At Amazon Web Services (AWS), Security is our highest priority. The AWS Security Risk and Compliance (SRC) team is seeking a Principal Security Industry Specialist to serve as the compliance bridge between AWS AI service teams and the security compliance organization. This is an individual contributor role responsible for ensuring AWS AI products and services are designed, launched, and operated in compliance with security frameworks, regulatory requirements, and internal governance standards across all regulated industry segments and geographies.
You will work directly with AI service teams, and downstream AWS services leveraging AI models, to advise on compliance requirements, surface regulatory risks introduced by new capabilities, and drive alignment with compliance programs before General Availability. Operating at the intersection of AI governance, risk management, and security compliance, you will translate complex and evolving regulatory requirements (EU AI Act, DORA, NIS2, FedRAMP) and compliance standards (ISO 42001) into actionable guidance that service teams can implement at the pace of innovation. This is a high-visibility, high-impact role requiring an individual contributor who can think big, influence across organizational boundaries, and ensure AWS's AI services meet the compliance expectations of our most highly regulated customers.
Key job responsibilities
Serve as the primary compliance engagement point for AWS AI service teams, advising on regulatory requirements, compliance posture, and risk implications across the service lifecycle (design, build, launch, operate).
Partner with compliance assessment and assurance teams to ensure AI services approaching General Availability are evaluated against the AI Service Compliance Framework (AISCF) and existing security compliance regimes (SOC 2, ISO 27001, FedRAMP, PCI-DSS), providing subject matter expertise and service team context to inform assessment outcomes.
Work with service teams to identify compliance risks introduced by AI model onboarding, cross-region inference, trust and safety data retention, and model governance requirements; driving service teams toward compliant design decisions.
Develop and maintain compliance guidance, decision frameworks, and adoption criteria that enable service teams to self-assess and design for compliance at the architecture phase, reducing manual review cycles and accelerating compliant launches.
Collaborate with the AI Governance lead and Risk program owner to ensure service-level compliance findings and emerging regulatory trends inform enterprise risk posture and governance strategy.
Partner with TPMs building compliance assessment tooling and automation (e.g., AI-powered assessment agents, compliance registries, zero-touch compliance workflows), providing compliance domain expertise and requirements to shape scalable solutions.
Work with obligations monitoring teams to ensure new and evolving AI regulatory requirements are translated into service team guidance and compliance framework updates.
Partner with Assurance, as required, to engage with highly regulated customers and external stakeholders (regulators, auditors, industry groups) to validate that AWS AI service compliance posture meets their security assurance expectations.
Monitor regulatory trends across multiple jurisdictions and leadership on implications for AI service design and operation.
Influence leadership through data-driven narratives, compliance risk briefings, and white papers that drive resource allocation and strategic decision-making on AI compliance matters.
A day in the life
In this role, you'll spend your day advising AWS AI service teams on compliance requirements as they design and launch new capabilities, translating complex regulatory obligations into practical guidance that engineers can act on. You'll partner with assessment teams to provide service context that informs their evaluations, collaborate with TPMs building compliance automation tooling, and work across AI governance and risk functions to ensure service-level findings shape enterprise strategy. No two days look the same, but the constant is serving as the connective tissue between the teams building AWS's AI services and the compliance organization ensuring they meet the expectations of our most highly regulated customers.
About the team
The Compliance Operations and Regulatory Response (CORR) team serves as the operational backbone of AWS Security Risk and Compliance (SRC), managing the complete compliance lifecycle, from early detection of emerging regulatory requirements through horizon scanning and obligation management, to specialized compliance assessments, AI service compliance, and operational incident reporting. Our vision is to transform compliance from a reactive, manual bottleneck into a proactive, automated competitive advantage by delivering such things as zero-touch compliance-ready launches, scalable compliance infrastructure, and proactive risk management across all regulated industry segments and geographies.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
- 10+ years of security, compliance and risk management experience, or degree in advanced technology
- Experience implementing scalable compliance solutions (technology, procedures, processes, etc.) in a regulated environment
- 12+ years of regulatory frameworks and policy analysis methodologies experience
- Experience in written and oral communication, including the ability to communicate with all levels in the organization (technical, business, executive)
- Experience with IT compliance and risk management requirements (e.g. security, privacy, SOX, HIPAA etc.)
- Experience owning and driving large-scale cross-functional programs
- Master's degree or above in information management, information science, information technology, computer science, engineering or related field
- Experience in risk management and internal audit including: performing risk assessments and audits, designing controls, managing enterprise control frameworks, and prioritizing risk
- CISSP, CISA, CISM or other security certification
- 8+ years of working directly with government officials and regulatory bodies experience
- 6+ years of Artificial Intelligence/Machine Learning (AI/ML) Standards Law experience
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, VA, Arlington - 142,000.00 - 248,400.00 USD annually
USA, VA, Herndon - 142,000.00 - 248,400.00 USD annually
USA, WA, Seattle - 142,000.00 - 248,400.00 USD annually