical consideration is how to transmit a key between a QKD device and an end user within an endpoint.

This issue arises whether the QKD system is deployed within a large intranet or a small local-area network. In both cases, the keys must be transported over a non-QKD system. The standard deployment requirement is that the key delivery from the QKD system to the key consumer occurs “within the same secure site”, and the definition of a “secure site” is up to the system operator.

Related content
Prize honors Amazon senior principal scientist and Penn professor for a protocol that achieves a theoretical limit on information-theoretic secure multiparty computation.

The best practice is to make the boundary of the secure site as small as is practical. One extreme option is to remove the need for transporting keys over classical networks entirely, by putting the QKD device and the key user’s computing hardware in the same physical unit. This eliminates the need for traditional network protocols for key transport and realizes the full security benefits of QKD without external dependency. In cases where the extreme option is infeasible or impractical, the secure site should cover only the local QKD system and the intended key consumers.

Conclusion

QKD-generated keys will remain secure even when quantum computers emerge, and communications using these keys are not vulnerable to RNDL attacks. For QKD to reach its full potential, however, the community must collaborate closely with the broader cybersecurity ecosystem, particularly in areas like cryptography and governance, risk, and compliance (GRC). By integrating the insights and frameworks established in these fields, QKD can overcome its current challenges in trust and implementation.

This collective effort is essential to ensure that QKD becomes a reliable and integral part of secure communication systems. As these collaborations deepen, QKD will be well-positioned to enhance existing security frameworks, paving the way for its adoption across industries and applications.

Related content

US, WA, Redmond
At Amazon, we’re inventing on behalf of customers, and with Amazon Leo, we’re redefining what global connectivity looks like. Our mission is to deliver fast, affordable broadband to unserved and underserved communities around the world through a constellation of low Earth orbit (LEO) satellites. Every system we build helps connect people to education, healthcare, opportunity, and each other. As a Data Scientist, you will be responsible for developing advanced analytics and machine learning solutions for user terminals. You will develop predictive models to proactively identify possible user terminal failures in the field. You will work in a collaborative environment with a multi-disciplinary team, including constellation, RF, antenna, silicon, algorithm, and software engineers. Key job responsibilities As a Data Scientist, you will develop analytic tools for a team developing current and future user terminals. Your responsibilities include: • Develop statistical and analytical tool to enable the regression decision from on-orbit and lab measurement of user terminals • Publish documents and create compelling visualizations and presentations to communicate insights to stakeholders • Create and manage datasets for continued pre-training and supervised fine-tuning of LLMs • Develop scalable visualizations for analysis of user terminal performance • Work closely with constellation, RF, antenna, silicon, algorithm, and software engineers to root-cause the failures using data as the primary tool • Drive consensus on metrics and analysis approaches to support product development strategy Export Control Requirement: Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. A day in the life As a Data Scientist in the LEO Customer Terminal Team, you will work daily with satellite constellation, algorithm, RF, antenna, silicon, hardware, and software teams in a collaborative environment. Your focus will be using data as an intelligence source to enable design decisions for the team. About the team The LEO Customer Terminal team is responsible for developing both outdoor and indoor devices that enable customers to access internet service via the LEO satellite network. We own the entire process from early prototypes through mass production, including requirements documentation, architecture definition, hardware development, algorithm development, and all integration and verification testing.
