Hawthorne, CA, 90251, USA
1 day ago
Sr. Technical Program Manager, Privacy Controls Assurance, Devices & Services Trust & Privacy (DSTP)
Description Are you passionate about customer trust and privacy! Come join the Devices and Services Trust and Privacy (DSTP) team and help create new processes and mechanisms to safeguard and elevate customer trust across a portfolio of 30+ devices and services. We're looking for a talented Senior Technical Program Manager who can help DSTP meet its vision to deliver Earth’s most trusted devices and services by partnering with builder teams to guide, verify, and build trustworthy customer experiences while adhering to global and emerging regulatory standards. As a Senior Technical Program Manager, Privacy Controls Assurance you will be responsible for designing, conducting, and overseeing privacy controls assurance, conducting control gap assessments, identifying areas of improvement, and recommending appropriate risk reduction activities to builder teams to ensure compliance of customer data. Key job responsibilities * Design and implement a comprehensive and risk-based privacy controls assurance and testing program to evaluate the effectiveness and efficiency of privacy and trust controls across D&S. * Write detailed privacy control test cases and perform comprehensive privacy control assessments to evaluate the design and operating effectiveness of privacy controls in accordance with internal policies, external promises, and legal/regulatory requirements. * Test and evaluate privacy controls to identify drifts and quantify risk to be delivered through proactive compliance reporting to support internal policies, external promises, and legal/regulatory requirements. * Collaborate with cross-functional teams to identify, assess, and prioritize privacy control weaknesses and collaborate with control owners to develop risk mitigation plans for control improvement. * Proactively revise tests, making them flexible, specific, and repeatable so they better expose gaps in complex privacy controls, policies, standards, promises, and procedures. * Stay up to date with emerging privacy risks, threats, vulnerabilities, and evolving privacy controls assurance and testing frameworks to ensure appropriate residual risk calculations. * Coordinate with product and engineering teams to automate tests using internal and open source tools & infrastructure. * Develop a deep understanding of D&S’ infrastructure, applications, and data flows to design a repeatable controls testing methodology, appropriately document assessment findings, and provide mitigation recommendations in a clear and concise manner. * Establish metrics and regular reporting/escalation mechanisms for measuring results, progress, and gaps in performance and compliance. * Communicate plans, status, and critical issues clearly and effectively. * Support deep dive assessments and ad-hoc data analysis requests. A day in the life This is a cross-functional role where you will work directly with engineers, product managers, policy and compliance specialists, and Amazon builders to define and perform comprehensive privacy control tests to evaluate the effectiveness of privacy controls in accordance with internal policies, external promises, and legal/regulatory requirements. You will use your investigative and analytical experience in combination with your technical depth to write complex test cases that represent a vast array of customer environments, interactions, and flows. You will be responsible for knowing the ins and outs of impacted systems, and ensure the impacted builders/owners follow the correct paths to compliance. You should be comfortable working in a fast-paced, rapidly evolving environment with fast delivery time, rapid iteration, and data-driven decision-making. About the team This role is a part of Privacy Governance, Risk, and Compliance (GRC) team within DSTP, which includes developing processes, tools, and compliance mechanisms to improve leadership decision making through an integrated view of how well D&S manages its unique set of privacy and trust risks. Our GRC team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and are building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded professional and enable them to take on more complex tasks in the future. Basic Qualifications - 7+ years of technical program management working directly with software engineering teams experience - Experience managing programs across cross functional teams, building processes and coordinating release schedules - Bachelor's degree in engineering, computer science or equivalent - Experience defining technical requirements and specifications, writing procedures, adapting requirements to technical and business needs, implementing repeatable processes and driving automation or standardization, and using data and metrics to determine improvements. Preferred Qualifications - 7+ years of project management disciplines including scope, schedule, budget, quality, along with risk and critical path management experience - 7+ years of experience demonstrating the ability to follow procedure, be detail-oriented, and produce accurate results, while remaining flexible, insightful, and able to see “outside the box”. - 7+ years of experience finding, using, and analyzing information and/or data in support of complex analytical, investigative risk and incident investigations, risk assessment, or policy analysis. - 7+ years of experience briefing leadership on complex situations. - Familiarity with CI/CD automation frameworks (especially using Python and Java) - Broad understanding of cloud computing, LLM/AI/ML technology and trends, privacy regulations (e.g., GDPR, CCPA, COPPA, HIPAA), privacy GRC framework, and privacy risk management methodologies and tooling. Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner. Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $133,900/year in our lowest geographic market up to $231,400/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits . This position will remain posted until filled. Applicants should apply via our internal or external career site.
Confirm your E-mail: Send Email