Description
The Stores Security and Regulatory Compliance (Stores SRC) organization is currently hiring for a Security Industry Specialist to join our Customer and Industry Security Compliance (CISC) team.
SRC is comprised of teams that provide consistent high-level judgement to help Amazon businesses and subsidiaries comply with security regulations, policies and Amazon's high bar for security. The CISC Team sits within Stores SRC and serves as the primary Security Assurance team for Enterprise certifications of ISO 27001, SOC2 @type 2, PCI DSS, CE and CE+ as well as Compliance reviews and external security due diligence reviews for sales enablement in Amazon.
The CISC team is hiring a Security Compliance Specialist to focus on preparing for and supporting third-party attestation audits. This includes preparing reports and regulatory/industry certifications along with developing standard security response protocols for third-party inquiries submitted to Amazon, Amazon's corporate customers, business associates, and other third party (3P) partners.
The SRC team obsesses over our customers and work to ensure that they are confident that Amazon cares about data confidentiality, integrity, and availability by providing third-party attestations as proof of compliance. To support successful attestations, the SRC team identifies applicable controls, assesses their effectiveness, and works with control owners to remediate the findings.
The successful candidate will be a technically experienced and innovative security and compliance professional who has the ability to understand security processes, effectively communicate with technical teams and business leaders alike, and be able to drive automated and scalable process improvements across internal organizations and teams.
Key job responsibilities
Understand and serve as a subject-matter expert around Amazon security controls
Dive deep into the Amazon control environment to develop broad domain and technical understanding of control activities and implementation to articulate compliance to key stakeholders.
Developing a knowledge base of Amazon control activities and implementations; vetting with business partners and security stakeholders
Communicate to leadership key risks and areas of program improvement, as well as seek diverse opinions and coordinate improvement efforts.
Develop broad domain and technical understanding of Industry requirements and regulatory expectations to drive process improvement initiatives
Preparing for and supporting assessments and audits for PCI DSS, SOC2, ISO 27001, US Government regulations/standards, and other certifications and assessments by identifying applicable controls, assessing control readiness for third-party assessments, recommending appropriate remediation strategies, and tracking remediation activities to completion.
Driving and managing individual projects and campaigns with excellent project management skills.
Clearly communicating vision, deliverables, and project status to management and key technical and business stakeholders.
Delivering recommendations and risk interpretations in a clear, concise and audience-specific format.
A day in the life
Daily activities involve the full spectrum and full lifecycle of GRC activities in support of a range of different audits and attestation activities, and once familiar with workflows, including identifying and innovating ways to improve existing processes
About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.
The CISC Team has a manager responsible for several PCI DSS team members, an ISO 27001 team member also responsible for CE/CE+ certification, a SOC2 @type 2 team member, a Sales Enablement team member, and one dedicated to Regulatory compliance risk assessment and implementation. Culture is per the Privacy main mission - deliver Trust to internal and external customers, nailing the North star of delivering Audits, Attestations and making things clear, repeatable and smooth for all stakeholders.
Basic Qualifications
5+ years experience assessing complex technical processes
Experience in developing unified frameworks that include more than one of the following: ISO, SOC, NIST, PCI DSS, common regulatory regimes e.g. GDPR, US relevant regulations, etc.
Direct experience in working with security and business teams on controls design to address regulatory compliance requirements
Preferred Qualifications
Bachelor's degree, or BS degree
Demonstrated understanding of cloud computing services/architecture
Experience with using GRC tooling
Have a standard industry recognized certification such as (but not limited to) CISSP, CISA, CRISC and CISM.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .
USA, TX, Austin - 102,000.00 - 178,400.00 USD annually
USA, WA, Seattle - 102,000.00 - 178,400.00 USD annually