US, NY, New York
We are seeking an Applied Scientist to lead the development of evaluation frameworks and data collection protocols for robotic capabilities. In this role, you will focus on designing how we measure, stress-test, and improve robot behavior across a wide range of real-world tasks. Your work will play a critical role in shaping how policies are validated and how high-quality datasets are generated to accelerate system performance. You will operate at the intersection of robotics, machine learning, and human-in-the-loop systems, building the infrastructure and methodologies that connect teleoperation, evaluation, and learning. This includes developing evaluation policies, defining task structures, and contributing to operator-facing interfaces that enable scalable and reliable data collection. The ideal candidate is highly experimental, systems-oriented, and comfortable working across software, robotics, and data pipelines, with a strong focus on turning ambiguous capability goals into measurable and actionable evaluation systems. Key job responsibilities - Design and implement evaluation frameworks to measure robot capabilities across structured tasks, edge cases, and real-world scenarios - Develop task definitions, success criteria, and benchmarking methodologies that enable consistent and reproducible evaluation of policies - Create and refine data collection protocols that generate high-quality, task-relevant datasets aligned with model development needs - Build and iterate on teleoperation workflows and operator interfaces to support efficient, reliable, and scalable data collection - Analyze evaluation results and collected data to identify performance gaps, failure modes, and opportunities for targeted data collection - Collaborate with engineering teams to integrate evaluation tooling, logging systems, and data pipelines into the broader robotics stack - Stay current with advances in robotics, evaluation methodologies, and human-in-the-loop learning to continuously improve internal approaches - Lead technical projects from conception through production deployment - Mentor junior scientists and engineers
US, WA, Redmond
Amazon Leo is building a constellation of thousands of low Earth orbit satellites to deliver fast, reliable internet beyond the reach of existing networks. As a Guidance, Navigation & Control engineer, you will design the algorithms, simulations, and onboard autonomy that keep every satellite precisely pointed and stable so the payload can serve customers below, and keep the fleet flying safely. This is satellite GNC with demanding pointing and performance requirements, and you will see your work go from concept to orbit on a constellation that is launching and growing today. Amazon Leo will delight customers with reliable connectivity regardless of where they are. In this role, you will: - Take your GNC algorithms from concept all the way to orbit, and stay close to them through integration, test, and on-orbit operations - Solve hard precise-pointing, payload-cueing, and fleet-autonomy problems against demanding performance requirements - Work across the full lifecycle — design, simulation, test, and flight operations — rather than a narrow slice - Join a small team of some of the top GNC engineers in the industry, building a product people will love to use This position is part of the Satellite Attitude Determination and Control team, where we own the full lifecycle of our work — from algorithm design and flight software, through lab integration, to flying our own satellites on orbit. You will design and analyze the control system and algorithms, support development of our flight hardware and software, help integrate the satellite in our labs, and operate the GNC system in flight as a constellation of satellites flows through the production line into orbit. **Export Control Requirement:** Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. Key job responsibilities - Design and analyze algorithms for state estimation, attitude determination and control, precise pointing, and payload cueing against demanding performance requirements. - Write the production C++ flight code that runs these algorithms on the satellite. Our GNC engineers own their algorithms all the way into flight software, working alongside software development engineers rather than handing prototypes off to be reimplemented by another team. - Design concepts of operation that balance pointing and payload cueing, momentum management, power, thermal, and communications across all phases of the mission, including off-nominal and contingency scenarios. - Develop momentum management strategies using reaction wheels and magnetic torquers, and help size and lay out the GNC sensor and actuator suite — star trackers, magnetometers, sun sensors, IMUs, and GPS receivers — and the algorithms that consume them. - Develop onboard autonomy, including Fault Detection, Isolation, and Recovery, so the fleet operates safely at scale with minimal intervention. - Develop and validate models and simulations of the satellite and constellation across a range of fidelity levels, including 6-DOF time-domain simulation and Monte Carlo analysis, and run hardware-in-the-loop testing to verify closed-loop performance. - Support component-level environmental testing, functional and performance checkout, and subsystem and satellite integration in our labs. - Analyze fleet telemetry in bulk and build the metrics, dashboards, and tooling that let us monitor and continuously improve pointing performance and payload operations time as the constellation grows. - Operate the GNC system on orbit — reviewing fleet data, supporting maneuvers, and resolving anomalies when on-orbit behavior diverges from the ground model. - Contribute to architecture, design, and code reviews, and document your algorithms, analyses, and results clearly. A day in the life This role spans a diverse set of problems across the spacecraft and network system. You will derive and prototype estimation and control algorithms, turn them into production flight code, and prove them out through 6-DOF and Monte Carlo simulation and hardware-in-the-loop testing in the lab. You will support satellite integration, and when something on orbit does not behave the way the ground model predicted, you will dig into fleet telemetry to find out why and drive the fix. You will own problems end to end and have the focus to go deep on each one. Because GNC sits at the center of safe flight, you will work across the whole program. The payload, power, thermal, and operations teams all depend on GNC, so you will balance their needs against your pointing and momentum budgets. To get your algorithms running reliably on the spacecraft, you will partner closely with avionics, flight software, and our embedded software development engineers. You will help the mechanical teams shape the next generation of satellite hardware, from reaction wheels to star trackers. And as satellites move from design through manufacturing into orbit, you will work alongside systems engineering and Assembly, Integration & Test. The problems are genuinely hard — demanding pointing and performance requirements, a large constellation to keep flying safely, and the chance to invent advanced capabilities that have not been built before. The work is staffed with some of the strongest engineers in the industry, and the constant collaboration across teams makes it a place to keep learning and growing. About the team Our team brings deep experience across many satellite systems and other flight vehicles, with real bench strength in both our mission and the core GNC disciplines. We design, prototype, test, iterate, and learn together, and because GNC is central to safe flight, we tend to drive Concepts of Operation and many of the system-level analyses on the program. We also have a lot of freedom. We trust our engineers to pursue the problems they face in whatever way they find best, to choose their own tools and approaches, and to own the results. If you want the autonomy to solve hard problems your way, and a team of strong engineers to do it with, you will feel at home here.
