2,309 Security Risk jobs in the United States

Sr. Security Risk Specialist, Stores Security, Risk, & Compliance

98194 Seattle, Washington Amazon

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Description
Amazon Security is seeking a Senior Security Risk Specialist with a strong delivery record and proven risk management experience to join our Security, Risk, & Compliance (SRC) Risk team. Our team empowers stakeholders to grow securely by enabling leaders to understand and manage their risks and the impact of their decisions. We go beyond traditional methods of risk management, providing teams with insightful data and novel tools to make informed decisions that unlock opportunities and drive innovation.
This role will support security excellence initiatives within SRC, analyzing operations, identifying opportunities, assessing risk, and managing the execution of projects.
The successful candidate will be a hands-on security expert who thrives in the face of ambiguity, and has a proven track record of delivering high-impact goals. In this role, they will establish and lead ongoing projects focused on security risk management.
The ideal candidate is technically experienced and innovative security, risk, and compliance who has the ability to understand systems, security, and privacy processes, communicate to customers, and to be able to drive innovative process changes through multiple organizations and teams. You have experience with NIST Risk Management Framework (NIST 800-30).
If you enjoy working at scale in a rapidly changing environment and influencing the protection of customers' data within a large global organization, this position will provide you with a challenging opportunity.
Key job responsibilities
- Analyze business, product and security data, uncover evolving threats, identify weaknesses and opportunities in risk defense
- Apply a working knowledge of information security and privacy regulation to articulate customer and control impact and drive alignment to controls.
- Quantify risk control effects and trends, collaborate with engineering, operational and product teams, contribute to risk measurement, mitigation and prevention.
- Establish regular reporting mechanisms for measuring compliance and performance;
- Develops metrics that demonstrate the current risk state, indicators of progress, and business alignment
- Support Continuous Monitoring initiatives to drive enforcement, oversight and improvement of security controls implementation through automation
- Partner with tech and security teams and to review and challenge identified risks, remediation plans, progress and status, and drive action as needed
- Monitor and oversee performance against Key Risk Indicators, including "Path to Green" plans
- Drive the successful achievement of business goals, including timely identification, escalation and remediation of risks and issues that impact program execution and delivery.
About the team
The Security, Risk, & Compliance (SRC) Risk team is a group of highly-skilled technical and non-technical program managers and specialists who work at the intersection of Amazon's most critical security operations. Our team partners with incident response and vulnerability management to provide actionable insights, drive risk mitigation, and ensure the secure growth of Amazon's business. Given this strategic positioning, no two days are exactly the same, but our mission of empowering leaders to understand and manage risk, while supporting the continuous operational development of these high-impact teams, remains constant. Through our work, we ensure that Amazon's data and operations are safeguarded against evolving threats, enabling the company to grow securely.
Basic Qualifications
- 7+ years' experience implementing risk management frameworks and assessing security risks of devices, services, and applications with an expertise in conducting risk assessments
- Strong data-driven analytical skills, with experience in establishing and tracking program metrics
- Experience effectively articulating recommendations/conclusions both verbally and in written form
Preferred Qualifications
- Knowledge of cloud-based models (IaaS, PaaS, SaaS) and technologies used to implement controls within these environments
- Ability to communicate and manage information security concepts and requirements to personnel of varying technical backgrounds and positions
- Functional experience across two or more information and cyber security domains (e.g., application security, identity and access management, vulnerability management, Continuous Monitoring)
- Experience with secure development
- Proficient in data analysis and visualization
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $107,400/year in our lowest geographic market up to $229,700/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.
View Now

