At a Glance
- Tasks: Join a creative team to enhance security controls and compliance across diverse technologies.
- Company: Amazon, a leader in cloud security and innovation.
- Benefits: Flexible working hours, mentorship opportunities, and a commitment to work-life balance.
- Other info: Inclusive culture that values diverse experiences and promotes career growth.
- Why this job: Make a real impact on security assurance while collaborating with diverse teams.
- Qualifications: Experience in compliance, audit, and a passion for cloud security.
The predicted salary is between 63000 - 77000 £ per year.
Do you have a passion for applying the latest technologies and automation in traditionally manual processes? Do you have experience in finding innovative solutions to scale security controls across diverse teams and technologies? Do you have ideas about influencing the future of security assurance? At Amazon, Security is our highest priority. Come, join a creative team at Security Assurance dedicated to demonstrating the security controls of the services we offer here. At Amazon’s scale, we are committed to inventing new ways to provide the highest level of assurance to our most regulatory conscious customers.
You have a strong foundation in audit principles, as well as a diverse technology background. As part of the team, you will work with customers and regulators to demonstrate Amazon's security controls applicable to local requirements. You will join our team in helping customers understand how our infrastructure is designed, operated, maintained, and protected in accordance with global regulated industry standards. You will help inspire, lead, and transform our audit and compliance programs through innovative process engineering across multiple organizations and teams, engaging technical and non-technical stakeholders throughout the company.
Your combination of technical and audit background will help bridge security, technology, and compliance, and facilitate the scale of the program. The successful candidate is one who loves working across many stakeholders, including internal and external customers, to design solutions for complex compliance challenges. You are passionate about the security of the cloud and you want to solve real business problems. We have a team culture that encourages ownership, diversity, inclusion, and innovation. We expect team members and management alike to take a high degree of ownership for their program vision and execution of ideas. We expect this person to balance their unique perspective with those of the diverse perspectives of the team and its stakeholders.
You will have an opportunity to work directly with senior leadership within Amazon to improve our ability to demonstrate assurance for regulated customers. You should be a technically experienced and innovative security, compliance, and audit professional who has the ability to understand IT processes, communicate clearly and transparently with customers, and to be able to drive innovative process changes through multiple organizations and teams.
Key job responsibilities
- Dive deep into the Amazon control environment to develop broad domain and technical understanding of our security activities and control implementations to articulate compliance implications to both customers and internal/external audit functions.
- Develop understanding of regulated industry compliance requirements and communicate how we control activities to meet global regulatory obligations.
- Liaise with customers, regulators and auditors, articulate control implementation, and describe considerations for applying security and compliance concepts to monitor, evaluate, and continuously improve the organization by being a trusted advisor, facilitator and creative problem solver.
- Implement continuous improvements to the security organization and the program management process. Share program/project process frameworks, tools, and best practices that can be adopted throughout the organization.
- Apply a working knowledge of global information security regulation and policy to articulate customer and control impact and drive alignment to Amazon controls.
About the team
Diverse Experiences AWS Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why AWS Security
At AWS, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of AWS’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
Here at Amazon, we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employee-led affinity groups, reaching 40,000 employees in over 190 chapters globally. We have innovative benefit offerings, and host annual and ongoing learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon conferences. Amazon’s culture of inclusion is reinforced within our 16 Leadership Principles, which remind team members to seek diverse perspectives, learn and be curious, and earn trust.
Work/Life Balance
Our team puts a high value on work-life balance. It isn’t about how many hours you spend at home or at work; it’s about the flow you establish that brings energy to both parts of your life. We believe striking the right balance between your personal and professional life is critical to life-long happiness and fulfillment. We offer flexibility in working hours and encourage you to find your own balance between your work and personal lives.
Mentorship & Career Growth
Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded professional and enable them to take on more complex tasks in the future.
Basic qualifications
- Bachelor's degree or equivalent
- Experience in compliance program management, legal, governance, audit, risk/loss prevention, or equivalent
- Experience handling confidential information
- Experience in working directly with government officials and regulatory bodies
- 5+ years of working experience in performing and/or participating in IT audits based on ISAE 3401, auditing COBIT, ITIL, IT-Grundschutz and assessments of highly technical cloud-based environments.
- 3+ years’ experience working and building risk programs and strategies up to date on related industry trends (e.g., changing regulations, innovations in risk mitigation, testing mechanisms)
- 5+ years working in highly regulated industries (e.g. financial services, healthcare, and energy, telecommunications), including direct work with European audits and frameworks such as DORA.
Preferred qualification
- Experience with SQL and Excel
- Experience in program requirements definition, together with data and metrics leveraging to drive improvements
- 1 or more industry-recognized security, cloud, or audit professional certifications (e.g., CISA, CISM, CISSP, CCSP, Amazon Cloud Security Practitioner)
- Experience in technical security design, cloud services/deployment architecture (ideally Amazon cloud services offering), compliance consulting, or advisory work in a highly technical environment.
- Deep understanding of regulatory guidance, FCA guidance FG16/5 (Guidance for firms outsourcing to the ‘cloud’ and other third-party IT services), DORA requirements for Critical Service Provider, C5 requirements of the Federal Office of Information Security of Germany and other applicable standards and requirements.
- A record of delivery of IT process improvement projects with technology processes and/or major tech companies along with generating automated metrics to measure effectiveness and consistency.
- Experience building certification roadmaps based on customer requirements, compliance documentation, and ensuring that committed assessments are delivered on schedule.
- A detailed understanding of evaluating the design and effectiveness of IT controls and experience working with auditors/regulators for these types of assessments.
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information.
Security Assurance Specialist , AWS Compliance and Security Assurance EMEA in London employer: AmazonWebServices
At Amazon Web Services (AWS), we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. As a Senior Delivery Consultant (DevOps) in the UK, you'll have the opportunity to work closely with diverse clients, driving their cloud success while benefiting from extensive mentorship and professional growth opportunities. Our commitment to inclusion and employee empowerment ensures that every team member can thrive and contribute meaningfully to our mission of delivering cutting-edge cloud solutions.
StudySmarter Expert Advice🤫
We think this is how you could land Security Assurance Specialist , AWS Compliance and Security Assurance EMEA in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including AmazonWebServices, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through AmazonWebServices
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at AmazonWebServices. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Assurance Specialist , AWS Compliance and Security Assurance EMEA in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at AmazonWebServices insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to AmazonWebServices that you’re committed to staying ahead in the game.
How to prepare for a job interview at AmazonWebServices
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at AmazonWebServices to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at AmazonWebServices.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.