US, NY, New York
Amazon Advertising is one of Amazon's fastest growing and most profitable businesses, responsible for defining and delivering a collection of advertising products that drive discovery and sales. Our products are strategically important to our businesses driving long term growth. We deliver billions of ad impressions and millions of clicks and break fresh ground in product and technical innovations every day! Advertiser Growth Engine (AGE) team owns and builds services and applications across Amazon World-Wide Advertising that make advertising across multi-marketplaces as easy as flipping on a switch. We are focused on: (1) expanding Amazon Ads advertiser base, and (2) eliminating localization, operational, and marketplace knowledge gap barrier for Advertisers who advertise across multiple marketplaces. Our products and solutions are strategically important to enable our Retail and Marketplace businesses to drive long-term growth globally. We're looking for an experienced Applied Scientist with exceptional technical, analytical, and innovative capabilities to research, design, and create elegant machine learning solutions. The solutions will help our advertisers with multi-media and multi-lingual advertising offerings. You will use ideas from various domains of machine learning, including supervised and unsupervised methods, Deep Neural Networks, Natural Language Processing (NLP), and Computer Vision (CV) to build ML models that localizes multi-media advertising contents, including text, images and videos. You will also identify opportunities to leverage ML beyond localization, including, international expansion and global campaigns. Your work will directly impact our customers in the form of products and services used directly by our advertisers as well as our third-party integrators. As an Applied Scientist on this team, you will: - Build and deliver end-to-end machine learning solutions; build ML models and perform data analysis to deliver scalable solutions to business problems. - Perform hands-on analysis and modeling with enormous data sets to develop insights that increase traffic monetization and merchandise sales without compromising shopper experience. - Work closely with software engineers on detailed requirements to productionize the ML models you build. - Run A/B experiments that affect hundreds of millions of customers, evaluate the impact of your optimizations and communicate your results to various business stakeholders. - Establish scalable, efficient, automated processes for large-scale data analysis, machine-learning model development, model validation and serving. - Research new innovate machine learning approaches. Why you will love this opportunity: Amazon is investing heavily in building a world-class advertising business. This team defines and delivers a collection of advertising products that drive discovery and sales. Our solutions generate billions in revenue and drive long-term growth for Amazon’s Retail and Marketplace businesses. We deliver billions of ad impressions, millions of clicks daily, and break fresh ground to create world-class products. We are a highly motivated, collaborative, and fun-loving team with an entrepreneurial spirit - with a broad mandate to experiment and innovate. Impact and Career Growth: You will invent new experiences and influence customer-facing shopping experiences to help suppliers grow their retail business and the auction dynamics that leverage native advertising; this is your opportunity to work within the fastest-growing businesses across all of Amazon! Define a long-term science vision for our advertising business, driven from our customers' needs, translating that direction into specific plans for research and applied scientists, as well as engineering and product teams. This role combines science leadership, organizational ability, technical strength, product focus, and business understanding. Team video https://youtu.be/zD_6Lzw8raE
US, NY, New York
We are seeking an Applied Scientist to lead the development of evaluation frameworks and data collection protocols for robotic capabilities. In this role, you will focus on designing how we measure, stress-test, and improve robot behavior across a wide range of real-world tasks. Your work will play a critical role in shaping how policies are validated and how high-quality datasets are generated to accelerate system performance. You will operate at the intersection of robotics, machine learning, and human-in-the-loop systems, building the infrastructure and methodologies that connect teleoperation, evaluation, and learning. This includes developing evaluation policies, defining task structures, and contributing to operator-facing interfaces that enable scalable and reliable data collection. The ideal candidate is highly experimental, systems-oriented, and comfortable working across software, robotics, and data pipelines, with a strong focus on turning ambiguous capability goals into measurable and actionable evaluation systems. Key job responsibilities - Design and implement evaluation frameworks to measure robot capabilities across structured tasks, edge cases, and real-world scenarios - Develop task definitions, success criteria, and benchmarking methodologies that enable consistent and reproducible evaluation of policies - Create and refine data collection protocols that generate high-quality, task-relevant datasets aligned with model development needs - Build and iterate on teleoperation workflows and operator interfaces to support efficient, reliable, and scalable data collection - Analyze evaluation results and collected data to identify performance gaps, failure modes, and opportunities for targeted data collection - Collaborate with engineering teams to integrate evaluation tooling, logging systems, and data pipelines into the broader robotics stack - Stay current with advances in robotics, evaluation methodologies, and human-in-the-loop learning to continuously improve internal approaches - Lead technical projects from conception through production deployment - Mentor junior scientists and engineers
