Security Assurance Specialist, AWS Compliance and Security Assurance EMEA


Location
London
Hours
Full Time
Salary
Competitive, based on experience
About the Role
Do you have a passion for applying the latest technologies and automation in traditionally manual processes? Are you experienced in finding innovative solutions to scale security controls across diverse teams and technologies? At Amazon, Security is our highest priority. Join a creative team at Security Assurance dedicated to demonstrating the security controls of the services we offer. At Amazon's scale, we are committed to inventing new ways to provide the highest level of assurance to our most regulatory conscious customers.
You will work with customers and regulators to demonstrate Amazon's security controls applicable to local requirements and help customers understand how our infrastructure is designed, operated, maintained, and protected in accordance with global regulated industry standards. You will inspire, lead, and transform our audit and compliance programs through innovative process engineering across multiple organizations and teams, engaging both technical and non-technical stakeholders.
Your role will bridge security, technology, and compliance, facilitating the scale of the program. You will work directly with senior leadership to improve our ability to demonstrate assurance for regulated customers. This role requires a technically experienced and innovative security, compliance, and audit professional who understands IT processes, communicates clearly with customers, and drives innovative process changes across multiple teams.
Key responsibilities include:
- Developing a broad domain and technical understanding of Amazon's control environment to articulate compliance implications to customers and audit functions
- Understanding regulated industry compliance requirements and communicating how controls meet global regulatory obligations
- Liaising with customers, regulators, and auditors to articulate control implementation and apply security and compliance concepts
- Implementing continuous improvements to the security organization and program management processes
- Applying knowledge of global information security regulations to drive alignment to Amazon controls
Experience
- 5+ years performing or participating in IT audits based on ISAE 3401, auditing COBIT, ITIL, IT-Grundschutz, and assessments of highly technical cloud-based environments
- 3+ years building risk programs and strategies, staying current on industry trends such as changing regulations and innovations in risk mitigation
- 5+ years working in highly regulated industries (e.g., financial services, healthcare, energy, telecommunications), including direct experience with European audits and frameworks such as DORA
- Experience in compliance program management, legal, governance, audit, risk/loss prevention, or equivalent
- Experience handling confidential information and working directly with government officials and regulatory bodies
About you
You are passionate about cloud security and solving real business problems. You thrive working across diverse stakeholders, including internal and external customers, to design solutions for complex compliance challenges. You take ownership of your program vision and execution, balancing your perspective with those of your team and stakeholders. You value diversity, inclusion, and innovation, and are motivated to continuously improve processes and programs.
Qualifications
- Bachelor's degree or equivalent
- Preferred: Experience with SQL and Excel
- Preferred: Industry-recognized security, cloud, or audit certifications such as CISA, CISM, CISSP, CCSP, or Amazon Cloud Security Practitioner
- Preferred: Experience in technical security design, cloud services/deployment architecture (ideally Amazon cloud services), compliance consulting, or advisory roles in highly technical environments
- Preferred: Deep understanding of regulatory guidance including FCA FG16/5, DORA requirements for Critical Service Providers, C5 requirements of the Federal Office of Information Security of Germany, and other applicable standards
- Preferred: Proven track record delivering IT process improvement projects and generating automated metrics to measure effectiveness
- Preferred: Experience building certification roadmaps, compliance documentation, and ensuring timely delivery of assessments
- Preferred: Detailed understanding of evaluating IT control design and effectiveness and working with auditors/regulators for assessments

