96 Security Compliance jobs in London
Information Security & Compliance Manager
Posted today
Job Viewed
Job Description
About the Role:
We are seeking a proactive and commercially-minded
Information Security & Compliance Manager
to join our team. This is a mid-level individual contributor role suited for someone who thrives in a fast-paced environment, is comfortable wearing multiple hats, and is excited by both InfoSec and hands-on compliance operations.
This role will focus primarily on security, data privacy, compliance, and regulatory matters. You will play a key role in helping the business stay compliant with relevant laws and standards, including oversight of our SOC 2 compliance processes, while also helping to drive practical compliance solutions across the business. A background in
Security Engineering
is a big plus as it would enable you to own the end-to-end architecture and technical execution of our security controls and systems.
Key Responsibilities
Operational Security & Security Architecture
Drive strategic planning, execution, and operations of scalable, automated, and resilient security controls
Contribute towards defining Ravio's security engineering strategy that addresses identity, endpoint, and data protection across all environments
Design a global security architecture and support the security engineering roadmap (with a special focus on data security)
Oversee security monitoring, vulnerability management, and incident response
Coordinate tabletop exercises and incident response testing
Own the relationship with security vendors
Governance, Risk & Compliance (GRC)
Lead or support internal compliance programs, with a focus on data privacy, corporate governance, and regulatory frameworks
Manage the organization's compliance with frameworks and regulations (oversee SOC 2 Type II maintenance and readiness efforts)
Conduct risk assessments and maintain the enterprise risk register
Ensure third-party vendor risk management processes are in place
Awareness & Training
Develop and deliver security awareness programs
Promote a culture of security and compliance across the organisation
Audit & Reporting
Prepare for and support internal and external audits
Track compliance KPIs and report status to executive leadership
Ensure timely remediation of audit findings
About YounExperience & Qualifications
Strong working knowledge of global data privacy laws and compliance standards (e.g. GDPR, CCPA, SOC 2)
Strong knowledge of security standards, controls, and best practices (NIST, CIS, OWASP)
Familiarity with cloud security (AWS, Azure, GCP)
Experience with audit management, GRC tools, and security monitoring solutions
Excellent problem-solving, communication, and stakeholder management skills
Skills & Traits
You enjoy data privacy, compliance, and security operations and are happy to "roll up your sleeves" when needed
Pragmatic, solutions-oriented, and business-savvy
Excellent communication skills with the ability to influence across departments
Highly organised and able to manage multiple projects simultaneously
Comfortable working in a fast-moving, ambiguous, and collaborative environment
Strong plus: a background in Security Engineering
Compensation & Benefits
£75,000 - £5,000
Company ownership (everyone gets a meaningful equity stake in Ravio)
37 days paid time off (25 days holiday + 4 wellness day + 8 public holidays)
Up to 6% pension matching scheme
0 a month wellness allowance (Invest in your physical wellbeing, on us)
00 per year Learning and Development budget
Private healthcare cover with AXA
Personal travel insurance - just in case
Income protection insurance (for full peace of mind in case you cannot work because of sickness or disability)
16 weeks fully paid birthing parent leave, followed by 4 weeks at 50% pay & 8 weeks for non-birthing parent
For more information about what we collect and how we use it when you apply for a role with us, please refer to our Candidate Privacy Notice.
#J-18808-Ljbffrn
Senior Security Compliance Specialist,Payments Security Compliance
Posted 1 day ago
Job Viewed
Job Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums
Communicate clearly and effectively to executive management on the plans, status and critical issues.
Escalate urgent issues appropriately and driving them to closure in a timely manner
Oversight on remediation programs impacting regulated region (s) being supported
Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
Represents Security posture of regulated entities, in external regulatory audits
Review Implementation of Security best practices and standards, drive continuous improvements
Influence Security Control Assessment Automation efforts, for security and compliance at scale.
Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills. Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations.
Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
Senior Security Compliance Specialist,Payments Security Compliance
Posted 2 days ago
Job Viewed
Job Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums
Communicate clearly and effectively to executive management on the plans, status and critical issues.
Escalate urgent issues appropriately and driving them to closure in a timely manner
Oversight on remediation programs impacting regulated region (s) being supported
Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
Represents Security posture of regulated entities, in external regulatory audits
Review Implementation of Security best practices and standards, drive continuous improvements
Influence Security Control Assessment Automation efforts, for security and compliance at scale.
Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills. Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations.
Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
Senior Security & Compliance Specialist,Payments Security Compliance
Posted 13 days ago
Job Viewed
Job Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
- Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
- Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums
- Communicate clearly and effectively to executive management on the plans, status and critical issues.
- Escalate urgent issues appropriately and driving them to closure in a timely manner
- Oversight on remediation programs impacting regulated region (s) being supported
- Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
- Represents Security posture of regulated entities, in external regulatory audits
- Review Implementation of Security best practices and standards, drive continuous improvements
- Influence Security Control Assessment Automation efforts, for security and compliance at scale.
- Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
- Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills.
Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls,
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations. Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
Senior Security & Compliance Specialist,Payments Security Compliance
Posted 13 days ago
Job Viewed
Job Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
- Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
- Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums
- Communicate clearly and effectively to executive management on the plans, status and critical issues.
- Escalate urgent issues appropriately and driving them to closure in a timely manner
- Oversight on remediation programs impacting regulated region (s) being supported
- Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
- Represents Security posture of regulated entities, in external regulatory audits
- Review Implementation of Security best practices and standards, drive continuous improvements
- Influence Security Control Assessment Automation efforts, for security and compliance at scale.
- Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
- Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills.
Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls,
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations. Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
Senior Security Compliance Specialist, Payments Security Compliance
Posted 8 days ago
Job Viewed
Job Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customer's Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer org's voice heard in the relevant forums
Communicate clearly and effectively to executive management on the plans, status and critical issues.
Escalate urgent issues appropriately and driving them to closure in a timely manner
Oversight on remediation programs impacting regulated region (s) being supported
Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
Represents Security posture of regulated entities, in external regulatory audits
Review Implementation of Security best practices and standards, drive continuous improvements
Influence Security Control Assessment Automation efforts, for security and compliance at scale.
Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the "trusted advisor". Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazon's WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills. Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations.
Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Senior Security & Compliance Specialist, Payments Security Compliance

Posted 13 days ago
Job Viewed
Job Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customer's Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
- Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
- Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer org's voice heard in the relevant forums
- Communicate clearly and effectively to executive management on the plans, status and critical issues.
- Escalate urgent issues appropriately and driving them to closure in a timely manner
- Oversight on remediation programs impacting regulated region (s) being supported
- Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
- Represents Security posture of regulated entities, in external regulatory audits
- Review Implementation of Security best practices and standards, drive continuous improvements
- Influence Security Control Assessment Automation efforts, for security and compliance at scale.
- Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
- Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the "trusted advisor". Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazon's WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills.
Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls,
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations. Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Be The First To Know
About the latest Security compliance Jobs in London !
Security Compliance Engineer
Posted 576 days ago
Job Viewed
Job Description
The Security Compliance Engineer is a crucial member of our security team, responsible for ensuring our organisation's adherence to PCI standards and other relevant security regulations. This role involves implementing and maintaining secure payment environments, managing key encryption and decryption processes, and providing technical guidance for security compliance projects. The ideal candidate will have a strong understanding of PCI-DSS, PCI-PTS, PCI Software Security Framework, Secure Software Standard, Secure SLC Standard, and Amazon Web Services (AWS). They will also have excellent problem-solving skills, a hands-on approach to work, and the ability to communicate complex security concepts to a non-technical audience. Relevant certifications in information security and AWS are a plus.
We are a fast-growing SaaS company with offices in the UK, France, South Africa, Italy and the US. We believe that efficient public transport is key to delivering positive, sustainable change.
