Jobs

    Sr. Security Governance Specialist - Seattle, United States - Amazon, Inc.

    Amazon, Inc.
    Amazon, Inc. Seattle, United States

    3 weeks ago

    Default job background
    Description


    Are you passionate about security and access governance, monitoring and risk management? Buy with Prime and Multi-Channel Fulfillment (MCF) are looking for a highly motivated and experienced Security Governance Specialist ready to partner across Amazon tech and security groups to secure and protect our services and data.

    This security specialist will drive programs focused on providing multiple cross-cutting capabilities such as Access governance, Access policy management, security monitoring and detection, risk management, and continuous monitoring.

    You will act as a key member of the team responsible for Security Operations including Access Governance, security design, and exception activities, including automation.

    Candidates must have experience designing access control solution, access governance and risk management experience, including performing control self-assessments and managing external audits, designing controls, and prioritizing risk.


    We operate in a hyper-growth environment where priorities shift quickly, so a passion and discipline around security and delivery is critical.

    You will tackle challenging situations every day and, given the size of this initiative, you will collaborate with various levels across Buy with Prime, MCF and Amazon.

    We are seeking a security specialist, who is comfortable working in a fast-paced, ever-changing environment and willing to dive deep into assessments and analytical rigor.

    Our team is growing, and we need security specialists who don't work reactively, but can operate independently, anticipate potential security challenges, and proactively monitor and improve the mechanisms we use to detect and correct potential non-compliance.

    The ability to partner with Service Teams and develop automated mechanisms and responses to potential instances of non-compliance will be key to scale the security program in key areas of Access Management, Risk Management, and Continuous Monitoring.

    Key job responsibilities


    • Design, implement and manage access control governance process and access control policies
    • Analyze business, product and security data, uncover evolving threats, identify weaknesses and opportunities in risk defense
    • Apply a working knowledge of information security and privacy regulation and policy to articulate customer and control impact and drive alignment to controls.
    • Quantify risk control effects and trends, collaborate with engineering, operational and product teams, contribute to risk measurement, mitigation and prevention.
    • Build detections rules to recognize, prevent and mitigate access violations.
    • Establish regular reporting mechanisms for measuring compliance and performance;
    • Develops metrics that demonstrate the current risk state, indicators of progress, and business alignment
    • Support Continuous Monitoring initiatives to drive enforcement, oversight and improvement of security controls implementation through automation
    • Perform quality reviews on identified risks to drive adherence to policy and playbook requirements
    • Provide guidance to technology owners on the execution of security and compliance requirements, related processes and playbooks, and usage of related systems and tools
    • Collaborate with tech and process owners to identify, document, and manage the performance of technology risk concerns
    • Assist business and process owners with remediating risks (including Audit Identified Issues, Self-Identified Issues, Risk Identified Issues, and Regulatory Issues) and achieving compliance with multiple policies and standards
    • Partner with tech and security teams and to review and challenge identified risks, remediation plans, progress and status, and drive action as needed
    • Monitor and oversee performance against Key Risk Indicators, including "Path to Green" plans
    • Drive the successful achievement of business goals, including timely identification, escalation and remediation of risks and issues that impact program execution and delivery
    • Active participation during the identification, remediation, and oversight of technology issues/ risks; including action plan development and execution
    About the team

    Buy with Prime is helping people reimagine the way they shop.

    Our vision is to enable every entrepreneur in the world to reach every customer in the world through every channel they can imagine.

    Buy with Prime is a new way to extend Prime shopping benefits-including fast, free shipping, seamless checkout experience, and free returns-to merchants' own online stores, ultimately increasing selection for Prime members.

    Buy with Prime is an exciting next step in our mission to help merchants of all sizes grow their business-whether on Amazon or beyond.

    Mentorship & Career Growth

    Our team is dedicated to supporting new members.

    We have a broad mix of experience levels and tenures, and we're building an environment that celebrates knowledge sharing and mentorship.

    Work/Life Balance

    Our team puts high value on work-life balance.

    Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren't focused on how many hours you spend at work or online.

    Instead, we're happy to offer a flexible schedule so you can have a more productive and well-balanced life-both in and outside of work.

