Amazon
Sr. Security Compliance Specialist, Kuiper External Security Assurance
Amazon, Nashville, Tennessee, United States, 37247
Overview
Sr. Security Compliance Specialist, Kuiper External Security Assurance – Job ID: 3091681 | Amazon.com Services LLC Project Kuiper is an Amazon initiative to increase global broadband access through a constellation of over 3,000 Low Earth Orbit (LEO) satellites. Its mission is to bring fast, affordable broadband to unserved and underserved communities worldwide. At Project Kuiper, we are obsessed with customer trust and are seeking an individual contributor who is creative, and passionate about delivering Governance, Risk and Compliance solutions to meet Kuiper\'s regulatory and external assurance needs. In this role, you will work collaboratively with various business and security teams across Amazon to identify compliance needs, assess the maturity of processes and controls, design, build, and execute high-impact security or compliance programs and liaise with external auditors and regulators. Export Control Requirement: Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. Responsibilities
Design and drive scalable processes within a GRC (Governance, Risk, and Compliance) framework to ensure compliance with Kuiper\'s regulatory and contractual security and privacy requirements Build and maintain compliance certifications such as ISO 27001, ISO 22301, NIST 800-53, ISO 27701, SOC 2, GDPR, CCPA, etc.; identify applicable security controls, assess compliance gaps and readiness, develop remediation strategies, and drive remediation activities to completion Drive certifications and assurance programs by liaising with external auditors and other Amazon security teams, articulating control implementation and impact, and establishing considerations for applying security and risk concepts to a highly technical and complex environment Communicate to key stakeholders and leadership on controls implementation, audit results, compliance program metrics, key risks and areas of program improvement, and seek diverse opinions to coordinate improvement efforts Work closely with engineering, compliance, security, bizdev and Legal teams to identify future compliance and regulatory requirements and define compliance solutions Serve as a subject matter expert and advisor on complex assurance issues Understand and manage cross-functional GRC requirements to translate them into GRC tooling Be comfortable with hands-on day-to-day problem solving and implementing quick and effective action plans to meet short- and long-term priorities About the team
The Kuiper Security team owns the security of product and operations of Project Kuiper end-to-end, providing the infrastructure and mechanisms to ensure the security of our satellite constellation and to provide assurance to customers and regulators on security, privacy and resiliency programs. We drive the implementation of compliance programs, and own collaboration with external auditors and regulators. You will work in a start-up like environment, backed by Amazon\'s infrastructure to bootstrap security mechanisms and foster a security culture. Basic Qualifications
8+ years’ experience managing product compliance issues, preferably within a technology company or aerospace/regulated industry, analyzing regulatory requirements, and developing policies and procedures Demonstrate comprehensive understanding of compliance requirements for ISO 27001, ISO 22301, SOC 2, and US Government Compliance Frameworks/Programs (FedRAMP, NIST 800-53, NIST 800-171, NIST RMF, FISMA) Highly organized with ability to build trusting relationships with stakeholders at various levels across the organization Experience in large-scale project management roles, preferably in product regulatory compliance Preferred Qualifications
Experience implementing and managing Privacy programs like GDPR, CCPA, ISO27701 and other global data privacy requirements Industry certifications such as CISSP, CISA, CISM, ISO 27001:2022 Lead Implementer/Lead Auditor, or ISO 22301:2019 Lead Implementer/Lead Auditor Experience integrating compliance processes into tools and driving automation Strong data-driven analytical skills with experience in establishing and tracking program metrics Experience coordinating and leading external audits and regulator interactions Proven ability to balance competing priorities and deliver amidst ambiguity Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company\’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn\'t listed, please contact your Recruiting Partner. Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $107,400/year in our lowest geographic market up to $229,700/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
#J-18808-Ljbffr
Sr. Security Compliance Specialist, Kuiper External Security Assurance – Job ID: 3091681 | Amazon.com Services LLC Project Kuiper is an Amazon initiative to increase global broadband access through a constellation of over 3,000 Low Earth Orbit (LEO) satellites. Its mission is to bring fast, affordable broadband to unserved and underserved communities worldwide. At Project Kuiper, we are obsessed with customer trust and are seeking an individual contributor who is creative, and passionate about delivering Governance, Risk and Compliance solutions to meet Kuiper\'s regulatory and external assurance needs. In this role, you will work collaboratively with various business and security teams across Amazon to identify compliance needs, assess the maturity of processes and controls, design, build, and execute high-impact security or compliance programs and liaise with external auditors and regulators. Export Control Requirement: Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. Responsibilities
Design and drive scalable processes within a GRC (Governance, Risk, and Compliance) framework to ensure compliance with Kuiper\'s regulatory and contractual security and privacy requirements Build and maintain compliance certifications such as ISO 27001, ISO 22301, NIST 800-53, ISO 27701, SOC 2, GDPR, CCPA, etc.; identify applicable security controls, assess compliance gaps and readiness, develop remediation strategies, and drive remediation activities to completion Drive certifications and assurance programs by liaising with external auditors and other Amazon security teams, articulating control implementation and impact, and establishing considerations for applying security and risk concepts to a highly technical and complex environment Communicate to key stakeholders and leadership on controls implementation, audit results, compliance program metrics, key risks and areas of program improvement, and seek diverse opinions to coordinate improvement efforts Work closely with engineering, compliance, security, bizdev and Legal teams to identify future compliance and regulatory requirements and define compliance solutions Serve as a subject matter expert and advisor on complex assurance issues Understand and manage cross-functional GRC requirements to translate them into GRC tooling Be comfortable with hands-on day-to-day problem solving and implementing quick and effective action plans to meet short- and long-term priorities About the team
The Kuiper Security team owns the security of product and operations of Project Kuiper end-to-end, providing the infrastructure and mechanisms to ensure the security of our satellite constellation and to provide assurance to customers and regulators on security, privacy and resiliency programs. We drive the implementation of compliance programs, and own collaboration with external auditors and regulators. You will work in a start-up like environment, backed by Amazon\'s infrastructure to bootstrap security mechanisms and foster a security culture. Basic Qualifications
8+ years’ experience managing product compliance issues, preferably within a technology company or aerospace/regulated industry, analyzing regulatory requirements, and developing policies and procedures Demonstrate comprehensive understanding of compliance requirements for ISO 27001, ISO 22301, SOC 2, and US Government Compliance Frameworks/Programs (FedRAMP, NIST 800-53, NIST 800-171, NIST RMF, FISMA) Highly organized with ability to build trusting relationships with stakeholders at various levels across the organization Experience in large-scale project management roles, preferably in product regulatory compliance Preferred Qualifications
Experience implementing and managing Privacy programs like GDPR, CCPA, ISO27701 and other global data privacy requirements Industry certifications such as CISSP, CISA, CISM, ISO 27001:2022 Lead Implementer/Lead Auditor, or ISO 22301:2019 Lead Implementer/Lead Auditor Experience integrating compliance processes into tools and driving automation Strong data-driven analytical skills with experience in establishing and tracking program metrics Experience coordinating and leading external audits and regulator interactions Proven ability to balance competing priorities and deliver amidst ambiguity Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company\’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn\'t listed, please contact your Recruiting Partner. Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $107,400/year in our lowest geographic market up to $229,700/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
#J-18808-Ljbffr