Risk Mgr, Compliance 2LOD, Global Operations Enterprise Services
Amazon
- Location
- GB, London
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 36d ago
About this role
Amazon's Global Operations Enterprise Services (GOES) Compliance & Data Integrity (CDI) vertical is seeking a talented and motivated Risk Manager to support the Compliance Second Line of Defense (2LOD) function. CDI's 2LOD exists to provide continuous, independent verification that compliance standards are being met accurately, completely, and consistently across CDI's full infrastructure portfolio, operating between Internal Audit cycles to ensure the organization maintains a live, defensible compliance posture rather than a point-in-time snapshot. This role owns the lifecycle of complex cross-functional compliance assurance programs, translating audit findings and continuous monitoring results into sustainable compliance improvements across 200+ jurisdictions and 4K+ facilities. This is an individual contributor role on a globally dispersed team. A successful candidate will be a self-directed senior IC who thrives in ambiguity, taking unfamiliar problems, defining the right approach and delivering the outcome without a prescribed playbook. They have demonstrated experience managing complex compliance or audit programs with limited guidance, partnering with legal and regulatory stakeholders, and influencing business and technology decisions across organizational boundaries. The candidate must be able to define program objectives, drive measurable risk reduction, and represent compliance programs credibly to senior internal and external audiences. Key job responsibilities Program Ownership & Execution • Own the lifecycle of one or more complex compliance assurance programs, from scoping and continuous monitoring design through finding remediation and closure, ensuring alignment with CDI's compliance strategy and the organization's portfolio-wide assurance posture • Manage parallel workstreams across geographies, identifying and resolving cross-stream dependencies before they become blockers • Define program objectives, establish KPIs, and drive measurable improvements in compliance health, control effectiveness, and find remediation timeliness across the portfolio • Manage assurance activities and audit fieldwork support across assigned program areas, ensuring timely, accurate, and auditable responses to both Internal Audit and independent monitoring requirements • Streamline and eliminate excess processes and controls in assurance workflows, creating predictable, scalable verification paths that improve portfolio-wide coverage • Oversee the rollout of controls and testing mechanisms, measuring their effectiveness and ensuring findings are treated as system improvement inputs rather than one-time corrections • Drive toward automated assurance execution within your program scope, identifying opportunities to reduce reliance on manual workflows and fragmented documentation standards Risk Assessment & Decision Support • Assess complex risks surfaced through assurance findings and translate them into actionable remediation plans with clear ownership, timelines, and success metrics that feed back into compliance execution priorities • Use lateral thinking to navigate problems where obvious path is blocked, surfacing alternative approaches the team has not considered • Provide long-term perspective on risk-related business and technology decisions, helping partner teams prioritize remediation efforts against operational demands • Balance operational continuity against compliance requirements when developing control recommendations, ensuring the portfolio maintains continuous coverage rather than episodic readiness • Use data to recommend risk tolerance levels, exercising judgment on which decisions to escalate to the function lead (high-stakes, cross-team, one-way doors) and which to make independently, while flagging gaps in risk assessment methodology Cross-Functional Partnership • Partner with CDI functions to ensure assurance submissions reflect accurate, auditable evidence of control execution at