Sr. Security Risk Specialist, Stores Security, Risk, & Compliance

98194 Seattle, Washington Amazon

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Description
Amazon Security is seeking a Senior Security Risk Specialist with a strong delivery record and proven risk management experience to join our Security, Risk, & Compliance (SRC) Risk team. Our team empowers stakeholders to grow securely by enabling leaders to understand and manage their risks and the impact of their decisions. We go beyond traditional methods of risk management, providing teams with insightful data and novel tools to make informed decisions that unlock opportunities and drive innovation.
This role will support security excellence initiatives within SRC, analyzing operations, identifying opportunities, assessing risk, and managing the execution of projects.
The successful candidate will be a hands-on security expert who thrives in the face of ambiguity, and has a proven track record of delivering high-impact goals. In this role, they will establish and lead ongoing projects focused on security risk management.
The ideal candidate is technically experienced and innovative security, risk, and compliance who has the ability to understand systems, security, and privacy processes, communicate to customers, and to be able to drive innovative process changes through multiple organizations and teams. You have experience with NIST Risk Management Framework (NIST 800-30).
In this role, you'll help support our mission: empowering leaders with the insights they need to manage risks and drive innovation securely. You will have the opportunity to challenge traditional risk management methods, pushing the boundaries to make data-driven decisions that have a real impact on our organization and our customers.
If you enjoy working at scale in a rapidly changing environment and influencing the protection of customers' data within a large global organization, this position will provide you with a challenging opportunity.
Key job responsibilities
- Analyze business, product and security data, uncover evolving threats, identify weaknesses and opportunities in risk defense
- Apply a working knowledge of information security and privacy regulation to articulate customer and control impact and drive alignment to controls.
- Quantify risk control effects and trends, collaborate with engineering, operational and product teams, contribute to risk measurement, mitigation and prevention.
- Establish regular reporting mechanisms for measuring compliance and performance;
- Develops metrics that demonstrate the current risk state, indicators of progress, and business alignment
- Support Continuous Monitoring initiatives to drive enforcement, oversight and improvement of security controls implementation through automation
- Partner with tech and security teams and to review and challenge identified risks, remediation plans, progress and status, and drive action as needed
- Monitor and oversee performance against Key Risk Indicators, including "Path to Green" plans
- Drive the successful achievement of business goals, including timely identification, escalation and remediation of risks and issues that impact program execution and delivery.
About the team
The Security, Risk, & Compliance (SRC) Risk team is a group of highly-skilled technical and non-technical program managers and specialists who work at the intersection of Amazon's most critical security operations. Our team partners with incident response and vulnerability management to provide actionable insights, drive risk mitigation, and ensure the secure growth of Amazon's business. Given this strategic positioning, no two days are exactly the same, but our mission of empowering leaders to understand and manage risk, while supporting the continuous operational development of these high-impact teams, remains constant. Through our work, we ensure that Amazon's data and operations are safeguarded against evolving threats, enabling the company to grow securely.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.
Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.
Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Basic Qualifications
- 7+ years' experience implementing risk management frameworks and assessing security risks of devices, services, and applications with an expertise in conducting risk assessments
- Strong data-driven analytical skills, with experience in establishing and tracking program metrics
- Experience effectively articulating recommendations/conclusions both verbally and in written form
Preferred Qualifications
- Knowledge of cloud-based models (IaaS, PaaS, SaaS) and technologies used to implement controls within these environments
- Ability to communicate and manage information security concepts and requirements to personnel of varying technical backgrounds and positions
- Functional experience across two or more information and cyber security domains (e.g., application security, identity and access management, vulnerability management, Continuous Monitoring)
- Experience with secure development
- Proficient in data analysis and visualization
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $107,400/year in our lowest geographic market up to $229,700/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.
View Now

Security Risk and Compliance Analyst

75215 Park Cities, Texas ISN Software

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

Our Company: ISN was established in 2001 and is a global leader in contractor and supplier management. We work closely with a variety of household-name clients in the US, Canada, Europe, Australia, Latin America, and the Middle East to connect them with safe and reliable contractors and suppliers and incorporate a level of due diligence in the contractor management process.

The Position: The Security Risk and Compliance Analyst position will be responsible for providing technical and business assistance for a wide variety of information security risk and compliance related matters. The Security Risk and Compliance Analyst will assist in completing client and prospect security questionnaires, assessing risk in new software and vendor requests, and participating in risk and compliance audits.

Who should apply?
  • Bachelor's Degree in Cyber Security, Risk and Compliance, or equivalent/related field or equivalent years of experience
  • 4+ years professional experience in Security, Risk and compliance
  • Strong experience in Microsoft Purview - Data Loss Prevention (DLP) configurations, alerts, remediation, reporting etc
  • Experience writing, reviewing and maintaining security policies, standards and procedures
  • Ability to perform risk assessments, support and participate in the audits - ISO 9001 and ISO 27001
Primary Duties & Responsibilities:
  • Assist in completing and reviewing security questionnaires, requests for proposal (RFP), requests for information (RFI), and vendor evaluations as needed
  • Perform security evaluations of new software products across the business and provide risk feedback to requesting ISN team members
  • Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
  • Respond to cyber security alerts including DLP alerts, attempting remediation, and escalation as required
  • Assist in documenting and escalating incidents (including event history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment
Job Location: 3232 McKinney Ave Ste 1500, Dallas, TX 75204.
  • Employees must be within a commutable distance to the Dallas, TX office. Relocation is required for candidates not already local to the DFW area.
  • Required to come to the office at least 2 times per week during the first 90 days.
  • After 90 days, your role on the Products team will have the option to work remotely with at least 1 in-person engagement required monthly.
ISN Benefits*
  • 100% company-paid monthly insurance premiums for employees and dependents
    • Medical, Dental, Vision, and Life Insurance
  • Employee assistance program
  • 4% retirement matching
  • Long-Term & Short-Term Disability Coverage
  • Paid time off
    • 0-1 year - 15 day (pro-rated first year)
    • 1-5 years - 20 days
    • 5-10 years - 25 days
    • 10+ years - 30 days
  • Holidays - 13 paid holidays
  • Monthly cell phone reimbursement
  • Complimentary parking space or monthly reimbursement for DART public transportation
  • Team-building activities and events, including quarterly kick-off meetings and community volunteer day
  • Matching charitable gift program
  • Professional development & training opportunities
  • Wellness Program: Focuses on community, financial, mental, nutrition, physical and social health
  • Business casual, jeans allowed

