> Markdown version of [/jobs/ext/498657-security-industry-specialist-subsidiary-acquisition-grc](https://www.wearedevelopers.com/jobs/ext/498657-security-industry-specialist-subsidiary-acquisition-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Industry Specialist, Subsidiary & Acquisition GRC - **Company:** Amazon.com, Inc. - **Location:** Hawthorne, CA, United States - **Salary:** $102,000.0 - $178,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Code Review, Cyber Security, Data Sharing, Identity and Access Management, Network Security, PCI Data Security Standards, Software Architecture, Software Engineering, Data Logging, Information Technology, Software Coding, Restful APIs, Software Version Control - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=aba60edd566c0a66 ## About the Role Do you have experience in Stakeholder management?, Do you have a Master's degree?, * Experience in security or compliance consulting or advisory work in support of a highly technical environment * 3+ years of IT platform implementation in a technical and analytical role experience * Bachelor's degree in computer science or equivalent, or 5+ years of IT Security experience * 3+ years in performing and/or participating in technical assessments in direct support of a major compliance effort (e.g. NIST, SOC 2, or ISO), * Master's degree or above in a technical or engineering related field, such as Electrical Engineering, Computer Science, etc. - Knowledge of one or more of the following domains: access-control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security * 1+ years of technical specialist, design and architecture experience, or AWS Professional level certification * Knowledge of professional software engineering & best practices for full software development life cycle, including coding standards, software architectures, code reviews, source control management, continuous deployments, testing, and operational excellence * Experience communicating across technical and non-technical audiences, including executive level stakeholders or clients * Experience with compliance & security standards including PCI DSS, ISO 27001, HIPAA, and NIST ## Description Blink (Amazon's subsidiary) Security team is growing and looking for a highly motivated security risk & compliance specialist to join our team and drive regulatory compliance requirements for our products. In this role, you will work collaboratively with various business and security teams across Amazon to identify compliance needs, assess the maturity of processes and controls, design, build, and execute high-impact security or compliance programs to ensure successful audit executions. You should be a technically experienced and innovative security, risk, compliance, and audit professional who has the ability to understand systems, security, and privacy processes, communicate to customers, and to be able to drive innovative process changes through multiple organizations and teams., * Understand and rationalize regulatory requirements for service and device security * Proactively assess, identify and develop recommendations regarding data protection, insider threat, data sharing, identity and access management, and third party risk issues and vulnerabilities by working with multiple stakeholder teams, including Privacy, Legal, HR, IT, etc * Engage with the Business and SMEs to ensure compliance to information security policies * Review security controls that are technical in nature, such as access controls, data encryption in transit and at rest, and auditing and logging user activity * Develop and maintain relevant security risk metrics to promote transparency across the organization; measures, monitors and reports on information security risks to management * Maintain control libraries and compliance requirements and guidance materials for various security standards and regulations. * Provide business specific interpretations and support automation opportunities * Liaise with auditors, articulate control implementation and impact, and establish considerations for applying security, privacy and compliance concepts to a technical cloud environment A day in the life The Subsidiary & Acquisition Security team designs and engineers high-profile consumer devices, including the Ring, Blink, Amazon Keys, and Side walk family of products. The Subsidiary & Acquisition GRC team works to ensure that our services are designed and implemented to the high standards required to maintain and enhance customer trust. Security and Privacy are paramount to maintaining trust and we need to continue to build trusted products, maintain and operate trusted environments, and advocate trust to customers and stakeholders About the team Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores. Inclusive Team Culture In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices. ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Smart City, Smart Mobility](https://www.wearedevelopers.com/videos/954-smart-city-smart-mobility) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)