Sr. Security Governance Specialist, MCCF

3 days ago


Bengaluru, Karnataka, India Amazon Full time ₹ 1,50,00,000 - ₹ 2,50,00,000 per year
DESCRIPTION

Are you passionate about security and access governance, monitoring and risk management? Buy with Prime and Multi-Channel Fulfillment (MCF) are looking for a highly motivated and experienced Security Governance Specialist ready to partner across Amazon tech and security groups to secure and protect our services and data. This security specialist will drive programs focused on providing multiple cross-cutting capabilities such as Access governance, Access policy management, security monitoring and detection, risk management, and continuous monitoring. You will act as a key member of the team responsible for Security Operations including Access Governance, security design, and exception activities, including automation. Candidates must have experience designing access control solution, access governance and risk management experience, including performing control self-assessments and managing external audits, designing controls, and prioritizing risk.

We operate in a hyper-growth environment where priorities shift quickly, so a passion and discipline around security and delivery is critical. You will tackle challenging situations every day and, given the size of this initiative, you will collaborate with various levels across Buy with Prime, MCF and Amazon. We are seeking a security specialist, who is comfortable working in a fast-paced, ever-changing environment and willing to dive deep into assessments and analytical rigor. Our team is growing, and we need security specialists who don't work reactively, but can operate independently, anticipate potential security challenges, and proactively monitor and improve the mechanisms we use to detect and correct potential non-compliance. The ability to partner with Service Teams and develop automated mechanisms and responses to potential instances of non-compliance will be key to scale the security program in key areas of Access Management, Risk Management, and Continuous Monitoring.

Key job responsibilities

  • Design, implement and manage access control governance process and access control policies
  • Analyze business, product and security data, uncover evolving threats, identify weaknesses and opportunities in risk defense
  • Apply a working knowledge of information security and privacy regulation and policy to articulate customer and control impact and drive alignment to controls.
  • Quantify risk control effects and trends, collaborate with engineering, operational and product teams, contribute to risk measurement, mitigation and prevention.
  • Build detections rules to recognize, prevent and mitigate access violations.
  • Establish regular reporting mechanisms for measuring compliance and performance;
  • Develops metrics that demonstrate the current risk state, indicators of progress, and business alignment
  • Support Continuous Monitoring initiatives to drive enforcement, oversight and improvement of security controls implementation through automation
  • Perform quality reviews on identified risks to drive adherence to policy and playbook requirements
  • Provide guidance to technology owners on the execution of security and compliance requirements, related processes and playbooks, and usage of related systems and tools
  • Collaborate with tech and process owners to identify, document, and manage the performance of technology risk concerns
  • Assist business and process owners with remediating risks (including Audit Identified Issues, Self-Identified Issues, Risk Identified Issues, and Regulatory Issues) and achieving compliance with multiple policies and standards
  • Partner with tech and security teams and to review and challenge identified risks, remediation plans, progress and status, and drive action as needed
  • Monitor and oversee performance against Key Risk Indicators, including "Path to Green" plans
  • Drive the successful achievement of business goals, including timely identification, escalation and remediation of risks and issues that impact program execution and delivery
  • Active participation during the identification, remediation, and oversight of technology issues/ risks; including action plan development and execution

About the team

Multichannel Commerce & Fulfillment (MCCF) is the Multi-Channel Fulfillment service offered by Amazon to help merchants manage their ecommerce operations. Our vision is to enable every entrepreneur in the world to reach every customer in the world through every channel they can imagine. Buy with Prime is a new way to extend Prime shopping benefits - including fast, free shipping, seamless checkout experience, and free returns - to merchants' own online stores, ultimately increasing selection for Prime members. Our mission to help merchants of all sizes grow their business - whether on Amazon or beyond.

Mentorship & Career Growth

Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we're building an environment that celebrates knowledge sharing and mentorship.

Work/Life Balance

Our team puts high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren't focused on how many hours you spend at work or online. Instead, we're happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work.