*All benefits are subject to change with notice to the employee

All job offers will be contingent on successful completion of a drug screen and background check.

ISN is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

ISN does not provide work visa sponsorship for this position (such as H-1B visa sponsorship in the United States). Applicants for employment must possess work authorization/right to work without the need for sponsorship by the employer now or in the future.
View Now

Security Risk and Compliance Specialist

30383 Atlanta, Georgia Fisher & Phillips

Posted 9 days ago

Job Viewed

Tap Again To Close

Job Description

Join to apply for the Security Risk and Compliance Specialist role at Fisher Phillips

Join to apply for the Security Risk and Compliance Specialist role at Fisher Phillips

(Atlanta, Full-time Hybrid)

Fisher Phillips, a premier international labor and employment law firm, is seeking a skilled and experienced Security Risk and Compliance Specialist to join our team. In this essential role, you will contribute to the seamless operation of our services, providing crucial support to our department in delivering exceptional client service and maintaining our commitment to excellence.

The Security Risk and Compliance Specialist supports the Director of Information Security in managing security-related contractual obligations and compliance requirements. This role ensures organizational compliance with internal policies and is responsible for reviewing contractual commitments and actual controls, assisting with remediation planning, and contributing to security awareness materials. The ideal candidate is an analytical, detail-oriented professional who thrives in a fast-paced environment and is adept at managing risk while enabling business operations. This role is essential to ensuring, compliance requirements are met, and security risks are identified and mitigated in a timely manner.

Key Responsibilities

Contract & Agreement Review:

  • Review client and vendor agreements for security and compliance requirements
  • Analyze security-related terms to ensure commitments align with firm policies, procedures, and technical capabilities
  • Identify and document gaps between contractual requirements and current security controls
  • Collaborate with the Director of Information Security to prioritize and escalate identified gaps
  • Assist with drafting and negotiating security terms in new contracts

Compliance & Risk Management

  • Support security risk assessments for vendor engagements and client obligations.
  • Maintain documentation of security requirements, gaps, and mitigation plans.
  • Lead or assist with compliance audits (e.g., SOC 2, HIPAA, GDPR, CCPA, PCI-DSS, ISO 27001) by gathering evidence and managing documentation.
  • Maintain and update compliance documentation, including policies, standards, and procedures.
  • Coordinate responses to client security questionnaires and due diligence requests.
  • Work with Information Governance, Legal, and IT teams to maintain privacy and contractual requirements

Security Awareness & Training

  • Support the development and delivery of security training and phishing simulation programs
  • Create internal communications and awareness campaigns to foster a security-conscious culture
  • Help ensure training content aligns with client, vendor, and regulatory security requirements
  • Assist the Director of Information Security in planning and tracking awareness initiatives

Policy Management & Documentation

  • Draft, review, and maintain information security policies, standards, procedures, and guidelines
  • Ensure policies align with contractual obligations, business goals, risk appetite, and current threat landscape
  • Collaborate with legal and HR teams to enforce and communicate policy changes

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience
  • Minimum 3 years of experience in information security, IT compliance, or cybersecurity risk management
  • Experience reviewing client or vendor contracts for security and compliance requirements
  • Familiarity with security frameworks such as NIST CSF, ISO/IEC 27001, CIS Controls, and COBIT
  • Knowledge of regulatory requirements: HIPAA, SOC 2, GDPR, PCI-DSS, SOX, or FedRAMP
  • Excellent analytical, investigative, and problem-solving skills
  • Exceptional communication skills (written and verbal), with the ability to work crossfunctionally and present to leadership
  • Ability to explain security concepts clearly in writing for training and awareness purposes
  • Strong organizational skills with the ability to manage multiple tasks and deadlines

Preferred Qualifications

  • Professional certifications such as CISSP, CISA, CISM, CRISC, Security+, or ISO 27001 Lead Auditor/Implementer
  • Familiarity with cloud platforms (AWS, Azure, GCP) and their security tools and shared responsibility models
  • Experience with governance, risk, and compliance (GRC) tools (e.g., Archer, OneTrust, LogicGate)
  • Experience with SIEM tools, EDR, and vulnerability management platforms (e.g.,SumoLogic, CrowdStrike, Tenable)

Why Join Us

At Fisher Phillips, we recognize that exceptional talent is the foundation of our success, enabling

us to deliver outstanding service to both our internal and external clients. Joining our team

means collaborating in a professional yet dynamic environment that leverages cutting-edge

technology. Our leadership is committed to fostering your professional growth and providing

opportunities to challenge yourself in meaningful ways.

