yoinka

Principal Security Industry Specialist, AWS Security & Risk Compliance, AWS Security Risk and Compliance

Amazon

US, WA, SeattleFull TimePrincipal
Sign in to applyVerified 1h ago
Location
US, WA, Seattle
Employment
Full Time
Work model
On-Site
Level
Principal
Posted
10h ago

Skills

AWS

About this role

At Amazon Web Services (AWS), Security is our highest priority. The AWS Security Risk and Compliance (SRC) team is seeking a Principal Security Industry Specialist to serve as the compliance bridge between AWS AI service teams and the security compliance organization. This is an individual contributor role responsible for ensuring AWS AI products and services are designed, launched, and operated in compliance with security frameworks, regulatory requirements, and internal governance standards across all regulated industry segments and geographies. You will work directly with AI service teams, and downstream AWS services leveraging AI models, to advise on compliance requirements, surface regulatory risks introduced by new capabilities, and drive alignment with compliance programs before General Availability. Operating at the intersection of AI governance, risk management, and security compliance, you will translate complex and evolving regulatory requirements (EU AI Act, DORA, NIS2, FedRAMP) and compliance standards (ISO 42001) into actionable guidance that service teams can implement at the pace of innovation. This is a high-visibility, high-impact role requiring an individual contributor who can think big, influence across organizational boundaries, and ensure AWS's AI services meet the compliance expectations of our most highly regulated customers. Key job responsibilities ● Serve as the primary compliance engagement point for AWS AI service teams, advising on regulatory requirements, compliance posture, and risk implications across the service lifecycle (design, build, launch, operate). ● Partner with compliance assessment and assurance teams to ensure AI services approaching General Availability are evaluated against the AI Service Compliance Framework (AISCF) and existing security compliance regimes (SOC 2, ISO 27001, FedRAMP, PCI-DSS), providing subject matter expertise and service team context to inform assessment outcomes. ● Work with service teams to identify compliance risks introduced by AI model onboarding, cross-region inference, trust and safety data retention, and model governance requirements; driving service teams toward compliant design decisions. ● Develop and maintain compliance guidance, decision frameworks, and adoption criteria that enable service teams to self-assess and design for compliance at the architecture phase, reducing manual review cycles and accelerating compliant launches. ● Collaborate with the AI Governance lead and Risk program owner to ensure service-level compliance findings and emerging regulatory trends inform enterprise risk posture and governance strategy. ● Partner with TPMs building compliance assessment tooling and automation (e.g., AI-powered assessment agents, compliance registries, zero-touch compliance workflows), providing compliance domain expertise and requirements to shape scalable solutions. ● Work with obligations monitoring teams to ensure new and evolving AI regulatory requirements are translated into service team guidance and compliance framework updates. ● Partner with Assurance, as required, to engage with highly regulated customers and external stakeholders (regulators, auditors, industry groups) to validate that AWS AI service compliance posture meets their security assurance expectations. ● Monitor regulatory trends across multiple jurisdictions and leadership on implications for AI service design and operation. ● Influence leadership through data-driven narratives, compliance risk briefings, and white papers that drive resource allocation and strategic decision-making on AI compliance matters. A day in the life In this role, you'll spend your day advising AWS AI service teams on compliance requirements as they design and launch new capabilities, translating complex regulatory obligations into practical guidance that engineers can act on. You'll partner with assessment teams to provide service context that informs their evaluations,

Principal Security Industry Specialist, AWS Security & Risk Compliance, AWS Security Risk and Compliance at Amazon — US, WA, Seattle | Yoinka