Principal Risk Manager, Governance & Compliance, Amazon Business

Dallas, Texas, USA

Amazon.com

Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...

View all jobs at Amazon.com

Apply now Apply later

Come be a part of a rapidly expanding $35 billion-dollar global business. At Amazon Business, a fast-growing startup passionate about building solutions, we set out every day to innovate and disrupt the status quo. We stand at the intersection of tech & retail in the B2B space developing innovative purchasing and procurement solutions to help businesses and organizations thrive. At Amazon Business, we strive to be the most recognized and preferred strategic partner for smart business buying. Bring your insight, imagination and a healthy disregard for the impossible. Join us in building and celebrating the value of Amazon Business to buyers and sellers of all sizes and industries. Unlock your career potential.

We are seeking a Security Risk Manager from diverse backgrounds, who are creative problem solvers and passionate about delivering solutions that improve both user experience and security while meeting internal and external standards and compliance requirements.

In this role, you will work across many stakeholders to design solutions that meet global industry standards and regulatory requirements. As part of the team, you will identify industry requirements, evaluate compliance requests, and deliver results that demonstrate the effectiveness of Amazon's internal security controls. In this highly visible role, you will partner with stakeholders across Amazon to execute a risk management approach, identify risks, and act as a thought leader who recommends and leads risk mitigation strategies with system and product owners across Amazon Business. You’ll apply your creative problem-solving skills and work with service teams and partner security teams to provide assurance to customers, as well as, design, build, and execute high-impact security or compliance programs.

Key job responsibilities
You will be responsible for a set of long-term security outcomes. Your day-to-day job responsibilities will include:
• Building ISO 27001, SOC2, and other security and privacy certifications and attestation programs, identifying applicable security controls, assessing compliance gaps and readiness, developing remediation strategies, and driving remediation activities to completion;
• Driving certifications and assessments programs by liaising with external auditors and other Amazon security teams, articulating control implementation and impact, and establishing considerations for applying security, privacy, and compliance concepts to a technical cloud environment;
• Developing and implementing comprehensive security risk management strategies and frameworks to proactively identify, assess, mitigate and monitor security risks to the organization.
• Overseeing the organization's security risk management program, including conducting risk assessments, threat analysis, and vulnerability testing.
• Delivering recommendations and risk interpretations in a clear, concise and audience-specific format
• Developing broad domain and technical knowledge in AWS and Amazon security solutions including the operational processes and controls in place that support InfoSec compliance programs;
• Communicating to key stakeholders and leadership the operational processes around Amazon security practices and how controls are implemented across the environment;
• Communicating to leadership key risks and areas of program improvement, as well as, seek diverse opinions and coordinate improvement efforts;
• Working closely with engineering, compliance, security, and Legal teams to meet compliance and regulatory requirements and design compliance solutions;
• Serving as a subject matter expert and advisor on complex security risk issues.

Basic Qualifications


- 6+ years of compliance, audit or risk management experience
- Knowledge of Microsoft Office products and applications at an advanced level
- Bachelor's degree or equivalent

Preferred Qualifications

- Project Management Professional (PMP) or equivalent certification
- Experience leveraging technology and implementing lean principles / Six Sigma methodologies to drive process improvements or equivalent
- Master's degree or equivalent

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $109,000/year in our lowest geographic market up to $185,000/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Apply now Apply later
Job stats:  2  0  0

Tags: AWS Cloud Compliance Governance ISO 27001 Privacy Risk assessment Risk management SOC 2

Perks/benefits: Equity / stock options Startup environment Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.