We believe in rewarding talent with more than just a competitive salary. Our comprehensive

benefits package includes health, dental, and vision insurance, a 401(k) with profit sharing,

generous paid time off, and holidays.

Your well-being is our priority. We offer 24/7 telehealth services, a variety of wellness

programs, and additional optional benefits designed to support your unique lifestyle. At Fisher

Phillips, youll find a workplace that values your health, happiness, and continued professional

development. To learn more about our firm, visit us at

Equal Opportunity Employer

Fisher Phillips is committed to providing equal employment opportunities to all employees and

applicants, regardless of race, ethnicity, religion, sex (including related medical conditions),

gender, sexual orientation, national origin, citizenship status, veteran status, marital status,

pregnancy, age, disability, or any other protected status, in compliance with all applicable laws.

The statements in this position description are not necessarily all-inclusive. Additional duties and

responsibilities may be assigned, and requirements may vary from time to time.

Relocation costs are not covered. We are only accepting direct applicants; thirdparty

recruiters or agencies will not be considered. No phone inquiries, please. Seniority level
  • Seniority level Mid-Senior level
Employment type
  • Employment type Full-time
Job function
  • Job function Strategy/Planning and Information Technology
  • Industries Law Practice

Referrals increase your chances of interviewing at Fisher Phillips by 2x

Sign in to set job alerts for Security Professional roles. Security Officers - Full Time & Part Time - All Shifts - $17.68/hr. Security Officer - Mercedes-Benz Stadium Overnight Security Officer - Waldorf Astoria Atlanta Buckhead SECURITY OFFICER | SECURITY | PART TIME (46394) Branch Security Officer - Atlanta Phipps Security Guard (Unarmed) - 3pm - 11pm Shift Friday and Saturday Security Officer - Dekalb - Full-Time & PT Wk Ends $6/hr Security Officers - Temporary - Full Time & Part Time - 1st and 2nd Shift only! - 20.00/hr.

Were unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr
View Now

Security Risk Analyst:

95053 Santa Clara, California Akraya

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Posting

Primary Skills: Risk Assessment-Expert, NIST-Advanced, ISO 27001-Advanced, Vendor Management-Intermediate, Audit Support-Intermediate

Contract Type: W2

Duration: 05-06 Months

Location: Santa Clara

Pay Range: $70 - $75 per hour

This role may require travel to business meetings and events and requires reliable transportation to do so.

View Now

Security Risk Analyst

92189 San Diego Country Estates, California PlayStation Global

Posted today

Job Viewed

Tap Again To Close

Job Description

Why PlayStation?

PlayStation isn't just the Best Place to Play - it's also the Best Place to Work. Today, we're recognized as a global leader in entertainment producing The PlayStation family of products and services including PlayStation®5, PlayStation®4, PlayStation®VR, PlayStation®Plus, acclaimed PlayStation software titles from PlayStation Studios, and more.

PlayStation also strives to create an inclusive environment that empowers employees and embraces diversity. We welcome and encourage everyone who has a passion and curiosity for innovation, technology, and play to explore our open positions and join our growing global team.

The PlayStation brand falls under Sony Interactive Entertainment, a wholly-owned subsidiary of Sony Group Corporation.

PlayStation is looking for an Information Security Analyst to join our team and operate the day-to-day Information Security, Risk and Compliance management processes. This is a mixture of processing requests from the business and driving internal security projects such as security audit and assessment. This role requires a sound understanding of technical and engineering terminology, outstanding ability to articulate risk across any security domains (technical and governance) with the demonstrable ability to work independently and process high volumes of security requests on a weekly basis. This role also provides ample opportunity to work across technical and game-related projects with studio and PlayStation engineering teams and therefore requires risk advisory and influencing experience.