    We are open to hiring candidates to work out of one of the following locations:

    Arlington, VA, USA | Santa Clara, CA, USA | Seattle, WA, USA | Tempe, AZ, USA


    BASIC QUALIFICATIONS

    • 5+ years of governance, risk, and monitoring experience for a large and complex organization
    • Strong knowledge of security certification and compliance frameworks (e.g. ISO 27001, AICPA SOC 1/2/3, HIPAA, HiTRUST, and NIST SP / CMMCv2) and ability to adapt and apply them- in conjunction with business requirements- as required
    • Knowledge of cloud-based models (IaaS, PaaS, SaaS) and technologies used to implement controls within these environments
    • Ability to communicate and manage information security concepts and requirements to personnel of varying technical backgrounds and positions
    • Understand and ensure compliance and risk management requirements for supported area and work with other stakeholders to implement key risk initiatives
    • Functional experience across two or more information and cyber security domains (e.g., application security, identity and access management, vulnerability management, Continuous Monitoring)

    PREFERRED QUALIFICATIONS

    • Good understanding of Fine Grained Access controls and working knowledge of creating, managing and monitoring access policies.
    • A fast learner who can quickly absorb the nuances and behaviors of Amazon's systems architecture.
    • Effective analytical skills. Proven history of analyzing data and situations to identify meaningful observations.
    • Strong critical thinking skills, consistent attention to detail and ability to meet deadlines amidst competing priorities
    • Strong relationship management skills to navigate the complexities of aligning stakeholders, building consensus and resolving conflicts in a large, distributed organization
    • Proven ability to manage multiple and often competing priorities in a global environment; Ability to drive routines, projects and programs with a track record of successful execution / change
    • Ability to decompose complex issues and drive timely decisions, knowing when to engage others for additional input or escalation; ability to synthesize information in order to drive results
    • Strong communication skills (written and oral); Ability to communicate complex ideas in a clear and concise manner, including to senior business leaders and executives
    • Participation in cross-functional teams and ability to work effectively in a geographically dispersed team
    Amazon is committed to a diverse and inclusive workplace.

    Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

    For individuals with disabilities who would like to request an accommodation, please visit

    Our compensation reflects the cost of labor across several US geographic markets.

    The base pay for this position ranges from $95,500/year in our lowest geographic market up to $229,700/year in our highest geographic market.

    Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.

    Amazon is a total compensation company.

    Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits.

    For more information, please visit This position will remain posted until filled. Applicants should apply via our internal or external career site.


  • Neighborcare Health Seattle, United States

    SUMMARY: · The Insurance Reimbursement Supervisor works alongside the Insurance Reimbursement and Patient Financial Specialist. They will work with the team to ensure the collection of and to maximize revenue opportunities through daily/regular oversight of the team by ensuring c ...


  • Milliman Seattle, United States

    POSITION SUMMARY: · The Governance/Corporate Paralegal works with the Assistant Corporate Secretary and the Governance team of Milliman's Legal Department primarily related to corporate governance of Milliman's entity portfolio. Tasks will have direct visibility to C-Suite execut ...


  • University of Washington Seattle, United States

    Enterprise Records and Health Information has an outstanding opportunity to for an OUTPATIENT SURGERY CODER. · WORK SCHEDULE · 8:00 am - 5:00 pm · Mondays - Fridays · 100% Remote · POSITION HIGHLIGHTS · Implements the mission and goals of Enterprise Records and Health Information ...


  • AIS Inc Seattle, United States

    A.I.S., Inc. (AIS) is a national scientific services firm supporting maritime activities requiring certification of compliance with environmental regulations as well as collecting data for use by Federal, State, Municipal, and other government agencies along the US coastline. · P ...


  • AIS Inc Seattle, United States

    A.I.S., Inc. (AIS) is a national scientific services firm supporting maritime activities requiring certification of compliance with environmental regulations as well as collecting data for use by Federal, State, Municipal, and other government agencies along the US coastline. · P ...


  • Walden Security Seattle, United States

    Walden Security is currently offering a sign on bonus of $1000 paid after 90 days on the contract. They are recruiting experienced Court Security Officers. CSOs will provide armed security to courthouses under the USMS contract. · Essential Duties and Responsibilities: Includes t ...