Kuba is in the transport sector, but we are a technology provider that enables Ticketing-as-a-Service (TaaS). We offer cutting-edge ticketing technology coupled with broad practical sector experience.
It's an exciting time to work at Kuba as we are accelerating into an incredible period of growth, and you'll have a chance to grow with us.
- Implement and maintain secure payment environments, including data encryption, secure networks, and secure transaction systems in compliance with PCI-DSS, PCI-PTS, PCI Software Security Framework, Secure Software Standard, Secure SLC Standard, and AWS best practices.
- Conduct regular audits to ensure secure handling of cardholder data and compliance with PCI, AWS, and other relevant security standards.
- Develop and implement security policies and procedures related to data protection, network security, and incident management to ensure compliance with PCI standards, AWS best practices, and other relevant regulations.
- Manage key encryption and decryption processes, ensuring secure key management.
- Provide technical guidance and support for all security compliance projects.
- Collaborate with various teams to ensure security standards are met across all projects.
- Stay updated on the latest security standards, systems, and authentication protocols, including AWS security services and features.
- Participate in the creation and or maintenance of the Information Security Management System.
Requirements
- Proven experience in a technical role managing security compliance, preferably with a focus on PCI standards and AWS. Experience in roles such as Security Analyst, Security Engineer, or similar is preferred.
- Strong knowledge of PCI-DSS, PCI-PTS, PCI Software Security Framework, Secure Software Standard, Secure SLC Standard, and AWS.
- Expertise in key management, encryption/decryption processes, and AWS security services and features.
- Familiarity with various network architectures, cloud services, system management practices, process improvement strategies, and AWS infrastructure.
- Strong problem-solving skills and a hands-on approach to tackling challenges.
- Excellent communication skills, with the ability to explain complex security concepts to non-technical team members.
- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or AWS Certified Security - Specialty are a plus.
Benefits
Salary and benefits commensurate with position
Security and Compliance Manager (London)
Posted 204 days ago
Job Viewed
Job Description
Deskpro, a leading provider of help desk software, is seeking a Security and Compliance Manager to join our team. As a Security and Compliance Manager at Deskpro, you will be responsible for ensuring the security and compliance of our software and systems, as well as implementing and enforcing policies and procedures to safeguard sensitive data.
We take security seriously, and we work with many enterprise and government clients. In this role, you will have the opportunity to make an impact and contribute to the continued success of Deskpro as a trusted provider of secure help desk solutions.
Responsibilities:
- Manage all existing security and compliance security policies, practices, procedures and systems
- Where required, develop and implement additional security policies, practices and procedures
- Ensure compliance with relevant industry standards and regulations
- Monitor and assess potential security risks and vulnerabilities
- Design and implement security controls, including authentication, encryption, and access controls
- Perform regular security audits and vulnerability assessments
- Engage with customers and prospects regarding custom security and compliance requests
- Conduct security incident response and investigations
- Educate and train employees on security best practices
- Maintain awareness of emerging security threats and solutions
- Collaborate with cross-functional teams to implement security measures
- Stay up-to-date with industry trends and best practices in security and compliance
Requirements
- Proven experience in a similar role, with a focus on security and compliance
- Deep knowledge of relevant industry standards and regulations (e.g., SOC 2, ISO 27001, GDPR, HIPAA)
- Strong understanding of security principles, technologies, and best practices
- Experience in developing and implementing security policies and procedures
- Familiarity with security tools and technologies, such as intrusion detection systems, firewalls, and data encryption
- Ability to assess and mitigate security risks
- Excellent communication and interpersonal skills
- Ability to work independently and collaboratively in a fast-paced environment
- Attention to detail and strong analytical skills
- Relevant certifications (e.g., CISSP, CISM, CRISC) are a plus
Benefits
Competitive benefits package including stock options. Specifics will be dependent on location (either London, UK or Austin, TX, USA).