Senior Regulatory Assurance Specialist, Security & Privacy Regulatory Enablement (SPRe)


Location
London
Hours
Full Time
Salary
Competitive, commensurate with experience
About the Role
Amazon's Security & Privacy Regulatory Enablement (SPRe) team drives regulatory compliance assurance across Security, Privacy, and AI domains. This Senior Regulatory Assurance Specialist role focuses on delivering external audits and regulatory examinations across multiple jurisdictions and frameworks, including payments, DMA, GDPR, and more. You will manage the full audit lifecycle, coordinate evidence collection, and represent Amazon's security and privacy posture to external auditors and regulators. The role requires deep expertise in both security and privacy compliance, strong stakeholder communication skills, and the ability to operate in complex, multi-jurisdictional environments. You will also contribute to regulatory analysis, control environment assessments, and automation initiatives to scale compliance efforts. This position leads the Assure function within SPRe, ensuring Amazon demonstrates compliance to external authorities and maintains customer trust through rigorous audit and regulatory assurance activities.
About the Team
SPRe operates as a continuous flywheel with three interconnected functions: Anticipate (regulatory engagement), Enable (programme design and compliance monitoring), and Assure (audit delivery and examination management). This role leads Assure, working alongside security and privacy specialists across India, Europe, and the US.
Diversity and Inclusion
Amazon Security values diverse experiences and encourages candidates from all backgrounds to apply. We foster an inclusive culture that embraces curiosity, continuous learning, and diverse perspectives to address complex security challenges.
Work/Life Balance
We promote work-life harmony and flexibility to support success both at work and at home.
Training and Career Growth
Amazon offers extensive knowledge-sharing, training, and career development resources to help you grow as a well-rounded professional.
Experience
- 7+ years in compliance programme management, regulatory assurance, audit delivery, governance, or risk management across security and/or privacy domains
- Experience performing technical audits supporting major compliance efforts such as ISO 27001, SOC 2, NIST, SOX, GDPR, DMA, DSA, HIPAA, or equivalent frameworks
- Proven track record managing external audit relationships, coordinating evidence, and driving findings to closure
- Skilled in conducting risk assessments, designing controls, and managing enterprise control frameworks
- Ability to navigate complex regulatory environments with high ambiguity and exercise sound judgment
- Excellent written and verbal communication skills for diverse technical and non-technical stakeholders
- Experience handling confidential information in regulated environments
About You
- Self-motivated and able to work independently in a fast-paced, global environment
- Strong collaborator who can influence cross-functional teams and senior stakeholders
- Detail-oriented with a passion for compliance and continuous improvement
- Comfortable working across multiple jurisdictions and regulatory frameworks
- Adaptable and eager to learn emerging regulatory trends, especially in AI governance and payments industry regulations
Qualifications
- Bachelor's degree or equivalent in Information Security, Computer Science, Risk Management, Privacy/Data Protection, Engineering, or related discipline
- Preferred professional certifications such as CISA, CISM, CISSP, CIPP/E, CIPP/US, CIPM, CIPT, CDPSE, PCIP, QSA, or similar
- Experience with GRC tools, data analytics, and automation of compliance processes is a plus
- Knowledge of AI governance frameworks (EU AI Act, NIST AI RMF) and emerging AI/ML regulatory trends preferred
- Experience working with payment industry regulations and supervisory authorities is advantageous

