

Share
Key job responsibilities
- Conduct security compliance assessments based on established control tests for compliance regimes (such as ISO, NIST, SOX, PCI, HIPAA, GDPR and other regulatory compliance)- Review security controls such as access controls, data encryption and audit logging- Participates in continuous improvements to the security assessment processes
- Captures and tracks information security assessment metrics and goals- Documents findings and recommendations in a clear, concise and audience-specific formatAbout the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Work/Life BalanceTraining and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- Bachelor's degree in Computer Science, Computer Engineering, Information Management, Information Systems, or other related discipline
- 2+ years of relevant industry experience including information assurance, data privacy and compliance in security domains
- 2+ years of information security governance, audit, risk management or related client service or consulting experience.
- Related security control and compliance experience in any of the frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Experience with security control reviews and compliance assessments
- Understanding of information security standards and frameworks
- CISSP, CISA, CISM, CIPP, CEH and/or other comparable security or audit certifications preferred
- Experience in control framework development and implementation
- Related security control and compliance experience in multiple frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Experience with AWS Cloud services, managing security for AWS Cloud services
These jobs might be a good fit

Share
Job Description:
Job Description:
Responsibilities
As a Critical Infrastructure Assurance Review (CIAR) - Info Security Exposure Mgmt. Sr Specialist, the individual will be focused on the following areas:
• Performing Critical Infrastructure Assurance Review (CIAR) process design and maturation.
• Testing of Core Infrastructure identified AITs, leveraging industry standard guidance against evolving ransomware and malware tactics, techniques, and procedures.
• Partnering with infrastructure teams and SMEs to facilitate the collection of evidence.
• Exercising independent judgment in evaluation criteria to obtain results.
• Performing QA and determining levels of compliance.
• Submitting observations for remediation tracking.
• Tracking and reporting of assessment status to leadership team.
• Iterating on the assessment and continually improving its in-scope questions and controls.
Required Skills:
• Experience in Information Security and/or IT Audit
• Technical writing and verbal communication skill
• Ability to effectively work with partners at varying knowledge and organization levels.
• Ability to communicate clearly and effectively with both technology/development and business partners – ability to translate between these two constituencies.
• Highly organized and motivated to deliver results with minimal direction.
• Creative and proactive problem solver – ability to understand what the team needs and offer suggestions above and beyond what they desire.
• Naturally curious individual with the ability to quickly become the authority in the various data and systems used by the team.
• Strong relationship, team building and facilitation skills.
• Good knowledge of current ransomware and malware threats and vulnerabilities, operating systems, database management and OSI Model.
• Proficient with Microsoft Office (Word, PowerPoint, Excel), Tableau, SharePoint.
Desired skills:
• Information Security certifications, including ISO27002 / CISSP / CEH / CISM / CISA
• Experience in coordinating team projects
• Knowledge of NIST and NSA guidelines
• Education: B.E. / B. Tech/M.E. /M. Tech/B.Sc./M.Sc./BCA/MCA (prefer IT/CS specialization)
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
1st shift (United States of America)These jobs might be a good fit

Share
Key job responsibilities
- Understands and rationalizes compliance requirements in the healthcare and payments domains. Provides business specific interpretations and supports automation opportunities while working with Dev teams.
- Reviews security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity to assess whether the controls are implemented and operating effectively.- Delivers recommendations and risk interpretations in a clear, concise and audience-specific format- Supports data analysis requests to identify trends and provide valuable insights to the leadership.About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Work/Life BalanceTraining and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- Bachelor’s degree in Management Information Systems, Computer Science or relevant field
- 5+ years of relevant industry experience including information assurance, data privacy and compliance in healthcare domains.
- 5+ years of information security governance, audit, risk management or related client service or consulting experience.
- Skilled in risk management, business risk analysis and making complex business/risk trade-off recommendations and decisions.
- Technical knowledge and familiarity with information security standards and frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Master degree in Management Information Systems, Computer Science or relevant field with 5+ years of relevant industry experience including information assurance, data privacy and compliance in healthcare domains.
- Experience in control framework development and implementation
- Related security control and compliance experience in various frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- CISSP, CISA, CISM, CIPP, CEH and/or other comparable security controls or audit certifications preferred.
- Experience with AWS Cloud services, managing security for AWS Cloud services
These jobs might be a good fit

Share
Key job responsibilities
- Conduct security compliance assessments based on established control tests for compliance regimes (such as ISO, NIST, SOX, PCI, HIPAA, GDPR and other regulatory compliance)- Review security controls such as access controls, data encryption and audit logging- Participates in continuous improvements to the security assessment processes
- Captures and tracks information security assessment metrics and goals- Documents findings and recommendations in a clear, concise and audience-specific formatAbout the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Work/Life BalanceTraining and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- Bachelor’s degree in Management Information Systems, Computer Science or relevant field
- 2+ years of relevant industry experience including information assurance, data privacy and compliance in security domains
- 2+ years of information security governance, audit, risk management or related client service or consulting experience.
- Related security control and compliance experience in any of the frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Experience with security control reviews and compliance assessments
- Understanding of information security standards and frameworks
- CISSP, CISA, CISM, CIPP, CEH and/or other comparable security or audit certifications preferred
- Experience in control framework development and implementation
- Related security control and compliance experience in multiple frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Experience with AWS Cloud services, managing security for AWS Cloud services
These jobs might be a good fit

