Amazon · Seattle, WA

Salary
$102,000–$178,400from the description
Posted
Jul 2, 2026
Location
Seattle, WA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

This role sits within AWS's security assurance function, focused on building and maintaining a security controls product that supports external audit and compliance activities. Day-to-day work involves documenting and updating security controls and policies, reviewing audit evidence, and acting as a bridge between AWS technical teams and external auditors or regulators. It suits someone with an IT audit background who is comfortable navigating multiple compliance frameworks and communicating complex control environments to varied audiences.

Mid level · 3+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Must have (3)
IT auditsecurity controls · 3+ yrsprocess improvement · 3+ yrs
Nice to have (2)
compliance frameworksintrusion detection systems

We read this from the posting text with AI. Skim the description below before ruling yourself out.

Why we read it this way (7)

The role is primarily a security compliance/assurance analyst position — writing and documenting security controls, working with audit frameworks, and communicating with auditors and stakeholders — making 15-1212 (Information Security Analysts) the best fit, though 15-1211 (Computer Systems Analysts) is a plausible runner-up given the heavy business-process and compliance-framework orientation.

The posting lists multiple office locations (Arlington VA, Herndon VA, Seattle WA, New York NY); compensation is quoted for the Herndon, VA location. The role is not listed as remote.

The title carries no seniority level; the minimum requirements (3+ years, bachelor's degree) support a Mid-level classification despite the broad scope described in the narrative.

'Process improvement with automation and analysis' is listed as a Basic Qualification with 3+ years required, but names no specific technology or tool — it is captured as a general skill rather than a named technology.

Intrusion detection systems and risk management appear only under Preferred Qualifications and are marked accordingly.

The degree requirement is a hard gate: 'Bachelor's degree in Computer Science, Information Systems, Finance, Accounting, or a related field' with no 'or equivalent experience' language.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): risk management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