Security Assessor II, SRC Security Assurance
Seattle, Washington, USA
Full Time Mid-level / Intermediate USD 91K - 196K
Amazon.com
Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...
Amazon Security is looking for a Security Industry Specialist focused on driving information security compliance for Amazon's Healthcare and Payments systems. This role will provide advisory guidance to new and existing businesses at Amazon, and will regularly conduct deep dives into critical risk areas. If you enjoy working in a rapidly changing environment and influencing the strategic security and compliance direction of a large global organization, this position will provide you with a challenging opportunity. You will be responsible for driving consensus across teams to define and influence the secure and compliant design of systems worldwide, in a scalable way.
Key job responsibilities
- Understands and rationalizes compliance requirements in the healthcare and payments domains. Provides business specific interpretations and supports automation opportunities while working with Dev teams.
- Establishes credibility and maintains strong working relationships with groups involved with payment security and compliance matters (Stores Security, Legal, Business Development, Internal Audit, Fraud, Physical Security, Developer Community, Networking, Systems, etc.).
- Collaborates with Compliance Specialists and business/service teams to understand and validate assessment scope.
- Reviews security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity to assess whether the controls are implemented and operating effectively.
- Responsible for building and influencing security as a core competency throughout our relationships with internal teams/partners/vendor; this includes providing education and training to the organization.
- Delivers recommendations and risk interpretations in a clear, concise and audience-specific format
- Engages with the Business and SMEs to ensure compliance to information security policies
- Supports data analysis requests to identify trends and provide valuable insights to the leadership.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- Bachelor’s degree in Management Information Systems, Computer Science or relevant field
- 3+ years of relevant industry experience including information assurance, data privacy and compliance in payments or healthcare domains.
- 3+ years of information security governance, audit, risk management or related client service or consulting experience.
- Skilled in risk management, business risk analysis and making complex business/risk trade-off recommendations and decisions.
- Technical knowledge and familiarity with information security standards and frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Related security control and compliance experience in various frameworks including: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, etc.
- CISSP, CISA, CISM, CIPP, CEH and/or other comparable security controls or audit certifications preferred.
- Experience with service-oriented architectures, web services security and cloud security (preferably AWS cloud services).
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $91,800/year in our lowest geographic market up to $196,300/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
Key job responsibilities
- Understands and rationalizes compliance requirements in the healthcare and payments domains. Provides business specific interpretations and supports automation opportunities while working with Dev teams.
- Establishes credibility and maintains strong working relationships with groups involved with payment security and compliance matters (Stores Security, Legal, Business Development, Internal Audit, Fraud, Physical Security, Developer Community, Networking, Systems, etc.).
- Collaborates with Compliance Specialists and business/service teams to understand and validate assessment scope.
- Reviews security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity to assess whether the controls are implemented and operating effectively.
- Responsible for building and influencing security as a core competency throughout our relationships with internal teams/partners/vendor; this includes providing education and training to the organization.
- Delivers recommendations and risk interpretations in a clear, concise and audience-specific format
- Engages with the Business and SMEs to ensure compliance to information security policies
- Supports data analysis requests to identify trends and provide valuable insights to the leadership.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Basic Qualifications
- Bachelor’s degree in Management Information Systems, Computer Science or relevant field
- 3+ years of relevant industry experience including information assurance, data privacy and compliance in payments or healthcare domains.
- 3+ years of information security governance, audit, risk management or related client service or consulting experience.
- Skilled in risk management, business risk analysis and making complex business/risk trade-off recommendations and decisions.
- Technical knowledge and familiarity with information security standards and frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
Preferred Qualifications
- Masters degree in Management Information Systems, Computer Science or relevant field with 5+ years of relevant industry experience including information assurance, data privacy and compliance in payments or healthcare domains- Related security control and compliance experience in various frameworks including: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, etc.
- CISSP, CISA, CISM, CIPP, CEH and/or other comparable security controls or audit certifications preferred.
- Experience with service-oriented architectures, web services security and cloud security (preferably AWS cloud services).
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $91,800/year in our lowest geographic market up to $196,300/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
Job stats:
0
0
0
Tags: Audits Automation AWS CEH CIPP CISA CISM CISSP Cloud Compliance Computer Science Encryption GLBA Governance HIPAA HITRUST NIST PCI DSS Privacy Risk analysis Risk management
Perks/benefits: Career development Equity / stock options Flex hours Startup environment Team events
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information System Security Officer jobsSenior Security Analyst jobsProduct Security Engineer jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSystems Engineer jobsSenior Information Security Analyst jobsInformation Security Manager jobsSenior Network Security Engineer jobsIT Security Engineer jobsCyber Security Specialist jobsChief Information Security Officer jobsIT Security Analyst jobsSecurity Consultant jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Information Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsThreat Intelligence Analyst jobsCyber Security Architect jobsSecurity Operations Analyst jobs
SaaS jobsTS/SCI jobsBash jobsEncryption jobsEDR jobsThreat detection jobsIDS jobsMalware jobsSplunk jobsIPS jobsTerraform jobsSDLC jobsTop Secret jobsFinance jobsSQL jobsForensics jobsDocker jobsRMF jobsIntrusion detection jobsSOC 2 jobsCompTIA jobsITIL jobsOWASP jobsActive Directory jobsDoDD 8570 jobs
GIAC jobsAnsible jobsVPN jobsTCP/IP jobsHIPAA jobsSANS jobsUNIX jobsIT infrastructure jobsSOAR jobsSAP jobsData Analytics jobsClearance Required jobsCRISC jobsCCSP jobsOSCP jobsPolygraph jobsMITRE ATT&CK jobsJira jobsJavaScript jobsMachine Learning jobsBanking jobsSOX jobsSecurity strategy jobsDNS jobsNIST 800-53 jobs