Security & Compliance Engineer I, AWS Security Assurance Services, LLC

Amazon.com Inc

Seattle, WA

JOB DETAILS
SKILLS
Amazon Web Services (AWS), Automation, Cloud Architecture, Cloud Computing, Code Reviews, Customer Support/Service, DevOps, Emerging Technology, HIPAA (Health Insurance Portability and Accountability Act), Identify Issues, Leadership, Machine Tool, Maintain Compliance, Operational Support, Operations Security (OPSEC), PCI, PCI-DSS, Policy Development, Procedure Development, Protective Services, Python Programming/Scripting Language, Reporting Dashboards, Risk, Risk Management, Software Engineering, Statements on Auditing Standards (SAS), Statistical Analysis System (SAS), Threat Modeling, U.S. National Institute of Standards and Technology (NIST), Willing to Travel
LOCATION
Seattle, WA
POSTED
10 days ago

AWS Security Assurance Services (SAS) is hiring an Associate Security & Compliance Engineer to help build and operate AWS security and compliance solutions for highly regulated customers. You will execute your team's security processes, contribute to runbooks and tooling, write and review code and Infrastructure-as-Code, and help ship secure-by-design implementations aligned to compliance frameworks (SOC2, HIPAA, PCI-DSS, CIS, NIST, FedRAMP).

You'll work on well-defined security problems with regular checkpoints from your team, learn from peer review, and grow your skills in secure design, threat modeling, and AWS security engineering. You will be a reliable contributor on customer engagements and a strong security advocate within your team.

Key job responsibilities

  • Implement custom security controls, enforcements, detections, and automated remediations
  • Contribute to Infrastructure-as-Code modules for Landing Zones, AWS Control Tower customizations, and security baselines using Terraform, AWS CDK, or CloudFormation.
  • Write Python and policy-as-code (cfn-guard, OPA Rego, Cedar) to extend preventive and detective controls.
  • Participate in code, IaC, and design reviews; provide constructive feedback
  • Contribute to POCs on emerging technologies; implement components, run experiments, and document findings so the team can build on the results.
  • Implement continuous compliance monitoring checks, evidence collection automations, and reporting dashboards.
  • Help identify, confirm and document risks and mitigations during design and implementation stages of customer engagements.
  • Apply common risk trade-offs (e.g., tactical compensating controls vs. addressing root causes) under guidance.
  • Contribute to runbooks, tools, and other security mechanisms used by the team and customers.
  • Participate in operational support; help ensure root causes of operational and security issues are identified and resolved.
  • Follow established procedures to diagnose problems, and escalate appropriately when blocked.
  • Communicate security risk for low-complexity problems clearly in writing and verbally to your team and direct leadership.
  • Solicit differing views and learn from peer feedback.
  • Travel to customer sites as needed.

About the team

The AWS Security Assurance Services team, within AWS Support, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world's workloads requires reliable delivery of bar-raising security outcomes and investment in security mechanisms and automation on behalf of our customers.

AWS Security Assurance Services LLC, a PCI-QSAC and HITRUST External Assessor Firm, is a team of industry-certified assessors and Compliance Engineers with DevOps and Cloud Infrastructure Architect backgrounds, helping our customers achieve, maintain, and automate compliance in the cloud by tying applicable audit standards to AWS service-specific features and functionality. The SAS team works with our largest enterprise customers to operationalize the shared responsibility model as they migrate to the cloud.

About the Company

A

Amazon.com Inc

At Amazon, we don’t wait for the next big idea to present itself. We envision the shape of impossible things and then we boldly make them reality. So far, this mindset has helped us achieve some incredible things. Let’s build new systems, challenge the status quo, and design the world we want to live in. We believe the work you do here will be the best work of your life.

Wherever you are in your career exploration, Amazon likely has an opportunity for you. Our research scientists and engineers shape the future of natural language understanding with Alexa. Fulfillment center associates around the globe send customer orders from our warehouses to doorsteps. Product managers set feature requirements, strategy, and marketing messages for brand new customer experiences. And as we grow, we’ll add jobs that haven’t been invented yet.

It’s Always Day 1
At Amazon, it’s always “Day 1.” Now, what does this mean and why does it matter? It means that our approach remains the same as it was on Amazon’s very first day – to make smart, fast decisions, stay nimble, invent, and stay focused on delighting our customers. In our 2016 shareholder letter, Amazon CEO Jeff Bezos shared his thoughts on how to keep up a Day 1 company mindset. “Staying in Day 1 requires you to experiment patiently, accept failures, plant seeds, protect saplings, and double down when you see customer delight,” he wrote. “A customer-obsessed culture best creates the conditions where all of that can happen.” You can read the full letter here

Our Leadership Principles
Our Leadership Principles help us keep a Day 1 mentality. They aren’t just a pretty inspirational wall hanging. Amazonians use them, every day, whether they’re discussing ideas for new projects, deciding on the best solution for a customer’s problem, or interviewing candidates. To read through our Leadership Principles from Customer Obsession to Bias for Action, visit https://www.amazon.jobs/principles
COMPANY SIZE
10,000 employees or more
INDUSTRY
Retail
FOUNDED
1994
WEBSITE
http://Amazon.com/militaryroles