Jobs · Management · Washington

Security Compliance Specialist, Devices & Services Security Compliance

Amazon · Seattle, WA · Yesterday
ManagementFull-time

About the role

Amazon’s Devices & Services Security Compliance team is growing and looking for a highly motivated security compliance specialist to help us enhance and integrate our governance and compliance programs. You will help to determine the high security bar we hold for our products, analyze regulatory and certification requirements, and ensure we have sufficient enforcement mechanisms to keep our products and services safe for our customers.

Responsibilities

  • Understand and rationalize compliance requirements for service and device security.
  • Provide business specific interpretations and support automation opportunities
  • Review security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity
  • Engage with the Business and SMEs to define and ensure compliance to information security policies
  • Maintain control libraries and compliance requirements and guidance materials for various security standards and regulations

About The Team

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Qualifications

Basic Qualifications: Bachelor's degree or equivalent in Computer Science, Engineering, Information Systems Management, Information Security or other related fields, 4+ years of IT Security experience, 5+ years of compliance, audit or risk management experience, Experience working with multiple security frameworks and regulations like ISO 27001/2, HIPAA, NIST 800-53, NIST CSF

  • Preferred Qualifications: Experience working directly with security and engineering teams
  • Knowledge of AWS tech stack (e.g., AWS Redshift, S3, EC2, Glue)
  • Experience implementing repeatable processes and driving automation or standardization
  • Experience handling ambiguous or undefined challenges through strong problem solving abilities
  • Experience creating and delivering written and oral communications for technical and non-technical audiences
  • Knowledge of one or more of the following domains: access-control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security
  • Experience supporting security compliance for medical devices or software (e.g. HIPAA, HITRUST)
  • Experience with hardware and software development processes, products launches and lifecycles of devices and/or services

Skills

This role requires a technically experienced and innovative security governance, risk, and compliance professional who has the ability to understand systems, security, and privacy processes, communicate to customers, and to be able to drive innovative process changes through multiple organizations and teams.

Similar jobs