Governance Risk and Compliance Manager, AWS Security
DESCRIPTION
Amazon Web Services (AWS) is the leading cloud service provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at massive levels of scale. Businesses, from start-ups to enterprises to large government customers, run their operations and applications on AWS’ highly secure infrastructure.
AWS Security is looking for a Security Assurance Manager to lead and manage the certification, accreditation, assurance, and authorisation activities across the security program. You will establish and execute the overall strategy to achieve the overall milestone for the program. The successful candidate is a strategic thinker, with a deep understanding of the regulatory landscape, solid understanding of cloud technologies, experience in security and compliance, and demonstrated success in driving innovative strategies to overcome complex policies and obstacles to cloud assurance and authorisation. You will be responsible for ensuring the security of AWS services, which will lead towards achieving the overall milstone outcomes for a region. Additionally, you will be a thought leader and will be sought out for your expertise as you invent and innovative in the course of your duties.
Key job responsibilities
* Serve as the Security Assurance leader for all components within the cloud capability, guiding and overseeing assurance and authorization activities to ensure adherence to standards and protocols.
* Collaborate with internal teams and customers to establish baselines and level-set the security requirements, security controls, and security objectives.
* Develop and implement strategies to drive security outcomes across the cloud capability, determining the methodology for collecting evidence for submission and ensuring compliance with relevant frameworks.
* Implement ISM, PSPF, DSPF, ASIO T4, NIST and/or other security compliance frameworks into design and build baselines to achieve the agreed security posture.
* Create, optimise, and support cross-functional working groups and projects aimed at enhancing security efficiency and effectiveness across the organization.
* Utilise domain expertise to develop thought leadership material on cloud and emerging technologies, contributing to the organization’s knowledge base and industry positioning.
* Manage tight deadlines and drive results, demonstrating exceptional attention to detail and ensuring accuracy in all aspects of security management.
Hold or be able to attain an Australian Government Security Vetting Agency clearance (see https://www1.defence.gov.au/security/clearances).
A day in the life
In your day-to-day you will need to exercise sound judgment in making trade-offs between short versus long term security and business goals. You will demonstrate resilience and navigate difficult situations with composure and tact, with a goal to achieve a great outcome for the customer. You will be successful in this role by regularly analysing your own performance with a critical eye. A broad understanding of the AWS business and its interconnections is required. This position will also provide training, advice, and mentorship to other teams throughout AWS.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
The team is comprised of security professionals with a cross section of national security and private sector experience, providing a range of perspectives required for creative problem solving. We value diversity of thought, creativity, and a strong Bias for Action and Earn Trust. We believe that there are no "perfect" security solutions and we develop and iterate using a continuous improvement process.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
BASIC QUALIFICATIONS
* 6+ years experience working in areas related to security assurance, such as cybersecurity, auditing, security architecture, regulatory affairs or public sector agencies involved in cybersecurity management.
* Experience working with governance, risk and compliance programs that directly involve interaction with regulatory bodies.
* Proficient with government security frameworks, policies and standards (e.g. PSPF, ISM, DSPF. ASD Essential Eight)
* Experience working with cloud technologies.
PREFERRED QUALIFICATIONS
* Degree or equivalent experience in (Computer Science, Engineering, Cyber Security, IT Security Management, Security Risk Management)a related security field
* Minimum 5 years experience in implementing and operationalising security to meet business outcomes
* Ability to able to credibly coordinate between technical teams and business stakeholders
Acknowledgement of country:
In the spirit of reconciliation Amazon acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.
IDE statement:
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer, and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, disability, age, or other legally protected attributes.