BASIC QUALIFICATIONS
  • Bachelor's degree or equivalent in Information Security, Computer Science, Risk Management, Engineering, Math, Statistics, or a related discipline, or equivalent technology experience

    • 5+ years of governance, risk, and monitoring experience for a large and complex organization
    • Strong knowledge of security certification and compliance frameworks (e.g. ISO 27001, AICPA SOC 1/2/3, HIPAA, HiTRUST, and NIST SP / CMMCv2) and ability to adapt and apply them in conjunction with business requirements
    • Knowledge of cloud-based models (IaaS, PaaS, SaaS) and technologies used to implement controls within these environments
    • Ability to communicate and manage information security concepts and requirements to personnel of varying technical backgrounds and positions
    • Understand and ensure compliance and risk management requirements for supported area and work with other stakeholders to implement key risk initiatives
    • Functional experience across two or more information and cyber security domains (e.g., application security, identity and access management, vulnerability management, Continuous Monitoring)
PREFERRED QUALIFICATIONS
  • Experience working with global cross-functional teams

    • Good understanding of Fine Grained Access controls and working knowledge of creating, managing and monitoring access policies.
    • A fast learner who can quickly absorb the nuances and behaviors of Amazon's systems architecture.
    • Effective analytical skills. Proven history of analyzing data and situations to identify meaningful observations.
    • Strong critical thinking skills, consistent attention to detail and ability to meet deadlines amidst competing priorities
    • Strong relationship management skills to navigate the complexities of aligning stakeholders, building consensus and resolving conflicts in a large, distributed organization
    • Proven ability to manage multiple and often competing priorities in a global environment;
    • Ability to drive routines, projects and programs with a track record of successful execution / change
    • Ability to decompose complex issues and drive timely decisions, knowing when to engage others for additional input or escalation; ability to synthesize information in order to drive results
    • Strong communication skills (written and oral);
    • Ability to communicate complex ideas in a clear and concise manner, including to senior business leaders and executives

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.



  • Bengaluru, Karnataka, India Amazon Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Are you passionate about security and access governance, monitoring and risk management? Buy with Prime and Multi-Channel Fulfillment (MCF) are looking for a highly motivated and experienced Security Governance Specialist ready to partner across Amazon tech and security groups to secure and protect our services and data. This security specialist will drive...


  • Bengaluru, Karnataka, India National E-governance Services Limited Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    The Professional, Data Management & Governance job ensures the accuracy, security and effective use of the organization's moderately complex data. With limited supervision, this job supports the development Required Candidate profileSTRATEGIC PLANNING: Implements and supports the development of data management and governance strategies aligned with...


  • Bengaluru, Karnataka, India Pyramid It Consulting Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Skills: Data Engineering, Python, SQL, Cloud Engineer, Presales, Solutioning/Solutions Architect.Designation: Sr. Research Specialist

  • Security Specialist

    1 week ago


    Bengaluru, Karnataka, India beBeeSecurity Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Security Specialist Job OpportunityThis role is ideal for a skilled Security Specialist who can drive the company's incident response and threat hunting efforts.The Security Specialist will join a team of experienced professionals working to protect the organization's digital assets from cyber threats.Responsibilities:Incident Response: Respond to and manage...


  • Bengaluru, Karnataka, India National E-Governance Services Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    RequirementsSecurity Engineer with a strong background in Java (Full Stack) based Software Development, Spring MVC, Spring Boot, Spring Security, Hibernate including secure software development practices.Hands-on experience in source code reviews, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API security.8+...


  • Bengaluru, Karnataka, India Worldwide Flight Services (WFS) Full time ₹ 12,00,000 - ₹ 16,00,000 per year

    The Information Security Specialist will be responsible for monitoring, maintaining, and improving the organization's security posture. The role involves incident management and response, endpoint security, identity and access management, compliance with ISO 27001:2022, and support in employee awareness programs. The specialist will work closely with...


  • Bengaluru, Karnataka, India C5i Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Summary:The Data Governance Specialist supports the design, development, and execution of the organization's data governance framework. The role ensures alignment of data practices with business objectives, promotes data as a strategic asset, and collaborates with data owners, stewards, and cross-functional teams to strengthen data quality, compliance,...


  • Bengaluru, Karnataka, India Docusign Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Company OverviewDocusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now,...


  • Bengaluru, Karnataka, India DocuSign Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Company OverviewDocusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now,...


  • Bengaluru, Karnataka, India 3M Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    3M has a long-standing reputation as a company committed to innovation. We provide the freedom to explore and encourage curiosity and creativity. We gain new insight from diverse thinking, and take risks on new ideas. Here, you can apply your talent in bold ways that matter.Job Description:We are seeking a highly organized and communicative Information...