Privacy Engineer, Incident Response, Devices & Services Trust, Privacy, and Accessibility (TPA)
Job
Amazon.com, Inc.
Bellevue, WA (In Person)
Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
72
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
Description Devices and Services Trust and Privacy (DSTP) is responsible for maintaining and raising the trust bar for Amazon customers across a diverse set of 30+ Devices and Services (D&S). DSTP offers horizontal services for builders to ensure trust, privacy, and accessibility is built into our products and services. We also build customer-facing capabilities that provides customers with control and transparency and reducing privacy risk, while enabling partner teams to innovate with appropriate guardrails for content moderation, privacy, accessibility, and trust. The DSTP team is looking for a passionate Security and Privacy Incident Response Engineer who can lead the response to privacy and data protection issues across Devices & Services. You must thrive in dynamic/ambiguous situations, and think like both an attacker and defender, while working through the entire incident response lifecycle. You'll be working in a global team environment where clear and accurate communication and collaboration on privacy and data protection issues is critical. In this role, you will apply your creative and critical problem solving skills to quickly contain incidents and then work with cross-functional teams to remediate the root cause. You must have a passion for engineering solutions to complex privacy and data governance challenges, and recognize and fill gaps in capabilities. Above all, you should be passionate about privacy, information security, the ever-changing threat landscape and privacy/security automation and tooling. Key job responsibilities
- Manage escalated privacy and trust risk events/cases from start to finish; write detailed case notes, reports, summaries, short and long-term recommendations, and trade-off analyses for all audiences, including senior leadership.
- Interact with and influence other teams (e.g., service teams, engineering, product, legal); identify experts and stakeholders on other teams to support decisions on containing incidents or mitigating privacy and trust risks; build consensus and recommendations based on analysis of the nature of potential violations to Privacy Policies, Promises, or Legal/Regulatory requirements.
- Own successful delivery of large, impactful, and highly cross-functional program initiatives while simultaneously tracking a set of smaller projects. Demonstrate comfort with handling technical investigations and analysis, and provide actionable recommendations to senior leadership audience with minimal supervision.
- Develop deep knowledge of global privacy and data governance obligations, processes, best practices, and solutions utilized by Amazon. Utilize this knowledge to provide recommendations and consultation to improve DSTP processes and tooling and reduce risk through control automation and enhancements.
- Establish metrics and regular reporting/escalation mechanisms for measuring results, progress, and gaps in performance and compliance.
- Communicate plans, status, and critical issues clearly and effectively.
- Support deep dive assessments and ad-hoc data analysis requests.
- Bachelor's degree in computer science or equivalent
- 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- CCSP (Certified Cloud Security Professional) or CEH (Certified Ethical Hacker) or CFR (CyberSec First Responder) or Cloud+ or CySA+ (CompTIA Cybersecurity Analyst) or GCED (GIAC Certified Enterprise Defender) or GICSP (Global Industrial Cyber Security Professional) or PenTest+ Preferred Qualifications
- Experience applying threat modeling or other risk identification techniques or equivalent
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .
- 159,300.00
- 202,400.
Similar remote jobs
Genesis10
Columbus, OH
Posted2 days ago
Updated16 hours ago
WesBanco Bank Inc.
Columbus, OH
Posted2 days ago
Updated16 hours ago
Similar jobs in Bellevue, WA
Amazon.com, Inc.
Bellevue, WA
Posted2 days ago
Updated16 hours ago
Overlake Medical Center and Clinics
Bellevue, WA
Posted2 days ago
Updated16 hours ago
Amazon
Bellevue, WA
Posted2 days ago
Updated16 hours ago
Similar jobs in Washington
Costco Wholesale Corporation
Issaquah, WA
Posted2 days ago
Updated16 hours ago
The Blazing Onion Burger Co
Gig Harbor, WA
Posted2 days ago
Updated16 hours ago
Greystar Real Estate Partners LLC
North Bend, WA
Posted2 days ago
Updated16 hours ago