Security Assessor, Security Assurance is looking for a technical industry specialist focused on driving information security compliance in Healthcare and Payments systems. This role will provide advisory guidance to new and existing businesses at Amazon, and will regularly conduct deep dives into critical risk areas. If you enjoy working in a rapidly changing environment and influencing the strategic direction of a large global organization, this position will provide you with a challenging opportunity. You will be responsible for driving consensus across teams to define and influence the secure and compliant design of systems worldwide.

Key requirements include:
• Understands and rationalizes compliance requirements in the healthcare and payments domains. Provides business specific interpretations and supports automation opportunities while working with DevOps teams.
• Establishes credibility and maintains strong working relationships with groups involved with payment security and compliance matters (InfoSec, Legal, Business Development, Internal Audit, Fraud, Physical Security, Developer Community, Networking, Systems, etc.).
• Collaborates with Compliance Specialists and business/service teams to understand and validate assessment scope.
• Reviews security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity.
• Responsible for building and influencing security as a core competency throughout our relationships with internal teams/partners/vendor; this includes providing education and training to the organization.
• Delivers recommendations and risk interpretations in a clear, concise and audience-specific format
• Engages with the Business and SMEs to ensure compliance to information security policies
• Supports ad-hoc data analysis requests
• Performs analysis of historical data to identify trends and insights
• Leads the creation, implementation, monitoring, and maintenance of security Policies and Standards

• Bachelor’s degree in Management Information Systems, Computer Science or relevant field, Master’s Degree preferred.
• 5-8 years of relevant industry experience including information assurance, data privacy and compliance in healthcare domains.
• 5-8 years of information security governance, audit, risk management or related client service or consulting experience.
• Skilled in risk management, business risk analysis and making complex business/risk trade-off recommendations and decisions.
• Technical knowledge and familiarity with information security standards.

• Related security control and compliance experience in various frameworks including: HIPAA, HITRUST, PCI DSS, GLBA, ISO, NIST, etc.
• CISSP, CISA, CISM, CIPP, CEH and/or other comparable security controls or audit certifications preferred.
• Experience with service-oriented architectures and web services security.
• Demonstrated leadership, teamwork and collaboration skills.
• Results oriented, self-motivated.
• Occasional travel may be required.

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $91,800/year in our lowest geographic market up to $185,000/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit Applicants should apply via our internal or external career site.

Job Category
Job Type
Career Level