Senior Security Risk Specialist, Global Benefits Risk & Compliance

Amazon

Seattle (WA)

On-site

USD 119,000 - 209,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Amazon.com Services LLC is seeking a Senior Security Risk Specialist within the BXT Risk team to lead third-party vendor risk assessments for US health and financial employee benefits programs. You will evaluate security, privacy, and regulatory posture and drive scalable risk management across multiple vendors and systems.

The role requires strong collaboration with US benefits policy, process, and system owners to define strategies, assess complex risks, and implement remediation plans that

Qualifications

  • Bachelor's degree or equivalent in Information Security, Computer Science, Risk Management, Engineering, Math, Statistics, or related discipline
  • 7+ years of risk management, audit, legal, compliance or related field experience with external stakeholders
  • Experience with IT compliance and risk management requirements (security, privacy, SOX, HIPAA)

Responsibilities

  • Lead complex third-party vendor risk assessments across benefits programs and vendors, evaluating security, privacy, and compliance posture
  • Define and iterate risk assessment methodologies and frameworks to scale with diverse vendor requirements
  • Identify long-term risks from third-party vendors and influence business strategy to mitigate them
  • Make independent decisions on vendor engagements, audits, and regulators with minimal oversight
  • Drive benefits compliance management related to third-party service delivery and regulatory requirements
  • Lead risk and control assessments of vendor-managed processes and report remediation plans

Skills

Risk management
Regulatory compliance
Stakeholder communication

Education

Bachelor's degree or equivalent

Job description

Description

The Benefits Experience and Technology Risk team (BXT Risk) is responsible for managing employee benefits risk activities in countries where we do business. As a Senior Security Risk Specialist on the BXT Risk team, you will serve as a subject matter expert and strategic contributor to our benefits third-party risk ecosystem, working across the organization with US benefits policy, process, and system owners to define strategies, evaluate complex risks, and drive scalable solutions that mitigate risks introduced by third-party vendors and service providers supporting the organization's US health and financial employee benefit programs.

Key job responsibilities
Third-Party Risk Strategy And Assessment
  • Lead complex third-party vendor risk assessments across multiple benefits programs and vendor relationships, evaluating security, privacy, and compliance posture against federal, state, and local regulatory requirements
  • Define and iterate on risk assessment methodologies, frameworks, and mechanisms to scale for diverse vendor requirements and evolving regulatory expectations (e.g., quantitative risk models, vendor risk questionnaires, continuous monitoring approaches)
  • Identify long-term risks associated with third-party vendors and influence business strategy to proactively mitigate them before they materialize into risk events
  • Make diligent, independent decisions on how to engage vendors, auditors, and regulators on third-party risk matters with minimal oversight
  • Drive comprehensive benefits compliance management related to third-party service delivery, ensuring adherence to federal, state, and local regulatory requirements including HIPAA, ERISA, ACA, and COBRA
  • Lead risk and control assessments of vendor-managed processes, determine state of compliance, analyze risk exposure, and author reports detailing methodology, results, and remediation plans
Program Leadership And Scalable Solutions
  • Own and drive third-party risk review programs associated with benefits program launches, modifications, vendor onboarding, and transitions across the organization
  • Create predictable process paths, workflows, and repeatable mechanisms (e.g., for vendor security control design, testing, implementation, and validation) that multiple teams utilize to deliver consistent risk management outcomes
  • Identify opportunities to simplify approaches throughout the organization and across project boundaries; decouple dependencies and prevent duplicate or wasted effort
  • Define business problems, set objectives, analyze data, drive improvements, and influence resource allocation for third-party risk initiatives
  • Develop mechanisms to inspect, monitor, and improve third-party risk delivery over time; hold the team to a high standard for both solutions and practices
  • Escalate when risks or blockers emerge, propose viable recommendations to resolve them, identify the correct owners, and track issues to resolution
Vendor Systems, Process, And Compliance Oversight
  • Develop deep understanding of the employee benefits solutions utilized by Amazon and the third-party vendors that support them; drive business requirements for vendor system implementations and enhancements
  • Lead collaboration with vendors and external teams to evaluate security controls, negotiate remediation timelines, and ensure employee-centered benefits experiences are delivered securely
  • Understand the builder and stakeholder experience with security compliance and proactively seek to align third-party risk processes with existing workflows
  • Author written narratives to define strategy, evaluate trade-offs, anticipate risks, and recommend solutions on third-party risk that influence the organization and external partners
Stakeholder Engagement, Influence, And Communication
  • Drive business and technical discussions across the organization to make decisions on how to align with diverse, potentially conflicting, third-party risk and compliance expectations
  • Advise managers and directors on third-party risk matters; communicate effectively with leaders up to three levels above on risk posture, compliance gaps, and strategic recommendations
  • Write, speak, and network with key internal and external stakeholders to broaden influence on third-party risk management practices
  • Develop and deliver documentation such as manager and employee communications, FAQs, policy positions, standard operating procedures, and strategic narratives related to third-party risk
  • Mentor and develop junior team members in third-party risk assessment methodologies, compliance frameworks, and stakeholder engagement
About The Team