  • AbbVie, Inc Seattle, United States

    Company Description · AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas ...

  • University of Washington

    Inpatient Analyst

    1 week ago


    University of Washington Seattle, United States

    UW Medicine Enterprise Records and Health Information has an outstanding opportunity for an INPATIENT ANALYST. · WORK SCHEDULE · 8:00 am - 5:00 pm · Mondays - Fridays · 100% FTE, Remote · POSITION HIGHLIGHTS · Performs daily activities related to coding auditing, education and tr ...


  • solventum Seattle, United States

    Thank you for your interest in working for our Company. Recruiting the right talent is crucial to our goals. On April 1, 2024, 3M Healthcare underwent a corporate spin-off leading to the creation of a new company named Solventum. We are still in the process of updating our Career ...


  • Education Realty Trust Inc. Seattle, United States

    Ensures the physical aspects of the community are maintained and standards are met regarding the grounds, amenities and overall curb appeal and provides support to the service team members · JOB DESCRIPTION · * Job Description · Essential Responsibilities: · 1. Inspects the commu ...

  • Education Realty Trust Inc.

    Porter - Slate

    3 weeks ago


    Education Realty Trust Inc. Seattle, United States

    Ensures the physical aspects of the community are maintained and standards are met regarding the grounds, amenities and overall curb appeal and provides support to the service team members · JOB DESCRIPTION · In addition to our competitive compensation, we offer housing discounts ...


  • King County (WA) Seattle, United States

    Summary · This recruitment is open to King County employees only. · King County's Finance and Business Operations Division, Financial Management section, is seeking a Accounts Receivable Specialist (Fiscal Specialist 3) · The King County Financial Management Section, Accounts Rec ...


  • Otis Worldwide Seattle, United States

    Date Posted: · Country: · United States of America · Location: · OT372: SS - SEATTLE, WA 3315 South 116th Street #149, Seattle, WA, 98168 USA · Otis Elevator Company is searching for a highly motivated Manager, Modernization Field Operations to drive productivity and the performa ...


  • Otis Worldwide Seattle, United States

    Date Posted: · Country: · United States of America · Location: · OT372: SS - SEATTLE, WA 3315 South 116th Street #149, Seattle, WA, 98168 USA · The Seattle, WA service branch of Otis Elevator Company is searching for a highly motivated Field Operations Manager to oversee the repa ...


  • DESC Seattle, United States

    Apply · Job Type · Full-time · Description · Days Off: Thursday, Friday & Saturday · Shift: Night (11pm - 9:30am) · Insurance Benefits: Medical (no premiums/payroll deductions for employee coverage) , Dental, Life, Long-term Disability · Other Benefits: Employee Assistance Progra ...


  • Stantec Inc. Seattle, United States

    Senior Environmental Planning & Permitting Specialist PU ) · Description · At Stantec, we believe a healthy environment is fundamental to our communities, natural habitat, and the planet - our work is instrumental in responsible development, ecological/habitat restoration, resili ...


  • City of Seattle, WA Seattle, United States

    With more than 200 attorneys and professional staff, the Seattle City Attorney's Office is one of the largest law offices in Seattle and is the third largest public law office in the state. Our office is committed to making Seattle a safe, healthy, empowered and thriving communit ...


  • University of Washington Seattle, United States

    This is an entry level, full-time, non-renewable 12-month position from July 1, 2024 through June 30, 2025. · Washington Athletics aims to inspire champions in competition and in the classroom. We exist to enrich the lives of students to positively impact our community and world ...


  • Otis Worldwide Seattle, United States

    Date Posted: · Country: · United States of America · Location: · OT372: SS - SEATTLE, WA 3315 South 116th Street #149, Seattle, WA, 98168 USA · Looking to advance your leadership career at a fast-paced, Fortune 500 company? Join our team as General Manager and play a crucial role ...


  • Forterra Seattle, United States

    Revenue Stream Staff Accountant · Forterra innovates and scales land-based solutions to address the climate crisis and support equitable, green and prosperous communities. Forterra envisions people and nature thriving together in a place where everyone belongs. Forterra seeks to ...