Dallas, TX, US
60 days ago
Principal Risk Manager, Governance & Compliance, Amazon Business
Come be a part of a rapidly expanding $35 billion-dollar global business. At Amazon Business, a fast-growing startup passionate about building solutions, we set out every day to innovate and disrupt the status quo. We stand at the intersection of tech & retail in the B2B space developing innovative purchasing and procurement solutions to help businesses and organizations thrive. At Amazon Business, we strive to be the most recognized and preferred strategic partner for smart business buying. Bring your insight, imagination and a healthy disregard for the impossible. Join us in building and celebrating the value of Amazon Business to buyers and sellers of all sizes and industries. Unlock your career potential.

We are seeking a Security Risk Manager from diverse backgrounds, who are creative problem solvers and passionate about delivering solutions that improve both user experience and security while meeting internal and external standards and compliance requirements.

In this role, you will work across many stakeholders to design solutions that meet global industry standards and regulatory requirements. As part of the team, you will identify industry requirements, evaluate compliance requests, and deliver results that demonstrate the effectiveness of Amazon's internal security controls. In this highly visible role, you will partner with stakeholders across Amazon to execute a risk management approach, identify risks, and act as a thought leader who recommends and leads risk mitigation strategies with system and product owners across Amazon Business. You’ll apply your creative problem-solving skills and work with service teams and partner security teams to provide assurance to customers, as well as, design, build, and execute high-impact security or compliance programs.

Key job responsibilities
You will be responsible for a set of long-term security outcomes. Your day-to-day job responsibilities will include:
• Building ISO 27001, SOC2, and other security and privacy certifications and attestation programs, identifying applicable security controls, assessing compliance gaps and readiness, developing remediation strategies, and driving remediation activities to completion;
• Driving certifications and assessments programs by liaising with external auditors and other Amazon security teams, articulating control implementation and impact, and establishing considerations for applying security, privacy, and compliance concepts to a technical cloud environment;
• Developing and implementing comprehensive security risk management strategies and frameworks to proactively identify, assess, mitigate and monitor security risks to the organization.
• Overseeing the organization's security risk management program, including conducting risk assessments, threat analysis, and vulnerability testing.
• Delivering recommendations and risk interpretations in a clear, concise and audience-specific format
• Developing broad domain and technical knowledge in AWS and Amazon security solutions including the operational processes and controls in place that support InfoSec compliance programs;
• Communicating to key stakeholders and leadership the operational processes around Amazon security practices and how controls are implemented across the environment;
• Communicating to leadership key risks and areas of program improvement, as well as, seek diverse opinions and coordinate improvement efforts;
• Working closely with engineering, compliance, security, and Legal teams to meet compliance and regulatory requirements and design compliance solutions;
• Serving as a subject matter expert and advisor on complex security risk issues.
Confirm your E-mail: Send Email