IL, Tel Aviv
Are you a scientist interested in pushing the state of the art in Information Retrieval, Large Language Models and Recommendation Systems? Are you interested in innovating on behalf of millions of customers, helping them accomplish their every day goals? Do you wish you had access to large datasets and tremendous computational resources? Do you want to join a team of capable scientist and engineers, building the future of e-commerce? Answer yes to any of these questions, and you will be a great fit for our team at Amazon. Our team is part of Amazon’s Personalization organization, a high-performing group that leverages Amazon’s expertise in machine learning, generative AI, large-scale data systems, and user experience design to deliver the best shopping experiences for our customers. Our team is building next-generation personalization systems powered by Large Language Models. We are tackling novel research challenges to help customers discover products they'll love - at Amazon scale and latency requirements. We are a team uniquely placed within Amazon, to have a direct window of opportunity to influence how customers will think about their shopping journey in the future. As an Applied Science Manager, you will lead a team of scientists working at the frontier of LLM-based personalization. You will set the technical vision, drive the research agenda, and ensure your team delivers production-ready solutions. You will hire, mentor, and develop world-class scientists while fostering a culture of innovation and scientific rigor. You will partner closely with engineering and product teams to translate ambitious research into customer-facing impact, and represent your team's work to senior leadership. Please visit https://www.amazon.science for more information.
US, WA, Seattle
AWS Applied AI Solutions (AAIS) is building toward a future where every business innovates with Amazon AI teammates. To get there, we build AI solutions that improve human capabilities and transform entire business functions. We create end-to-end products that surprise and delight out-of-the-box, making complex things easy and hard things possible, with no cloud experience required. We start with customers who embrace the future and build bridges to meet the rest where they are. We pursue ambitious opportunities with conviction, and we are looking for builders who share that mindset. The Team Join the next science revolution at AWS Life Sciences Applied AI Solutions where you'll work alongside world-class scientists to build AI that transforms how therapeutics are discovered, developed, and brought to patients. We're out to revolutionize how medicines are discovered, developed, and brought to patients powered by a new generation of AI. Our team tackles some of the hardest open problems at the intersection of frontier AI and life sciences. We apply biological foundation models large language models and agentic reasoning systems to life sciences problems then put them into the hands of customers as applications and managed services they can fine-tune tailor and deploy on their own data. The science challenges are deep: how do you design agentic systems that reason correctly over complex biological regulatory and clinical logic? How do you enable customers to tailor foundation models to their proprietary data and get better outputs with less effort? How do you adapt models to reason faithfully in high-stakes scientific and regulatory domains? Today we're focused on two areas. In clinical trials we're building AI that automates and optimizes regulatory and clinical development workflows. In drug design our products (including Amazon Bio Discovery) accelerate discovery by giving bench scientists AI-guided protein engineering and antibody design capabilities. We combine frontier research with production-scale delivery to put breakthrough science into the hands of customers solving humanity's hardest problems. We value scientific rigor encourage publication and support conference participation. If you want to do research that ships this is the team. The Role We are seeking an Applied Scientist to build the models and methods behind our life sciences AI products with a primary focus on clinical trial operations and agentic reasoning. You will design train and evaluate systems that reason over complex clinical and operational logic and ship them into products customers use directly. You will work closely with senior and principal scientists on well-scoped research problems own your results end to end and see your work reach production. This role combines expertise in LLM reasoning and agentic AI with applied impact in life sciences. You will work on how large language models reason plan and act in complex scientific domains while applying domain knowledge to ensure models produce scientifically valid outputs. The problems span multiple fronts: • How do you