Based in San Diego, the candidate will be the key business relationship partner on behalf of Information Security and work on Information Security processes as well as strategic projects across PlayStation and the Studios group. This role will collaborate closely directly with business, technical and third party collaborators, as well as work multi-functionally with our other Information Security specialist teams across the globe to protect PlayStation's intellectual property, data and infrastructure whilst delivering new and evolving games, services and hardware to the market. This is an opportunity to provide security directly to the global PlayStation business, our PlayStation Network and global Studios and their game development.
What you'll be doing:
  • Review, triage, risk assess and process security requests from technical, engineering and business partners that require security input and approvals.
  • Work independently to understand collaborator requirements and the security risk involved. Use security policy, process and information security expertise to advise collaborators on appropriate solutions that do not open PlayStation up to security risks.
  • Review security requirements associated with third party engagement requests and determine what level of third party assurance is required.
  • Initiate and support the third-party due diligence and assurance assessment processes and able to articulate and advise on associated risks to the business, contractual requirements and resulting recommendations.
  • Articulate and communicate risk to relevant collaborators, whilst with technical teams, partners, and leadership teams to translate security risk into mitigation plans into action items.
  • Negotiates, tracks and reports these remediation efforts within the PlayStation risk programme.
  • Coordinates all aspects of information security and provides consulting services to business units and other partners.
  • Works with business partners from across Playstation and Studios to identify and implement information security requirements related to projects and engagements.
  • Monitors and reviews IT security controls to identify operational efficiency.
  • Performing security audits related to critical systems and prioritized business scopes.
  • Triage information security incidents, working with our 24/7 SOC teams, business partners and related third parties, as well as be responsible for reporting and raising where necessary.
  • Works with GRC and other security tools to collect and maintain security and risk information.
  • Maintains broad knowledge of industry trends in the field of information security and other technologies relevant to systems handled by the operations teams.
  • Advances the InfoSec program via partnerships with shared services teams within information security.
What we're looking for:
  • At least four years of related work experience within Information Security risk management or security audit, with a sound technical understanding of information technology, network or infrastructure management.
  • Must be a self-starter, comfortable with processing security requests independently initiating discussion with collaborators to drill down on exact requirements and how it aligns to process and policy.
  • Experience in business partner/collaborator management, across technical and non-technical partners.
  • Used to working within critical metrics and SLAs to ensure efficient responses and smooth ticket management.
  • Experience in Jira, Confluence and GRC tracking and assessment tools.
  • Can independently perform information Security due diligence and audits, identifying gaps and require mitigations.
  • Proven technical background in Information Security including work related to cloud infrastructure, SaaS applications, emerging technology.
  • Ability to understand technical terminology to understand and assess security environment.
  • Experience with third party due diligence and contract reviews.
  • Excellent communicator, able to translate both technical and business requirements and terminology to the applicable audience.
Desirable Knowledge and Skills:
  • Familiarity with AWS (or similar) cloud security and infrastructure.
  • Knowledge of and experience with SaaS and web infrastructure security
  • Awareness of security risks associated with AI and other emerging technologies
  • Microsoft Windows and Apple Mac OS hardening
  • Policy administration
  • Security standards such as SOX, ISO 27001, NIST, PCI
  • Ability to handle parallel tasks and accurately detail resolutions
  • Bachelor's degree in Computer Science, Information Security, or related field or equivalent experience


#LI-GM1

Please refer to our Candidate Privacy Notice for more information about how we process your personal information, and your data protection rights.

At SIE, we consider several factors when setting each role's base pay range, including the competitive benchmarking data for the market and geographic location.

Please note that the base pay range may vary in line with our hybrid working policy and individual base pay will be determined based on job-related factors which may include knowledge, skills, experience, and location.

In addition, this role is eligible for SIE's top-tier benefits package that includes medical, dental, vision, matching 401(k), paid time off, wellness program and coveted employee discounts for Sony products. This role also may be eligible for a bonus package. Click here to learn more.

The estimated base pay range for this role is listed below.

$140,000-$210,000 USD

Equal Opportunity Statement:

Sony is an Equal Opportunity Employer. All persons will receive consideration for employment without regard to gender (including gender identity, gender expression and gender reassignment), race (including colour, nationality, ethnic or national origin), religion or belief, marital or civil partnership status, disability, age, sexual orientation, pregnancy, maternity or parental status, trade union membership or membership in any other legally protected category.

We strive to create an inclusive environment, empower employees and embrace diversity. We encourage everyone to respond.

PlayStation is a Fair Chance employer and qualified applicants with arrest and conviction records will be considered for employment.
View Now

Security Risk Analyst

94199 San Francisco, California Anthropic

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

About Anthropic

Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

As part of Anthropic's Compliance Team, you'll help build and scale our risk management function. This unique role requires taking well established risk frameworks and adapting them to manage security and compliance risks in the rapidly evolving AI landscape.You'll be a key contributor in shaping how the organization evaluates and mitigates risks that evolve from industry leading research, products, and public policy. As our Risk Analyst reporting to the Head of Compliance, you'll be responsible for bringing clarity to complex risk scenarios, developing innovative assessment methodologies, and ensuring our risk management approach scales with our ambitious mission to ensure transformative AI helps people and society flourish.

