Program Security Officer, Amazon Leo for Government (ALG)
Amazon
- Location
- US, VA, Arlington
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 19h ago
About this role
The Amazon Leo for Government (ALG) Industrial Security team designs, builds, and implements security assurance and compliance programs in line with formal National Industrial Security Program (NISP) requirements and U.S. Government directives (DoD, IC). We are seeking a Security Industry Specialist II to join a team of industry-leading security professionals who leverage deep expertise in government security compliance regimes to deliver assurance about the design and operational effectiveness of security controls across Amazon's classified operations. In this role, you will apply your knowledge of NISPOM (32 CFR Part 117), ICD 705, and related government directives to execute security compliance processes, deliver security assurance products, and engage directly with government security officials to validate that Amazon's security posture meets their expectations. This position requires that the candidate selected be a US Citizen and must currently possess and maintain an active TS/SCI security clearance. Key job responsibilities Security Assurance & Compliance Program Execution • Leverage specific expertise with the NISPOM and related government security compliance frameworks to make sound decisions on delivering assurance about Amazon's security and control environment at accredited facilities. • Design and execute security compliance processes across personnel security (PERSEC), physical security (PHYSEC), and industrial security disciplines, including identifying internal enhancements based on compliance expectations and designing continuous monitoring for security controls. • Leverage existing mechanisms (evidence repositories, templates, engagement runbooks, Standard Operating Procedures) to deliver security assurance and fulfill government compliance requirements. • Prepare for and support DCSA security reviews, assessments, and vulnerability assessments; scope and negotiate engagement parameters with government assessors. Security Design & Accreditation • Implement security design and accreditation requirements for SCIFs and secure areas in accordance with ICD 705 and applicable construction/accreditation standards. • Conduct physical security vulnerability assessments, self-inspections, and remediation tracking to maintain compliance posture. • Administer access control, alarm/IDS, and CCTV programs for accredited and controlled spaces; maintain GSA-approved containers, combinations, keys, and end-of-day security checks (SF-701/SF-702). Governance, Risk & Compliance Operations • Administer the clearance lifecycle (initiations, reinvestigations, eligibility, and access determinations) in DISS/NBIS; process adverse information reports, SEAD 3 self-reporting submissions, and continuous evaluation/vetting alerts. • Conduct security in-processing/out-processing, indoctrinations, and debriefings (SF-312 execution); manage visit authorization requests (VARs) and program access rosters; enforce need-to-know. • Lead preliminary inquiries and investigations of security incidents, violations, and classified disclosures; draft incident reports, damage assessments, and corrective actions. • Safeguard classified and Controlled Unclassified Information (CUI) per NISPOM and DoD Manual 5200.01; handle, mark, transmit, and destroy classified material. • Support Facility Clearance (FCL) sponsorship, maintenance, and DD-254 flow-down management. Cross-Team Influence & Process Improvement • Work across teams within the ALG Security organization to influence goals, priorities, and trade-offs (e.g., recommending how to prioritize compliance requirements that could impact security operations). • Optimize cross-functional processes that improve projects and goals pertaining to security compliance risks, controls, and evidence. • Convey detailed technical and industry knowledge (verbally, in writing, and via diagram) to engineering, program management, and business teams — including control language,