Security Industry Specialist – PCI, Security Risk and Compliance – USA, TX, Austin

Amazon

  • Full Time

DESCRIPTION

The Security and Regulatory Compliance (SRC) organization is comprised of teams that provide consistent high-level judgement to help Amazon businesses comply with security regulations, policies, and Amazon’s high bar for security. The PCI Team serves as the primary security compliance team for Amazon. This role will provide advisory guidance to new and existing businesses at Amazon, and will conduct deep dives into critical security risk areas. If you enjoy working in a rapidly changing environment and influencing the strategic direction of a large global organization, this position will provide you with a challenging opportunity. You will be responsible for driving consensus across teams to define and influence the secure and compliant design of systems worldwide.

Key job responsibilities
* Lead planning and execution of PCI assessments which includes review of control design with a focus on payment card compliance and security (PCI-DSS)
* Coordinate audits with external assessors (QSA) and internal stakeholders to streamline assessment process related to collecting evidences
* Lead the validation of PCI requirements testing results and drive compliance gap remediation efforts
* Create and maintain documentation to support PCI program
* Understands compliance requirements (ISO, NIST, SOX, PCI, HIPAA, GDPR and other regulatory compliance)
* Establish credibility and maintaining strong working relationships with groups involved with Information Security and compliance teams (Info Sec, Legal, Internal Audit, Physical Security, Developer Community, Networking, Systems, etc.)
* Collaborate with business/service teams to understand and validate security assessment scope.
* Provides business specific requirements and supports automation opportunities while working with Engineering teams.
* Helps drive continuous improvements to the InfoSec organization, the program management process, and control implementation projects in coordination with the service teams
* Capture and track program metrics and goals
* Report on deliverables, and project status to management and key technical and business stakeholders
* Deliver recommendations and risk interpretations in a clear, concise and audience-specific format

About the team
About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

BASIC QUALIFICATIONS

* 8+ years of relevant industry experience, including information assurance and IT compliance.
* Skilled in risk management, Information security controls and making complex business/risk trade-off recommendations and decisions.
* Strong understanding of cloud computing architecture
* Familiarity with unified controls frameworks and GRC tooling
* Technical knowledge and familiarity with information security standards such as PCI DSS, NIST Cybersecurity Framework, ISO 27001, etc.
* Experience working with internal stakeholders on control design & implementation
* Ability to navigate through ambiguous situations with minimal supervision
* Previous ISA/QSA experience driving PCI DSS assessments and projects

PREFERRED QUALIFICATIONS

· Related security control and compliance experience in various frameworks including: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, etc.
· CISSP, CISA, CISM, CIPP, CEH, PCIP and/or other comparable security controls or audit certifications preferred.
· Experience with service-oriented architectures and web services security.
· Demonstrated leadership, teamwork and collaboration skills.
· Results oriented, self-motivated.
· Experience with building out a unified control programs

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $107,400/year in our lowest geographic market up to $229,700/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

 

USA, TX, Austin