Responsibilities:
  • Triage and evaluate submitted risks through comprehensive assessment of inherent and residual risk scores, aligning with company policies, objectives, and our current control environment
  • Drive collaborative engagement with stakeholders across the organization to develop effective risk treatment plans and establish robust mitigating controls
  • Contribute to and maintain our Controls Portfolio by documenting mitigating controls and ensuring accurate mapping to relevant compliance frameworks
  • Partner with the Risk Management Lead to analyze and report on key risk metrics and trends, providing actionable insights for executive decision-making and strategic planning
  • Shape the evolution of our risk management program, helping build and refine processes that scale with our growing organization
  • Ensure the effectiveness of risk management controls through rigorous monitoring and documentation support for both internal and external audits
You may be a good fit if you:
  • Have 5-10 years of experience in governance, risk, and/or compliance roles, with a track record of adapting frameworks to evolving business needs
  • Have navigated compliance challenges within high-growth organizations, particularly in heavily regulated environments
  • Possess deep understanding of information security risks, controls, and threat models, with the ability to apply this knowledge to emerging technology challenges
  • Bring hands-on experience with security frameworks such as SOC2, ISO 27001, FedRAMP, and HIPAA
  • Excel at quantitative risk analysis and can adapt frameworks to novel use cases
  • Can effectively translate complex security risks for diverse stakeholders, bridging technical details with business context to foster a risk-aware culture
Strong candidates may also have experience with:
  • Hands-on experience with GRC platforms, project management tools, and service management systems, with a focus on scaling and automating risk processes
  • Bring experience building or significantly improving risk management programs within high-growth technology organizations, particularly those dealing with emerging technologies
  • Hold relevant certifications such as CRISC, ISC2 Risk Management, ISO 31000, or other information security risk credentials that demonstrate commitment to the craft

Deadline to apply: None. Applications will be reviewed on a rolling basis.

The expected salary range for this position is:

Annual Salary:

$255,000-$345,000 USD

Logistics

Education requirements: We require at least a Bachelor's degree in a related field or equivalent experience.Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
How we're different

We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact - advancing our long-term goals of steerable, trustworthy AI - rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.

The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
Come work with us!

Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues.
View Now
Be The First To Know

About the latest Security risk Jobs in United States !

