Key job responsibilities - Design and drive scalable processes within a GRC (Governance, Risk, and Compliance) framework to ensure compliance with Leo's regulatory and contractual security and privacy requirements; - Building and maintaining compliance certifications such as ISO 27001, ISO 22301, NIST 800-53, ISO27701, SOC 2, GDPR, CCPA etc., identifying applicable security controls, assessing compliance gaps and readiness, developing remediation strategies, and driving remediation activities to completion; - Driving certifications and assurance programs by liaising with external auditors and other Amazon security teams, articulating control implementation and impact, and establishing considerations for applying security, and risk concepts to a highly technical and complex environment; - Communicating to key stakeholders and leadership on controls implementation, audit results, compliance program metrics, key risks and areas of program improvement, as well as, seek diverse opinions and coordinate improvement efforts; - Working closely with engineering, compliance, security, bizdev and Legal teams to identify future compliance and regulatory requirements and define compliance solutions; - Serving as an advisor on assurance issues; - Understand and manage cross-functional GRC requirements to translate them into GRC tool; and - Be comfortable with hands-on day-to-day problem solving and implementing quick and effective action plans to meet short- and long-term priorities. Basic Qualifications - Bachelor's degree or above - 3+ years of professional experience in governance, risk and compliance designing and implementing controls or experience performing audits over ISO 27001, NIST 800-53, SOC 1/ SOC 2 and other similar globally recognized compliance programs Preferred Qualifications - CISSP, CISA, CISM or other security certification - Experience building strategic relationships with stakeholders, including communicating and collaborating across teams and functions - Experience working with ITAR and EAR controlled data - Demonstrate comprehensive understanding of compliance requirements for ISO 27001, ISO 22301, SOC 2, and US Government Compliance Frameworks/Programs (FedRAMP, NIST 800-53, NIST 800-171, NIST Risk Management Framework, FISMA).