Job is more than 1 month old.
Job Details
Posted date: Sep 04, 2024
Location: Austin, TX
Estimated salary: $168,550
Range: $107,400 - $229,700
Description
The Security and Regulatory Compliance (SRC) organization is comprised of teams that provide consistent high-level judgement to help Amazon businesses comply with security regulations, policies, and Amazon鈥檚 high bar for security. The PCI Team serves as the primary security compliance team for Amazon. This role will provide advisory guidance to new and existing businesses at Amazon, and will conduct deep dives into critical security risk areas. If you enjoy working in a rapidly changing environment and influencing the strategic direction of a large global organization, this position will provide you with a challenging opportunity. You will be responsible for driving consensus across teams to define and influence the secure and compliant design of systems worldwide.Key job responsibilities
* Lead planning and execution of PCI assessments which includes review of control design with a focus on payment card compliance and security (PCI-DSS)
* Coordinate audits with external assessors (QSA) and internal stakeholders to streamline assessment process related to collecting evidences
* Lead the validation of PCI requirements testing results and drive compliance gap remediation efforts
* Create and maintain documentation to support PCI program
* Understands compliance requirements (ISO, NIST, SOX, PCI, HIPAA, GDPR and other regulatory compliance)
* Establish credibility and maintaining strong working relationships with groups involved with Information Security and compliance teams (Info Sec, Legal, Internal Audit, Physical Security, Developer Community, Networking, Systems, etc.)
* Collaborate with business/service teams to understand and validate security assessment scope.
* Provides business specific requirements and supports automation opportunities while working with Engineering teams.
* Helps drive continuous improvements to the InfoSec organization, the program management process, and control implementation projects in coordination with the service teams
* Capture and track program metrics and goals
* Report on deliverables, and project status to management and key technical and business stakeholders
* Deliver recommendations and risk interpretations in a clear, concise and audience-specific format
About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn鈥檛 followed a traditional path, or includes alternative experiences, don鈥檛 let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon鈥檚 products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it鈥檚 in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We鈥檙e continuously raising our performance bar as we strive to become Earth鈥檚 Best Employer. That鈥檚 why you鈥檒l find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there鈥檚 nothing we can鈥檛 achieve.
Qualifications
* 8+ years of relevant industry experience, including information assurance and IT compliance.* Skilled in risk management, Information security controls and making complex business/risk trade-off recommendations and decisions.
* Strong understanding of cloud computing architecture
* Familiarity with unified controls frameworks and GRC tooling
* Technical knowledge and familiarity with information security standards such as PCI DSS, NIST Cybersecurity Framework, ISO 27001, etc.
* Experience working with internal stakeholders on control design & implementation
* Ability to navigate through ambiguous situations with minimal supervision
* Previous ISA/QSA experience driving PCI DSS assessments and projects
Extended Qualifications
路 Related security control and compliance experience in various frameworks including: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, etc.路 CISSP, CISA, CISM, CIPP, CEH, PCIP and/or other comparable security controls or audit certifications preferred.
路 Experience with service-oriented architectures and web services security.
路 Demonstrated leadership, teamwork and collaboration skills.
路 Results oriented, self-motivated.
路 Experience with building out a unified control programs
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $107,400/year in our lowest geographic market up to $229,700/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
Check out other jobs at Amazon.