Jobs · Project Management · Washington

Privacy Engineer, Incident Response, Devices & Services Trust, Privacy, and Accessibility (TPA)

Amazon · Bellevue, WA · 6 days ago
Project ManagementFull-time

About the role

The Security and Privacy Incident Response Engineer manages escalated privacy and trust risk events/cases from start to finish. They write detailed case notes, reports, summaries, short and long-term recommendations, and trade-off analyses for all audiences, including senior leadership. They interact with and influence other teams to support decisions on containing incidents or mitigating privacy and trust risks, build consensus and recommendations based on analysis of the nature of potential violations to Privacy Policies, Promises, or Legal/Regulatory requirements. They own successful delivery of large, impactful, and highly cross-functional program initiatives while simultaneously tracking a set of smaller projects.

Responsibilities

  • Manage escalated privacy and trust risk events/cases from start to finish; write detailed case notes, reports, summaries, short and long-term recommendations, and trade-off analyses for all audiences, including senior leadership.
  • Interact with and influence other teams (e.g., service teams, engineering, product, legal); identify experts and stakeholders on other teams to support decisions on containing incidents or mitigating privacy and trust risks; build consensus and recommendations based on analysis of the nature of potential violations to Privacy Policies, Promises, or Legal/Regulatory requirements.
  • Own successful delivery of large, impactful, and highly cross-functional program initiatives while simultaneously tracking a set of smaller projects.
  • Demonstrate comfort with handling technical investigations and analysis, and provide actionable recommendations to senior leadership audience with minimal supervision.
  • Develop deep knowledge of global privacy and data governance obligations, processes, best practices, and solutions utilized by Amazon.
  • Utilize this knowledge to provide recommendations and consultation to improve DSTP processes and tooling and reduce risk through control automation and enhancements.
  • Establish metrics and regular reporting/escalation mechanisms for measuring results, progress, and gaps in performance and compliance.
  • Communicate plans, status, and critical issues clearly and effectively.
  • Support deep dive assessments and ad-hoc data analysis requests.

Requirements

Basic Qualifications:

  • Bachelor's degree in computer science or equivalent
  • 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • CCSP (Certified Cloud Security Professional) or CEH (Certified Ethical Hacker) or CFR (CyberSec First Responder) or Cloud+ or CySA+ (CompTIA Cybersecurity Analyst) or GCED (GIAC Certified Enterprise Defender) or GICSP (Global Industrial Cyber Security Professional) or PenTest+

Preferred Qualifications

  • Experience applying threat modeling or other risk identification techniques or equivalent
  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls

Similar jobs

Privacy Engineer

Western Alliance BankPhoenix, AZ· 1 mo ago
Engineeringapply on westernalliancebank.wd5.myworkdayjobs.com

Staff Privacy Engineer

Rivian and Volkswagen Group TechnologiesIrvine, CA· 3 wk ago
Engineering$190k–$238k/yrapply on jobs.ashbyhq.com