build LLM-based agentic systems that correctly reason over clinical protocols regulatory standards and complex multi-step operational workflows? • How do you evaluate agent reliability and faithfulness rigorously enough to trust in high-stakes clinical settings? • How do you develop model customization methods (fine-tuning retrieval augmentation domain adaptation) that let customers get strong results from foundation models on their own data? You will focus on clinical trial operations (agentic automation structured reasoning evaluation domain adaptation) with opportunities to contribute across drug discovery (protein engineering antibody design) as the portfolio grows. You will own end-to-end scientific solutions from research through production and your work will directly shape the tools that scientists use daily. Key job responsibilities • Design train fine-tune and evaluate LLM-based agentic systems that reason over clinical protocols regulatory standards and operational workflows • Build rigorous evaluation harnesses and benchmarks to measure agent reliability faithfulness and failure modes in high-stakes domains • Develop model customization methods (fine-tuning RLHF retrieval augmentation domain adaptation) that help customers get better outputs on their own data with less effort • Contribute to graph-based and causal modeling approaches for clinical trial operations • Partner with Life Sciences domain experts product and engineering to translate scientific challenges into shipped capabilities • Own experiments end to end: problem framing implementation evaluation iteration and hand-off to production • Publish at top-tier venues where the work supports it • Contribute to drug discovery efforts (protein engineering antibody design) as opportunities arise A day in the life • Design and run an experiment to validate a new agentic reasoning or fine-tuning method then ship it as a capability customers can use • Diagnose why a model is failing on a new class of inputs and implement a fix to unblock a delivery milestone • Build or extend an evaluation benchmark to measure how faithfully an agent reasons over clinical logic • Meet with domain experts to scope what the next model release needs to do • Review results with a senior scientist sharpen the approach and get it over the finish line • Prototype a new idea that could become the next capability in the product About the team Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses. We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve in the cloud. Here at AWS, it's in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity and AmazeCon conferences, inspire us to never stop embracing our uniqueness. We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
BR, SP, Sao Paulo
Do you feel the challenge and the adrenaline kick when a huge data-set stares you in the face and you know that somewhere inside are hidden very important business insights that can fundamentally alter the way top business leaders think and act? Do you enjoy presenting strong data backed insights to business leaders; insights that can topple their long held beliefs and compel them to change their direction completely? If yes, then you are the one we are looking for. We are looking to invite passionate leaders, with expertise in generate power business insights from very large datasets, on a journey where the primary aim would be to enable needle moving business impacts through statistical analysis. We are looking for leaders who can envision the design and development of analytical infrastructure which can support strategic and tactical decision-making. Those who join this high visibility team would have to navigate through significant ambiguity in defining business problems and converting them to analytical problems. This role requires additional exposure and experience to Machine Learning. Key job responsibilities Use machine learning and analytical techniques to create scalable solutions for business problems • Analyze and extract relevant information from large amounts of Amazon’s historical business data to help automate and optimize key processes • Design, development, evaluate and deploy innovative and highly scalable ml models such as risk scorecards, income models, fraud models for predictive learning in credit risk applications • Research and implement novel machine learning and statistical approaches • Work closely with software engineering teams to drive real-time model implementations and new feature creations • Work closely with business owners and operations staff to optimize various business operations • Establish scalable, efficient, automated processes for large scale data analyses, model development, model validation and model implementation • Mentor other scientists and engineers in the use of ML techniques • Innovate with the latest GenAI technology to build highly automated solutions for efficient customer promotions • Design, develop and deploy end-to-end machine learning solutions in the Amazon production environment to delight Amazon customers • Collaborate with cross-functional teams to develop comprehensive ML/statistical models that can scale to millions of customers to multiple countries Understand the credit risk data and evaluate the best ml model/ solution for dynamic business problems. About the team Brazil Payments is part of the International Emerging Stores Payments team and focuses on supporting the launch of new payment and financial products to our customers in Brazil.
