Supply Chain Information Security Assessor, Supply Chain Intellectual Property Security
Amazon
- Location
- CN, 44, Shenzhen
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 19h ago
Skills
About this role
Overview
We're seeking a Supply Chain Information Security Assessor to protect the lifecycle of standards, procedures, and logical assets across Amazon's supplier network in APAC. This role requires international travel (up to 75%) across the APAC region. The Supply Chain information Security Assessor plays a critical role in mapping how sensitive content moves from Amazon through contract manufacturers (CMs) and downstream to sub-suppliers, assessing controls at each stage, and driving remediation through influence rather than direct authority. This position involves conducting on-site evaluations of Document Control Centers, verifying transmission and destruction processes, tracking logical asset governance (Standards and procedures, software licenses, firmware, digital keys), and identifying where Amazon's security obligations terminate in the contractual chain. The ideal candidate will have technical expertise in data transmission security and document lifecycle management, a strong understanding of manufacturing and supplier ecosystems, and the ability to build trust-based relationships that drive security outcomes across multi-tiered supply chains without direct reporting authority. Fluency in both Mandarin (Chinese) and English is required. Key job responsibilities SOP & Document Lifecycle Assessment • Map end-to-end document workflows at CM facilities: receipt, storage in Document Control Centers (DCC), distribution to the factory floor, and destruction. • Assess transmission methods and storage controls for data-in-transit and data-at-rest risks. • Verify destruction processes (physical and digital) meet corporate standards with auditable logs. Downstream Information Flow & Contractual Navigation • Map how Amazon IP flows from CMs to sub-suppliers (component makers, PCB houses, tooling vendors), documenting content type, delivery method, and retention at each node. • Identify where Amazon's security requirements terminate in the contractual chain and flag gaps where sensitive content reaches suppliers with no direct obligation to Amazon. • Coordinate with Legal, Operations, and supply chain stakeholders to recommend remediation paths. Logical Asset Governance • Track and inventory logical assets (software licenses, firmware, digital keys, credentials) provided to suppliers; verify return, revocation, or secure destruction when no longer needed. Influence, Reporting & Continuous Improvement • Drive security outcomes across CM organizations and sub-supplier tiers through trust-based relationships, without direct reporting authority. • Document findings, develop risk ratings, and track remediation closure through follow-up assessments. • Contribute to standardized assessment frameworks and automation tools for document lifecycle security.