Amazon.com Services LLC
Technology
SecurityIndustrySpecialist,Subsidiary&AcquisitionGRC
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Security Industry Specialist, Subsidiary & Acquisition GRC at Amazon.com Services LLC. Skills: Security risk, Compliance, Audit. Understand regulatory requirements. Assess compliance needs”
What You'll Achieve.
Ensure successful audit executions; Promote transparency across measures
Industry & Context.
Identify compliance needs; Assess issues; Develop recommendations; Review security controls; Troubleshoot vulnerabilities
What They're Looking For.
Must Have
3+ years IT platform implementation, Bachelor's degree in computer science or equivalent, 5+ years IT Security experience, 3+ years performing technical assessments, Experience in security or compliance consulting
Nice to Have
Master's degree in technical or engineering field, 1+ years technical specialist experience, 1+ years design and architecture experience, AWS Professional level certification, Experience communicating across technical and non-technical audiences, Experience with compliance & security standards
What You'll Do.
Understand regulatory requirements
Assess compliance needs
Assess maturity of processes
Assess maturity of controls
Design security programs
Build security programs
Execute security programs
Design compliance programs
Build compliance programs
Execute compliance programs
Ensure successful audit executions
Identify compliance needs
Assess data protection issues
Develop data protection recommendations
Assess insider threat issues
Develop insider threat recommendations
Assess third party risk issues
Develop third party risk recommendations
Ensure compliance to policies
Review technical security controls
Develop security risk metrics
Maintain control libraries
Maintain compliance requirements
Provide business interpretations
Support automation opportunities
Articulate control implementation
Articulate control impact
Establish security considerations
Establish privacy considerations
Establish compliance considerations
How You'll Work.
Team & Collaboration
Business teams; Security teams; Stakeholder teams; Privacy teams; Legal teams; HR teams; IT teams; Business and SMEs; Multiple organizations; Multiple teams
Communication Scope
Communicate to customers; Communicate across audiences
Full Job Description
Blink (Amazon’s subsidiary) Security team is growing and looking for a highly motivated security risk & compliance specialist to join our team and drive regulatory compliance requirements for our products. In this role, you will work collaboratively with various business and security teams across Amazon to identify compliance needs, assess the maturity of processes and controls, design, build, and execute high-impact security or compliance programs to ensure successful audit executions. You should be a technically experienced and innovative security, risk, compliance, and audit professional who has the ability to understand systems, security, and privacy processes, communicate to customers, and to be able to drive innovative process changes through multiple organizations and teams. Key job responsibilities • Understand and rationalize regulatory requirements for service and device security • Proactively assess, identify and develop recommendations regarding data protection, insider threat, data sharing, identity and access management, and third party risk issues and vulnerabilities by working with multiple stakeholder teams, including Privacy, Legal, HR, IT, etc • Engage with the Business and SMEs to ensure compliance to information security policies • Review security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity • Develop and maintain relevant security risk metrics to promote transparency across the organization; measures, monitors and reports on information security risks to management • Maintain control libraries and compliance requirements and guidance materials for various security standards and regulations. • Provide business specific interpretations and support automation opportunities • Liaise with auditors, articulate control implementation and impact, and establish considerations for applying security, privacy and compliance concepts to a technical cloud enviro
Applying for this Security Industry Specialist, Subsidiary & Acquisition GRC role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
ANONYMOUS · UNFILTERED
What do employees actually say about Amazon.com Services LLC?
Real rants from real employees. Read before you apply.