Security Controls Specialist, AWS Security Assurance Engineering

At Amazon Web Services (AWS), Security is our highest priority. The AWS Security Assurance team is responsible for demonstrating the security controls of services offered by AWS. At AWS' scale, we invent new ways to provide the highest level of assurance to our most regulatory conscious customers. We are looking for a person motivated to take on challenges with a technical background to be part of a growing team that analyzes AWS controls. As part of the AWS Security Assurance team, you will be seen as an expert in how AWS control systems and processes meet security and compliance standards. You will be a key liaison with AWS service teams, infrastructure teams, AWS Security, and related Amazon corporate teams. You will have the ability to dive deep, understand, document, and communicate IT systems and processes, and be able to drive innovative process changes through multiple organizations and teams. You are someone who loves working across many stakeholders to design solutions for complex compliance challenges. We have a team culture that encourages ownership, diversity, inclusion, and innovation. We expect team members and management alike to take a high degree of ownership for their program vision and execution of ideas. You will work have an opportunity to work directly with most divisions within AWS service to improve AWS’ ability to demonstrate assurances for regulated customers.This role can be based out of one of the following locations: New York City, NY; Arlington or Herndon, VA; Seattle, WA; or Dallas, TX.Key job responsibilities
  • Manage requests for control intake, changes and mapping.
  • Delivering campaigns to define complex control requirements taking into account compliance, security and technical feedback.
  • Fielding and addressing requests in collaboration with internal stakeholders related to control implementations and evidence.
  • Developing engineering requirements to build tooling to collect, assess and monitor control operational status.
  • Managing GRC technology solutions to enable workflow, access and lifecycle related activities to drive use of control implementations consistently across AWS.
A day in the lifeInclusive Team CultureHere at AWS, we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employee-led affinity groups, reaching 40,000 employees in over 190 chapters globally. We have innovative benefit offerings, and we host annual and ongoing learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences. Amazon’s culture of inclusion is reinforced within our 16 Leadership Principles, which remind team members to seek diverse perspectives, learn and be curious, and earn trust.    Mentorship & Career GrowthOur team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. Our senior members enjoy one-on-one mentoring. We care about your career growth as a passionate learner that is motivated to take on challenges.    Work/Life BalanceOur team also puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well balanced life—both in and outside of work.

Basic Qualifications

  • Bachelor's Degree in Computer Science or other related fields, or equivalent experience.
  • 5+ years of experience in project/program management in a technical field.
  • 5+ years developing, assessing, and/or evaluation of controls with in the context of audits and security compliance assessments.

Preferred Qualifications

  • Have expertise in security control domains such as Identity and access management, data protection, privacy, business continuity and resiliency, risk management, vulnerability management, physical security or other security and risk domains.
  • Experience conducting assessments, audits or evaluations against global control frameworks.
  • Experience with monitoring and automating security controls.
  • Have a record of delivery of IT process improvement projects with technology processes and/or major tech companies.
  • Have experience in cloud technologies, cloud deployment models (IaaS/PaaS/SaaS), and familiarity with AWS core services (EC2, S3, DDB, RDS, KMS, etc.).
  • Have experience in performing technical assessments and documentation of network, operating systems, application security, as well as auditing IT processes, including working knowledge of NIST 800-53 controls.
  • Have an understanding of evaluating the design and effectiveness of IT controls.
  • Certifications such as CISA, CISM, CISSP or other security, technical or audit related areas
  • Meets/exceeds Amazon’s leadership principles requirements for this role.
  • Meets/exceeds Amazon’s functional/technical depth and complexity for this role.
#SecurityAssurance Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $127,300/year in our lowest geographic market up to $210,400/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit Applicants should apply via our internal or external career site.

Cyber Security Jobs by Category

Cyber Security Salaries