Demo

Principal Risk Manager, Governance & Compliance, Amazon Business

Amazon
Seattle, WA Full Time
POSTED ON 2/4/2025
AVAILABLE BEFORE 3/25/2025
Description

Come be a part of a rapidly expanding $35 billion-dollar global business. At Amazon Business, a fast-growing startup passionate about building solutions, we set out every day to innovate and disrupt the status quo. We stand at the intersection of tech & retail in the B2B space developing innovative purchasing and procurement solutions to help businesses and organizations thrive. At Amazon Business, we strive to be the most recognized and preferred strategic partner for smart business buying. Bring your insight, imagination and a healthy disregard for the impossible. Join us in building and celebrating the value of Amazon Business to buyers and sellers of all sizes and industries. Unlock your career potential.

We are seeking a Security Risk Manager from diverse backgrounds, who are creative problem solvers and passionate about delivering solutions that improve both user experience and security while meeting internal and external standards and compliance requirements.

In this role, you will work across many stakeholders to design solutions that meet global industry standards and regulatory requirements. As part of the team, you will identify industry requirements, evaluate compliance requests, and deliver results that demonstrate the effectiveness of Amazon's internal security controls. In this highly visible role, you will partner with stakeholders across Amazon to execute a risk management approach, identify risks, and act as a thought leader who recommends and leads risk mitigation strategies with system and product owners across Amazon Business. You’ll apply your creative problem-solving skills and work with service teams and partner security teams to provide assurance to customers, as well as, design, build, and execute high-impact security or compliance programs.

Key job responsibilities

You will be responsible for a set of long-term security outcomes. Your day-to-day job responsibilities will include:

  • Building ISO 27001, SOC2, and other security and privacy certifications and attestation programs, identifying applicable security controls, assessing compliance gaps and readiness, developing remediation strategies, and driving remediation activities to completion;
  • Driving certifications and assessments programs by liaising with external auditors and other Amazon security teams, articulating control implementation and impact, and establishing considerations for applying security, privacy, and compliance concepts to a technical cloud environment;
  • Developing and implementing comprehensive security risk management strategies and frameworks to proactively identify, assess, mitigate and monitor security risks to the organization.
  • Overseeing the organization's security risk management program, including conducting risk assessments, threat analysis, and vulnerability testing.
  • Delivering recommendations and risk interpretations in a clear, concise and audience-specific format
  • Developing broad domain and technical knowledge in AWS and Amazon security solutions including the operational processes and controls in place that support InfoSec compliance programs;
  • Communicating to key stakeholders and leadership the operational processes around Amazon security practices and how controls are implemented across the environment;
  • Communicating to leadership key risks and areas of program improvement, as well as, seek diverse opinions and coordinate improvement efforts;
  • Working closely with engineering, compliance, security, and Legal teams to meet compliance and regulatory requirements and design compliance solutions;
  • Serving as a subject matter expert and advisor on complex security risk issues.

Basic Qualifications

  • Bachelor’s Degree in Computer Science, Information Systems Management, Cyber Security, Mathematics, Accounting/Auditing, or other related fields
  • 10 years of experience in security risk management, regulatory, or compliance role, preferably in a large, complex organization.
  • Knowledge of risk management methods and industry best practices.
  • 5 years of experience in performing implementation and technical audits/assessments in direct support of a major compliance effort (e.g., ISO 27001, SOC 2, or NIST 800 series frameworks)
  • CISSP, CISA, CISM, CIA or other comparable security controls or audit certifications
  • Analytical decision making with a demonstrated ability problem solve, make decisions in complex situations and drive issues to completion.
  • Proven history of working effectively across cross-functional teams and business functions to drive positive change.

Preferred Qualifications

  • 7 years of technical program management experience
  • Experience in technical security design in support of a highly technical DevSecOps and cloud environment
  • Knowledge of software development lifecycles and modern transaction processing environments.
  • Experience evaluating the design and effectiveness of security controls and experience working with auditors/regulators
  • Skilled in making complex business/risk trade-off recommendations and decisions
  • Experience communicating audit/assessment results and remediation plans with leadership, and prioritizing and remediating findings with service/system owner
  • Excellent written and verbal communication and stakeholder management skills to influence decision-makers.
  • Strategic thinking ability to align security risk management with broader business objectives.

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $129,800/year in our lowest geographic market up to $214,500/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.


Company - Amazon.com Services LLC

Job ID: A2815162

Salary : $129,800 - $214,500

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Principal Risk Manager, Governance & Compliance, Amazon Business?

Sign up to receive alerts about other jobs on the Principal Risk Manager, Governance & Compliance, Amazon Business career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$124,413 - $154,875
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$164,394 - $225,474
Income Estimation: 
$161,616 - $208,121
Income Estimation: 
$87,128 - $112,557
Income Estimation: 
$122,325 - $159,127
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$176,392 - $248,211
Income Estimation: 
$163,962 - $219,201
Income Estimation: 
$58,470 - $77,272
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$75,905 - $103,047
Income Estimation: 
$74,367 - $98,680
Income Estimation: 
$74,367 - $98,680
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$94,973 - $125,755
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$121,926 - $164,179
Income Estimation: 
$124,413 - $154,875
Income Estimation: 
$87,128 - $112,557
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Amazon

Amazon
Hired Organization Address NV, NV Full Time
DESCRIPTION This is not a corporate, remote or office-based position. This is a full-time, entry level position located ...
Amazon
Hired Organization Address Las Vegas, NV Full Time
DESCRIPTION Amazon is a Fortune 500 company based in Seattle, Washington, and the global leader in e-commerce. Since our...
Amazon
Hired Organization Address NV, NV Full Time
DESCRIPTION In this role, you'll be a part of Amazon Key’s Channel Sales team. The team is in charge of building strateg...
Amazon
Hired Organization Address Baton Rouge, LA Full Time
DESCRIPTION AMZL Sr. Station Leaders are responsible for all budgetary, people development and operations objectives for...

Not the job you're looking for? Here are some other Principal Risk Manager, Governance & Compliance, Amazon Business jobs in the Seattle, WA area that may be a better fit.

AI Assistant is available now!

Feel free to start your new journey!