The BXT Risk team is made up of lawyers, risk specialists, data security specialists, automation experts, and privacy specialists with global HR and benefits backgrounds. We are a dedicated collective committed to creating supportive, comprehensive benefits solutions. We provide our benefits stakeholders guidance to help them identify and manage potential risks and improve their team's risk management strategies and compliance posture. The team proactively scans the horizon for new and emerging risks not yet fully developed or understood, and performs inspections to identify compliance gaps and control weaknesses before they materialize into risk events. We provide end-to-end risk management oversight, including risk identification, risk assessments, risk quantification, compliance advisory services, inspection services, control design and testing, compliance solutions, risk monitoring and reporting, issue management, and risk training.

We cultivate an environment where every team member feels valued, empowered, and equipped to thrive both professionally and personally. Our work goes beyond benefits operations - we're building experiences that genuinely care for our employees.

Basic Qualifications
  • Bachelor's degree or equivalent in Information Security, Computer Science, Risk Management, Engineering, Math, Statistics, or a related discipline, or equivalent technology experience
  • 7+ years of risk management, audit, legal, compliance or related field work including engaging with external stakeholders experience
  • Experience with IT compliance and risk management requirements (e.g. security, privacy, SOX, HIPAA etc.)
Preferred Qualifications
  • CISSP, CISA, CISM or other security certification
  • Advanced degree in a related area (Information Security, Risk Management, MSHR, MBA, JD)
  • Deep knowledge of federal benefits regulations including ACA, COBRA, ERISA, and HIPAA, as well as state and local regulations including Massachusetts, Vermont, Hawaii, and San Francisco
  • Experience influencing vendor security and compliance strategies across an organization, including negotiating remediation timelines and shaping vendor contractual obligations
  • Proficiency across multiple widely adopted security compliance regimes and frameworks (SOC, PCI, NIST, ISO) with ability to apply expertise across diverse regulatory environments

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, WA, Seattle - 119,300.00 - 208,900.00 USD annually

Company

Amazon.com Services LLC

Job ID: A10415257

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Benefits Risk & Vendor Compliance Strategist
Senior Benefits Risk & Vendor Compliance Strategist

Amazon • Seattle (WA)

On-site
USD 119,000 - 209,000
Technical Business Developer III
Technical Business Developer III

Amazon.com Services LLC - A57 • New York (NY)

On-site
USD 140,000 - 190,000
Senior Risk Analyst, SPEAR Special Programs & Projects
Senior Risk Analyst, SPEAR Special Programs & Projects

Amazon • Washington (IN)

On-site
USD 119,000 - 209,000
Health insurance
RSU package
Paid time off
Senior Risk Manager, Amazon Health Services, Business Compliance
Senior Risk Manager, Amazon Health Services, Business Compliance

Amazon • Seattle (WA)

On-site
USD 121,000 - 164,000
Health insurance
RSU eligibility
401(k) matching
+1
Manager, Security Engineering, Secure Third Party Tools
Manager, Security Engineering, Secure Third Party Tools

Amazon • Seattle (WA)

On-site
USD 175,000 - 237,000
RSUs
Sign-on bonus
Health insurance
+2
AWS Security Risk Specialist, AWS Security, Risk, and Compliance
AWS Security Risk Specialist, AWS Security, Risk, and Compliance

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 56,000 - 97,000
Health insurance
RSUs
401(k) matching
+3
Security Industry Specialist, Subsidiary & Acquisition GRC
Security Industry Specialist, Subsidiary & Acquisition GRC

Amazon • Hawthorne (CA)

On-site
USD 102,000 - 178,000
RSUs
Health benefits
Security Industry Specialist, Subsidiary & Acquisition GRC
Security Industry Specialist, Subsidiary & Acquisition GRC

Amazon • Austin (TX)

On-site
USD 102,000 - 178,000
Manager, Security Engineering, Corporate Services Security (CPSS)
Manager, Security Engineering, Corporate Services Security (CPSS)

Amazon • Arlington (VA)

On-site
USD 175,000 - 237,000
Security Assurance Specialist , AWS Compliance & Security Assurance
Security Assurance Specialist , AWS Compliance & Security Assurance

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 102,000 - 178,000
RSUs
Health insurance
401(k) matching
+1