Senior Regulatory Assurance Specialist, Security & Privacy Regulatory Enablement (SPRe)


Location
London
Hours
Full Time
Salary
Competitive, commensurate with experience
About the Role
Amazon's Security & Privacy Regulatory Enablement (SPRe) team serves as the regulatory enablement engine for Amazon's security, privacy, and AI compliance assurance needs. The team manages new regulatory requirements from initial publication to demonstrated compliance across Security, Privacy, and AI domains using a repeatable, scalable operating model (Anticipate → Enable → Assure). This role leads the Assure function, delivering external audits and regulatory examinations across security and privacy domains in multiple jurisdictions and regulatory frameworks.
As a Senior Regulatory Assurance Specialist, you will manage the full external audit lifecycle—from planning and scoping through evidence coordination, auditor management, and report issuance. You will represent Amazon’s security and privacy posture in regulatory audits and examinations, coordinate evidence collection, develop and maintain Risk Control Matrices (RCMs), and manage audit findings through to formal closure.
You will work closely with legal teams to analyze regulatory requirements, perform scoping and applicability assessments, and dive deep into control environments to assess control design and operational effectiveness. You will contribute to emerging regulations and technology standards, influence automation efforts for evidence collection and control testing, and communicate audit status and critical issues to senior stakeholders. This role requires prioritizing and delivering results across a global, multi-jurisdictional environment.
SPRe operates through three interconnected gears: Anticipate (regulatory engagement and horizon scanning), Enable (programme design and compliance monitoring), and Assure (external audit delivery and regulatory examination management). This role is critical to demonstrating Amazon’s compliance to external regulators, auditors, and supervisory authorities, directly impacting customer trust.
Experience
- 7+ years in compliance programme management, regulatory assurance, audit delivery, governance, or risk management spanning security and/or privacy domains
- Experience performing technical audits/assessments supporting major compliance efforts (e.g., ISO 27001, SOC 2, NIST, SOX, GDPR, DMA, DSA, HIPAA, or equivalent frameworks)
- Proven experience managing external audit relationships, coordinating evidence, and managing findings through closure
- Experience conducting risk assessments, designing controls, and managing enterprise control frameworks
- Ability to work with high ambiguity in complex regulatory environments and exercise sound judgment in prioritization
- Excellent written and verbal communication skills for technical and non-technical stakeholders across multiple jurisdictions
- Experience handling confidential information in regulated environments
About You
- Self-motivated and experienced professional with a strong background in both Information Security and Privacy compliance
- Comfortable operating across multiple regulatory domains and jurisdictions
- Skilled at breaking down complex regulatory requirements into manageable programmes and delivering results
- Collaborative team player who can influence automation and compliance process improvements
- Able to communicate clearly to senior stakeholders and drive issues to resolution
Qualifications
- Bachelor's degree or equivalent in Information Security, Computer Science, Risk Management, Privacy/Data Protection, Engineering, Math, Statistics, or related discipline, or equivalent technology experience
- Professional auditing qualifications or certifications preferred (CISA, CISM, CISSP, CIPP/E, CIPP/US, CIPM, CIPT, CDPSE, PCIP, QSA, or similar)
- Experience with GRC tools, data analytics, and automation of compliance processes preferred
- Knowledge of AI governance frameworks (EU AI Act, NIST AI RMF) and emerging AI/ML regulatory trends preferred
- Experience with payment industry regulations and supervisory authorities preferred
- Demonstrated ability to maintain trusted relationships with external regulators, auditors, and industry forums

