Berlin | Anteilig remote | Vollzeit

Security Assurance Specialist , AWS Compliance and Security Assurance EMEA

Key job responsibilities

As part of the team, you will work with customers and regulators to demonstrate Amazon security controls applicable to local requirements. You will join our team in helping customers understand how our infrastructure is designed, operated, maintained, and protected in accordance with global regulated industry standards. In this role, you will be responsible for the following activities:

  • Dive deep into the Amazon control environment to develop broad domain and technical understanding of our security activities and control implementations to articulate compliance implications to both customers and internal/external audit functions.
  • Develop understanding of regulated industry compliance requirements and communicate how we control activities to meet global regulatory obligations.
  • Liaise with customers, regulators and auditors, articulate control implementation, and describe considerations for applying security and compliance concepts to monitor, evaluate, and continuously improve the organization by being a trusted advisor, facilitator and creative problem solver.
  • Implement continuous improvements to the security organization and the program management process. Share program/project process frameworks, tools, and best practices that can be adopted throughout the organization.
  • Apply a working knowledge of global information security regulation and policy to articulate customer and control impact and drive alignment to Amazon controls.

BASIC QUALIFICATIONS

  • Bachelor's degree or equivalent in Computer Science, Engineering, Information Systems Management, Information Security or other related fields
  • This role requires you to be a national of an EU member state
  • 5+ years of working experience in performing and/or participating in IT audits based on ISAE 3401, auditing COBIT, ITIL, IT-Grundschutz and assessments of highly technical cloud-based environments.
  • 3+ years’ experience working and building risk programs and strategies up to date on related industry trends (e.g., changing regulations, innovations in risk mitigation, testing mechanisms)
  • 5+ years working in highly regulated industries (e.g. financial services, healthcare, and energy, telecommunications), including direct work with European audits and frameworks such as DORA.

PREFERRED QUALIFICATIONS

  • 1 or more industry-recognized security, cloud, or audit professional certifications (e.g., CISA, CISM, CISSP, CCSP, Amazon Cloud Security Practitioner
  • Experience in technical security design, cloud services/deployment architecture (ideally Amazon cloud services offering), compliance consulting, or advisory work in a highly technical environment.
  • Deep understanding of regulatory guidance, FCA guidance FG16/5 (Guidance for firms outsourcing to the ‘cloud’ and other third-party IT services), DORA requirements for Critical Service Provider, C5 requirements of the Federal Office of Information Security of Germany and other applicable standards and requirements.
  • A record of delivery of IT process improvement projects with technology processes and/or major tech companies along with generating automated metrics to measure effectiveness and consistency.
  • Experience building certification roadmaps based on customer requirements, compliance documentation, and ensuring that committed assessments are delivered on schedule.
  • A detailed understanding of evaluating the design and effectiveness of IT controls and experience working with auditors/regulators for these types of assessments