BR, SP, Sao Paulo
Do you feel the challenge and the adrenaline kick when a huge data-set stares you in the face and you know that somewhere inside are hidden very important business insights that can fundamentally alter the way top business leaders think and act? Do you enjoy presenting strong data backed insights to business leaders; insights that can topple their long held beliefs and compel them to change their direction completely? If yes, then you are the one we are looking for. We are looking to invite passionate leaders, with expertise in generate power business insights from very large datasets, on a journey where the primary aim would be to enable needle moving business impacts through statistical analysis. We are looking for leaders who can envision the design and development of analytical infrastructure which can support strategic and tactical decision-making. Those who join this high visibility team would have to navigate through significant ambiguity in defining business problems and converting them to analytical problems. This role requires additional exposure and experience to Machine Learning. Key job responsibilities • Use machine learning and analytical techniques to create scalable solutions for business problems • Analyze and extract relevant information from large amounts of Amazon’s historical business data to help automate and optimize key processes • Design, development, evaluate and deploy innovative and highly scalable models for predictive learning • Research and implement novel machine learning and statistical approaches • Work closely with software engineering teams to drive real-time model implementations and new feature creations • Work closely with business owners and operations staff to optimize various business operations • Establish scalable, efficient, automated processes for large scale data analyses, model development, model validation and model implementation • Mentor other scientists and engineers in the use of ML techniques • Innovate with the latest GenAI technology to build highly automated solutions for efficient customer promotions • Design, develop and deploy end-to-end machine learning solutions in the Amazon production environment to delight Amazon customers • Collaborate with cross-functional teams to develop comprehensive ML/statistical models that can scale to millions of customers to multiple countries About the team Brazil Payments is part of the International Emerging Stores Payments team and focuses on supporting the launch of new payment and financial products to our customers in Brazil.
BR, SP, Sao Paulo
Do you feel the challenge and the adrenaline kick when a huge data-set stares you in the face and you know that somewhere inside are hidden very important business insights that can fundamentally alter the way top business leaders think and act? Do you enjoy presenting strong data backed insights to business leaders; insights that can topple their long held beliefs and compel them to change their direction completely? If yes, then you are the one we are looking for. We are looking to invite passionate leaders, with expertise in generate power business insights from very large datasets, on a journey where the primary aim would be to enable needle moving business impacts through statistical analysis. We are looking for leaders who can envision the design and development of analytical infrastructure which can support strategic and tactical decision-making. Those who join this high visibility team would have to navigate through significant ambiguity in defining business problems and converting them to analytical problems. This role requires additional exposure and experience to Machine Learning. Key job responsibilities Use machine learning and analytical techniques to create scalable solutions for business problems • Analyze and extract relevant information from large amounts of Amazon’s historical business data to help automate and optimize key processes • Design, development, evaluate and deploy innovative and highly scalable ml models such as risk scorecards, income models, fraud models for predictive learning in credit risk applications • Research and implement novel machine learning and statistical approaches • Work closely with software engineering teams to drive real-time model implementations and new feature creations • Work closely with business owners and operations staff to optimize various business operations • Establish scalable, efficient, automated processes for large scale data analyses, model development, model validation and model implementation • Mentor other scientists and engineers in the use of ML techniques • Innovate with the latest GenAI technology to build highly automated solutions for efficient customer promotions • Design, develop and deploy end-to-end machine learning solutions in the Amazon production environment to delight Amazon customers • Collaborate with cross-functional teams to develop comprehensive ML/statistical models that can scale to millions of customers to multiple countries Understand the credit risk data and evaluate the best ml model/ solution for dynamic business problems. About the team Brazil Payments is part of the International Emerging Stores Payments team and focuses on supporting the launch of new payment and financial products to our customers in Brazil.