Find your next role
Discover amazing opportunities across our network of companies committed to gender equality in the workplace.
Amazon
The Stores Security and Regulatory Compliance (Stores SRC) organization is currently hiring for a Security Industry Specialist to join our Customer and Industry Security Compliance (CISC) team.
SRC is comprised of teams that provide consistent high-level judgement to help Amazon businesses and subsidiaries comply with security regulations, policies and Amazon’s high bar for security. The CISC Team sits within Stores SRC and serves as the primary Security Assurance team for Enterprise certifications of ISO 27001, SOC2 type 2, PCI DSS, CE and CE+ as well as Compliance reviews and external security due diligence reviews for sales enablement in Amazon.
The CISC team is hiring a Security Compliance Specialist to focus on preparing for and supporting third-party attestation audits. This includes preparing reports and regulatory/industry certifications along with developing standard security response protocols for third-party inquiries submitted to Amazon, Amazon’s corporate customers, business associates, and other third party (3P) partners.
The SRC team obsesses over our customers and work to ensure that they are confident that Amazon cares about data confidentiality, integrity, and availability by providing third-party attestations as proof of compliance. To support successful attestations, the SRC team identifies applicable controls, assesses their effectiveness, and works with control owners to remediate the findings.
The successful candidate will be a technically experienced and innovative security and compliance professional who has the ability to understand security processes, effectively communicate with technical teams and business leaders alike, and be able to drive automated and scalable process improvements across internal organizations and teams.
Key job responsibilities
- Understand and serve as a subject-matter expert around Amazon security controls
- Dive deep into the Amazon control environment to develop broad domain and technical understanding of control activities and implementation to articulate compliance to key stakeholders.
- Developing a knowledge base of Amazon control activities and implementations; vetting with business partners and security stakeholders
- Communicate to leadership key risks and areas of program improvement, as well as seek diverse opinions and coordinate improvement efforts.
- Develop broad domain and technical understanding of Industry requirements and regulatory expectations to drive process improvement initiatives
- Preparing for and supporting assessments and audits for PCI DSS, SOC2, ISO 27001, US Government regulations/standards, and other certifications and assessments by identifying applicable controls, assessing control readiness for third-party assessments, recommending appropriate remediation strategies, and tracking remediation activities to completion.
- Driving and managing individual projects and campaigns with excellent project management skills.
- Clearly communicating vision, deliverables, and project status to management and key technical and business stakeholders.
- Delivering recommendations and risk interpretations in a clear, concise and audience-specific format.
A day in the life
Daily activities involve the full spectrum and full lifecycle of GRC activities in support of a range of different audits and attestation activities, and once familiar with workflows, including identifying and innovating ways to improve existing processes
About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
The CISC Team has a manager responsible for several PCI DSS team members, an ISO 27001 team member also responsible for CE/CE+ certification, a SOC2 type 2 team member, a Sales Enablement team member, and one dedicated to Regulatory compliance risk assessment and implementation. Culture is per the Privacy main mission - deliver Trust to internal and external customers, nailing the North star of delivering Audits, Attestations and making things clear, repeatable and smooth for all stakeholders.