Share
As a Critical Infrastructure Assurance Review (CIAR) - Info Security Exposure Mgmt. Sr Specialist, the individual will be focused on the following areas:
• Performing Critical Infrastructure Assurance Review (CIAR) process design and maturation.
• Testing of Core Infrastructure identified AITs, leveraging industry standard guidance against evolving ransomware and malware tactics, techniques, and procedures.
• Partnering with infrastructure teams and SMEs to facilitate the collection of evidence.
• Exercising independent judgment in evaluation criteria to obtain results.
• Performing QA and determining levels of compliance.
• Submitting observations for remediation tracking.
• Tracking and reporting of assessment status to leadership team.
• Iterating on the assessment and continually improving its in-scope questions and controls.
• Experience in Information Security and/or IT Audit
• Technical writing and verbal communication skill
• Ability to effectively work with partners at varying knowledge and organization levels.
• Ability to communicate clearly and effectively with both technology/development and business partners – ability to translate between these two constituencies.
• Highly organized and motivated to deliver results with minimal direction.
• Creative and proactive problem solver – ability to understand what the team needs and offer suggestions above and beyond what they desire.
• Naturally curious individual with the ability to quickly become the authority in the various data and systems used by the team.
• Strong relationship, team building and facilitation skills.
• Good knowledge of current ransomware and malware threats and vulnerabilities, operating systems, database management and OSI Model.
• Proficient with Microsoft Office (Word, PowerPoint, Excel), Tableau, SharePoint.
Desired skills:
• Information Security certifications, including ISO27002 / CISSP / CEH / CISM / CISA
• Experience in coordinating team projects
• Knowledge of NIST and NSA guidelines
• Education: B.E. / B. Tech/M.E. /M. Tech/B.Sc./M.Sc./BCA/MCA (prefer IT/CS specialization)
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
1st shift (United States of America)These jobs might be a good fit

Share
Key job responsibilities
- Understands and rationalizes compliance requirements in the healthcare and payments domains. Provides business specific interpretations and supports automation opportunities while working with Dev teams.
- Reviews security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity to assess whether the controls are implemented and operating effectively.- Delivers recommendations and risk interpretations in a clear, concise and audience-specific format- Supports data analysis requests to identify trends and provide valuable insights to the leadership.About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Work/Life BalanceTraining and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- Bachelor’s degree in Management Information Systems, Computer Science or relevant field
- 5+ years of relevant industry experience including information assurance, data privacy and compliance in healthcare domains.
- 5+ years of information security governance, audit, risk management or related client service or consulting experience.
- Skilled in risk management, business risk analysis and making complex business/risk trade-off recommendations and decisions.
- Technical knowledge and familiarity with information security standards and frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Master degree in Management Information Systems, Computer Science or relevant field with 5+ years of relevant industry experience including information assurance, data privacy and compliance in healthcare domains.
- Experience in control framework development and implementation
- Related security control and compliance experience in various frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- CISSP, CISA, CISM, CIPP, CEH and/or other comparable security controls or audit certifications preferred.
- Experience with AWS Cloud services, managing security for AWS Cloud services
These jobs might be a good fit

Share
We're seeking a talented System Development Engineer (SDE) to help build media consumption devices using both open source and proprietary technologies. As a customer advocate, you'll own media technologies and quality end-to-end (E2E), working with internal and external partners to deliver best-in-class devices. Your responsibilities will include researching new technologies, developing tools, and defining processes for next-generation media stack development. You'll be involved in the research, design, implementation, documentation, and maintenance of new and existing systems, as well as creating software services and tools to enhance development quality.Key job responsibilities
A day in the life
Working collaboratively with internal and external partners, you'll help deliver best-in-class devices that delight customers. Your responsibilities will include researching emerging technologies, developing new tools, and defining processes that shape our next-generation media stack. You'll have the opportunity to influence how millions of customers experience entertainment in their daily lives.
- Experience in automating, deploying, and supporting infrastructure
- Experience programming with at least one modern language such as Python, Ruby, Golang, Java, C++, C#, Rust
- Experience with Linux/Unix
- Experience with CI/CD pipelines build processes
These jobs might be a good fit

Share
Key job responsibilities
- Conduct security compliance assessments based on established control tests for compliance regimes (such as ISO, NIST, SOX, PCI, HIPAA, GDPR and other regulatory compliance)- Review security controls such as access controls, data encryption and audit logging- Participates in continuous improvements to the security assessment processes
- Captures and tracks information security assessment metrics and goals- Documents findings and recommendations in a clear, concise and audience-specific formatAbout the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Work/Life BalanceTraining and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- Bachelor's degree in Computer Science, Computer Engineering, Information Management, Information Systems, or other related discipline
- 2+ years of relevant industry experience including information assurance, data privacy and compliance in security domains
- 2+ years of information security governance, audit, risk management or related client service or consulting experience.
- Related security control and compliance experience in any of the frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Experience with security control reviews and compliance assessments
- Understanding of information security standards and frameworks
- CISSP, CISA, CISM, CIPP, CEH and/or other comparable security or audit certifications preferred
- Experience in control framework development and implementation
- Related security control and compliance experience in multiple frameworks such as: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, or other regulatory regimes
- Experience with AWS Cloud services, managing security for AWS Cloud services
These jobs might be a good fit