Security Risk Analyst

92189 San Diego Country Estates, California Sony Interactive Entertainment

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Why PlayStation? PlayStation isn’t just the Best Place to Play — it’s also the Best Place to Work. Today, we’re recognized as a global leader in entertainment producing The PlayStation family of products and services including PlayStation5, PlayStation4, PlayStationVR, PlayStationPlus, acclaimed PlayStation software titles from PlayStation Studios, and more. PlayStation also strives to create an inclusive environment that empowers employees and embraces diversity. We welcome and encourage everyone who has a passion and curiosity for innovation, technology, and play to explore our open positions and join our growing global team. The PlayStation brand falls under Sony Interactive Entertainment, a wholly-owned subsidiary of Sony Group Corporation. PlayStation is looking for an Information Security Analyst to join our team and operate the day-to-day Information Security, Risk and Compliance management processes. This is a mixture of processing requests from the business and driving internal security projects such as security audit and assessment. This role requires a sound understanding of technical and engineering terminology, outstanding ability to articulate risk across any security domains (technical and governance) with the demonstrable ability to work independently and process high volumes of security requests on a weekly basis. This role also provides ample opportunity to work across technical and game-related projects with studio and PlayStation engineering teams and therefore requires risk advisory and influencing experience. Based in San Diego, the candidate will be the key business relationship partner on behalf of Information Security and work on Information Security processes as well as strategic projects across PlayStation and the Studios group. This role will collaborate closely directly with business, technical and third party collaborators, as well as work multi-functionally with our other Information Security specialist teams across the globe to protect PlayStation’s intellectual property, data and infrastructure whilst delivering new and evolving games, services and hardware to the market. This is an opportunity to provide security directly to the global PlayStation business, our PlayStation Network and global Studios and their game development. What you’ll be doing: Review, triage, risk assess and process security requests from technical, engineering and business partners that require security input and approvals. Work independently to understand collaborator requirements and the security risk involved. Use security policy, process and information security expertise to advise collaborators on appropriate solutions that do not open PlayStation up to security risks. Review security requirements associated with third party engagement requests and determine what level of third party assurance is required. Initiate and support the third-party due diligence and assurance assessment processes and able to articulate and advise on associated risks to the business, contractual requirements and resulting recommendations. Articulate and communicate risk to relevant collaborators, whilst with technical teams, partners, and leadership teams to translate security risk into mitigation plans into action items. Negotiates, tracks and reports these remediation efforts within the PlayStation risk programme. Coordinates all aspects of information security and provides consulting services to business units and other partners. Works with business partners from across Playstation and Studios to identify and implement information security requirements related to projects and engagements. Monitors and reviews IT security controls to identify operational efficiency. Performing security audits related to critical systems and prioritized business scopes. Triage information security incidents, working with our 24/7 SOC teams, business partners and related third parties, as well as be responsible for reporting and raising where necessary. Works with GRC and other security tools to collect and maintain security and risk information. Maintains broad knowledge of industry trends in the field of information security and other technologies relevant to systems handled by the operations teams. Advances the InfoSec program via partnerships with shared services teams within information security. What we’re looking for: At least four years of related work experience within Information Security risk management or security audit, with a sound technical understanding of information technology, network or infrastructure management. Must be a self-starter, comfortable with processing security requests independently initiating discussion with collaborators to drill down on exact requirements and how it aligns to process and policy. Experience in business partner/collaborator management, across technical and non-technical partners. Used to working within critical metrics and SLAs to ensure efficient responses and smooth ticket management. Experience in Jira, Confluence and GRC tracking and assessment tools. Can independently perform information Security due diligence and audits, identifying gaps and require mitigations. Proven technical background in Information Security including work related to cloud infrastructure, SaaS applications, emerging technology. Ability to understand technical terminology to understand and assess security environment. Experience with third party due diligence and contract reviews. Excellent communicator, able to translate both technical and business requirements and terminology to the applicable audience. Desirable Knowledge and Skills: Familiarity with AWS (or similar) cloud security and infrastructure. Knowledge of and experience with SaaS and web infrastructure security Awareness of security risks associated with AI and other emerging technologies Microsoft Windows and Apple Mac OS hardening Policy administration Security standards such as SOX, ISO 27001, NIST, PCI Ability to handle parallel tasks and accurately detail resolutions Bachelor’s degree in Computer Science, Information Security, or related field or equivalent experience Please refer to our Candidate Privacy Notice for more information about how we process your personal information, and your data protection rights. At SIE, we consider several factors when setting each role’s base pay range, including the competitive benchmarking data for the market and geographic location. Please note that the base pay range may vary in line with our hybrid working policy and individual base pay will be determined based on job-related factors which may include knowledge, skills, experience, and location. In addition, this role is eligible for SIE’s top-tier benefits package that includes medical, dental, vision, matching 401(k), paid time off, wellness program and coveted employee discounts for Sony products. This role also may be eligible for a bonus package. Click here to learn more. The estimated base pay range for this role is listed below. $140,000—$210,000 USD Equal Opportunity Statement: Sony is an Equal Opportunity Employer. All persons will receive consideration for employment without regard to gender (including gender identity, gender expression and gender reassignment), race (including colour, nationality, ethnic or national origin), religion or belief, marital or civil partnership status, disability, age, sexual orientation, pregnancy, maternity or parental status, trade union membership or membership in any other legally protected category. We strive to create an inclusive environment, empower employees and embrace diversity. We encourage everyone to respond. PlayStation is a Fair Chance employer and qualified applicants with arrest and conviction records will be considered for employment. #J-18808-Ljbffr

