> Markdown version of [/jobs/ext/2083500-aws-security-risk-specialist-aws-security-risk](https://www.wearedevelopers.com/jobs/ext/2083500-aws-security-risk-specialist-aws-security-risk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AWS Security Risk Specialist, AWS Security, Risk,... - **Company:** Amazon.com, Inc. - **Location:** Herndon, VA, United States - **Experience:** Experienced - **Salary:** $55,600.0 - $97,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cyber Security, Information Systems, Information Technology Audit, Information Technology - **Published:** August 16, 2026 - **Apply:** https://www.juju.com/job/00000000gncldj ## About the Role Bachelor's degree in Computer Science, Information Systems, Finance, Accounting, or a related field - 2+ years of experience in security, audits, customer trust, control assessments, and/or security controls. - 2+ years of experience assessing complex technical processes Preferred Qualifications - Experience in audits related to business processes, risk mitigation, program compliance, or internal audits - Experience with risk management and governance processes. - Experience in third-party, Government, and/or internal audit examinations. - Demonstrates high judgement and risk decision making abilities. - Experience with writing and documentation IT security or risk procedures. ## Description At Amazon Web Services (AWS), Security is our highest priority. The AWS Security Assurance team is responsible for demonstrating the security controls of services offered by AWS. At AWS' scale, we invent new ways to provide the highest level of assurance to our most security conscious customers. We are looking for a highly motivated risk specialist with either IT audit and/or risk assessment experience to join our team. As part of the team, you will be responsible for conducting risk assessments across our security controls product to ensure readiness of new tools with external compliance obligations. You will understand the key objectives and goals of customers, regulators, and third-party audit frameworks and understand AWS controls that strategically address these goals and objectives. Additionally, you will be responsible for assessing AWS' operational processes around controls and be able to determine document risk governance processes. The successful candidate is one who loves learning about AWS's internal security controls framework, learning about new AWS services, and enjoys working across many stakeholders and compliance frameworks. We have a team culture that encourages ownership, diversity, inclusion, and innovation. Our team members and management alike take a high degree of ownership for their program vision and execution of ideas. Our team members balance their unique perspective with those of the diverse perspectives of the team and its stakeholders. You will work directly with divisions within AWS service to improve AWS' ability to demonstrate assurances for our internal and external customers while reducing risk. In this role, you will facilitate open and transparent relationships with AWS internal stakeholders and customers. We seek a risk professional who can understand core security design principles, learn about new AWS services and their IT processes, and be able to document risk management and governance processes related to these assessments. This position can work out of our AWS office in Arlington, VA, Herndon, VA, or Seattle, WA. Key job responsibilities This position will be responsible for the following activities: * Be able to understand risk management and governance processes quickly and efficiently. * Write, articulate, and develop security risk documentation. * Review evidence needed to illustrate the key controls that exist across the AWS environment * Communicate to key stakeholders the operational processes around AWS security practices and how controls are implemented across the environment. * Communicate to leadership key risks and areas of program improvement, as well as seek diverse opinions and coordinate improvement efforts. * Fielding and addressing requests in collaboration with internal stakeholders across a security, risk, and compliance function at AWS. * Dive deep into the AWS control environment to develop broad domain and technical understanding of AWS control activities and implementation. * Bridge communication with key stakeholders and AWS technical communities to articulate control implementation., At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reliable scalability: How Amazon.com scales on AWS](https://www.wearedevelopers.com/videos/983-reliable-scalability-how-amazon-com-scales-on-aws) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)