View Now

Security Industry Specialist II, Security Risk & Compliance

78703 Austin, Texas Amazon

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Description
Amazon's Security Risk and Compliance (SRC) team is currently hiring a Security Compliance Specialist to focus on preparing for and supporting third-party attestation audits. This includes
preparing SOC2 reports and regulatory/industry certifications along with developing standard security response protocols for third-party inquiries submitted to Amazon, Amazon's corporate customers, business associates, and other third party (3P) partners. The Security Compliance Specialist will handle multiple requests submitted for proof of compliance with industry and regulatory security requirements and due diligence questionnaires daily.
The SRC team obsesses over our customers and work to ensure that they are confident that Amazon cares about data confidentiality, integrity, and availability by providing third-party attestations as proof of compliance. To support successful attestations, the SRC team identifies applicable controls, assesses their effectiveness, and works with control owners to remediate the findings.
The successful candidate will be a technically experienced and innovative security and compliance professional who has the ability to understand security processes, effectively communicate with technical teams and business leaders alike, and be able to drive automated and scalable process improvements across internal organizations and teams.
Key job responsibilities
- Understand and serve as a subject-matter expert around Amazon security controls
- Dive deep into the Amazon control environment to develop broad domain and technical understanding of control activities and implementation to articulate compliance to key stakeholders.
- Developing a knowledge base of Amazon control activities and implementations; vetting with business partners and security stakeholders
- Communicate to leadership key risks and areas of program improvement, as well as seek diverse opinions and coordinate improvement efforts.
- Develop broad domain and technical understanding of Industry requirements and regulatory expectations to drive process improvement initiatives
- Preparing for SOC2, SIG, ISO 27001, US Government regulations/standards, and other certifications and assessments by identifying applicable controls, assessing control readiness for third-party assessments, recommending appropriate remediation strategies, and tracking remediation activities to completion.
- Leading and managing projects and campaigns with excellent project management skills.
- Clearly communicating vision, deliverables, and project status to management and key technical and business stakeholders.
- Delivering recommendations and risk interpretations in a clear, concise and audience-specific format.
About the team
Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.
Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
#JoinBST
Basic Qualifications
- Bachelor's Degree in Computer Science, Information Systems Management, Mathematics, Accounting/Auditing, or other related fields
- 5+ years experience in security, audits, customer trust, control assessments, or risk assessments.
- 5+ years experience assessing complex technical processes
Preferred Qualifications
- Demonstrated understanding of cloud computing services/architecture
- Experience with monitoring and automating security controls.
- Experience with using GRC tooling
- Direct experience in working with security and business teams on controls design to address regulatory compliance requirements
- Experience in technical security design, compliance consulting, or advisory work in support of a highly technical DevOps and cloud environment.
- Experience in developing unified frameworks that include more than one of the following: ISO, NIST, PCI, HIPAA, GLBA, GDPR, NYDFS, etc.
- Have an industry certification such as CISSP, CISA, and CISM.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $91,800/year in our lowest geographic market up to $196,300/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.
View Now

Security Industry Specialist II, Security Risk & Compliance

98194 Seattle, Washington Amazon

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Description
Amazon's Security Risk and Compliance (SRC) team is currently hiring a Security Compliance Specialist to focus on preparing for and supporting third-party attestation audits. This includes
preparing SOC2 reports and regulatory/industry certifications along with developing standard security response protocols for third-party inquiries submitted to Amazon, Amazon's corporate customers, business associates, and other third party (3P) partners. The Security Compliance Specialist will handle multiple requests submitted for proof of compliance with industry and regulatory security requirements and due diligence questionnaires daily.
The SRC team obsesses over our customers and work to ensure that they are confident that Amazon cares about data confidentiality, integrity, and availability by providing third-party attestations as proof of compliance. To support successful attestations, the SRC team identifies applicable controls, assesses their effectiveness, and works with control owners to remediate the findings.
The successful candidate will be a technically experienced and innovative security and compliance professional who has the ability to understand security processes, effectively communicate with technical teams and business leaders alike, and be able to drive automated and scalable process improvements across internal organizations and teams.
Key job responsibilities
- Understand and serve as a subject-matter expert around Amazon security controls
- Dive deep into the Amazon control environment to develop broad domain and technical understanding of control activities and implementation to articulate compliance to key stakeholders.
- Developing a knowledge base of Amazon control activities and implementations; vetting with business partners and security stakeholders
- Communicate to leadership key risks and areas of program improvement, as well as seek diverse opinions and coordinate improvement efforts.
- Develop broad domain and technical understanding of Industry requirements and regulatory expectations to drive process improvement initiatives
- Preparing for SOC2, SIG, ISO 27001, US Government regulations/standards, and other certifications and assessments by identifying applicable controls, assessing control readiness for third-party assessments, recommending appropriate remediation strategies, and tracking remediation activities to completion.
- Leading and managing projects and campaigns with excellent project management skills.
- Clearly communicating vision, deliverables, and project status to management and key technical and business stakeholders.
- Delivering recommendations and risk interpretations in a clear, concise and audience-specific format.
About the team
Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.
Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
#JoinBST
Basic Qualifications
- Bachelor's Degree in Computer Science, Information Systems Management, Mathematics, Accounting/Auditing, or other related fields
- 5+ years experience in security, audits, customer trust, control assessments, or risk assessments.
- 5+ years experience assessing complex technical processes
Preferred Qualifications
- Demonstrated understanding of cloud computing services/architecture
- Experience with monitoring and automating security controls.
- Experience with using GRC tooling
- Direct experience in working with security and business teams on controls design to address regulatory compliance requirements
- Experience in technical security design, compliance consulting, or advisory work in support of a highly technical DevOps and cloud environment.
- Experience in developing unified frameworks that include more than one of the following: ISO, NIST, PCI, HIPAA, GLBA, GDPR, NYDFS, etc.
- Have an industry certification such as CISSP, CISA, and CISM.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $91,800/year in our lowest geographic market up to $196,300/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.
View Now
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Security Risk Jobs