Information Security & Compliance Manager

London, London Ravio

Posted today

Job Viewed

Tap Again To Close

Job Description

OverviewnWe help companies get compensation right. What we get paid at work has a massive impact on our lives, and it is one of the biggest factors in hiring and retaining talent. Ravio provides a real-time data platform that brings compensation into the modern age with clarity and transparency. We are the European leader in this space, serving more than 1,200 clients, and we aim to become the global go-to place for compensation data and tools for managing compensation. Joining a startup and scaling it into a global product is challenging and rewarding. If that sounds exciting to you, you’re in the right place.

About the Role:

We are seeking a proactive and commercially-minded

Information Security & Compliance Manager

to join our team. This is a mid-level individual contributor role suited for someone who thrives in a fast-paced environment, is comfortable wearing multiple hats, and is excited by both InfoSec and hands-on compliance operations.

This role will focus primarily on security, data privacy, compliance, and regulatory matters. You will play a key role in helping the business stay compliant with relevant laws and standards, including oversight of our SOC 2 compliance processes, while also helping to drive practical compliance solutions across the business. A background in

Security Engineering

is a big plus as it would enable you to own the end-to-end architecture and technical execution of our security controls and systems.

Key Responsibilities

Operational Security & Security Architecture

Drive strategic planning, execution, and operations of scalable, automated, and resilient security controls

Contribute towards defining Ravio's security engineering strategy that addresses identity, endpoint, and data protection across all environments

Design a global security architecture and support the security engineering roadmap (with a special focus on data security)

Oversee security monitoring, vulnerability management, and incident response

Coordinate tabletop exercises and incident response testing

Own the relationship with security vendors

Governance, Risk & Compliance (GRC)

Lead or support internal compliance programs, with a focus on data privacy, corporate governance, and regulatory frameworks

Manage the organization's compliance with frameworks and regulations (oversee SOC 2 Type II maintenance and readiness efforts)

Conduct risk assessments and maintain the enterprise risk register

Ensure third-party vendor risk management processes are in place

Awareness & Training

Develop and deliver security awareness programs

Promote a culture of security and compliance across the organisation

Audit & Reporting

Prepare for and support internal and external audits

Track compliance KPIs and report status to executive leadership

Ensure timely remediation of audit findings

About YounExperience & Qualifications

Strong working knowledge of global data privacy laws and compliance standards (e.g. GDPR, CCPA, SOC 2)

Strong knowledge of security standards, controls, and best practices (NIST, CIS, OWASP)

Familiarity with cloud security (AWS, Azure, GCP)

Experience with audit management, GRC tools, and security monitoring solutions

Excellent problem-solving, communication, and stakeholder management skills

Skills & Traits

You enjoy data privacy, compliance, and security operations and are happy to "roll up your sleeves" when needed

Pragmatic, solutions-oriented, and business-savvy

Excellent communication skills with the ability to influence across departments

Highly organised and able to manage multiple projects simultaneously

Comfortable working in a fast-moving, ambiguous, and collaborative environment

Strong plus: a background in Security Engineering

Compensation & Benefits

£75,000 - £5,000

Company ownership (everyone gets a meaningful equity stake in Ravio)

37 days paid time off (25 days holiday + 4 wellness day + 8 public holidays)

Up to 6% pension matching scheme

0 a month wellness allowance (Invest in your physical wellbeing, on us)

00 per year Learning and Development budget

Private healthcare cover with AXA

Personal travel insurance - just in case

Income protection insurance (for full peace of mind in case you cannot work because of sickness or disability)

16 weeks fully paid birthing parent leave, followed by 4 weeks at 50% pay & 8 weeks for non-birthing parent

For more information about what we collect and how we use it when you apply for a role with us, please refer to our Candidate Privacy Notice.

#J-18808-Ljbffrn
This advertiser has chosen not to accept applicants from your region.

Senior Security Compliance Specialist,Payments Security Compliance

London, London Amazon

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

Description

In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection



We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.



Key job responsibilities

Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations



Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums



Communicate clearly and effectively to executive management on the plans, status and critical issues.



Escalate urgent issues appropriately and driving them to closure in a timely manner



Oversight on remediation programs impacting regulated region (s) being supported



Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards



Represents Security posture of regulated entities, in external regulatory audits



Review Implementation of Security best practices and standards, drive continuous improvements



Influence Security Control Assessment Automation efforts, for security and compliance at scale.



Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions



Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums



About the team

The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:



We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.



We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.



We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.



We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.



We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.



We always favor automated policy enforcement over manual/best intentions policy enforcement.



We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.

Basic Qualifications

Bachelor's Degree in computer science, engineering or related discipline or equivalent experience



Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus



Experience with service-oriented architectures, private and public clouds and web services security.



Excellent communication, work prioritization and analytical skills. Result oriented, high energy, self-motivated



Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls

Preferred Qualifications

Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.



AWS knowledge preferred.



Work ethic based on a strong desire to exceed expectations.



Experience working successfully in a very fast-paced, results-oriented environment.



Knowledge of technology and payment industry trends



Senior-level written and verbal communication skills



Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units



Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.



Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.



Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
This advertiser has chosen not to accept applicants from your region.

Senior Security Compliance Specialist,Payments Security Compliance

London, London Amazon

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

Description

In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection



We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.



Key job responsibilities

Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations



Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums



Communicate clearly and effectively to executive management on the plans, status and critical issues.



Escalate urgent issues appropriately and driving them to closure in a timely manner



Oversight on remediation programs impacting regulated region (s) being supported



Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards



Represents Security posture of regulated entities, in external regulatory audits



Review Implementation of Security best practices and standards, drive continuous improvements



Influence Security Control Assessment Automation efforts, for security and compliance at scale.



Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions



Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums



About the team

The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:



We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.



We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.



We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.



We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.



We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.



We always favor automated policy enforcement over manual/best intentions policy enforcement.



We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.

Basic Qualifications

Bachelor's Degree in computer science, engineering or related discipline or equivalent experience



Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus



Experience with service-oriented architectures, private and public clouds and web services security.



Excellent communication, work prioritization and analytical skills. Result oriented, high energy, self-motivated



Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls

Preferred Qualifications

Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.



AWS knowledge preferred.



Work ethic based on a strong desire to exceed expectations.



Experience working successfully in a very fast-paced, results-oriented environment.



Knowledge of technology and payment industry trends



Senior-level written and verbal communication skills



Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units



Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.



Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.



Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
This advertiser has chosen not to accept applicants from your region.

Senior Security & Compliance Specialist,Payments Security Compliance

London, London Amazon

Posted 13 days ago

Job Viewed

Tap Again To Close

Job Description

Description

In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection



We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.



Key job responsibilities

- Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations



- Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums



- Communicate clearly and effectively to executive management on the plans, status and critical issues.



- Escalate urgent issues appropriately and driving them to closure in a timely manner



- Oversight on remediation programs impacting regulated region (s) being supported



- Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards



- Represents Security posture of regulated entities, in external regulatory audits



- Review Implementation of Security best practices and standards, drive continuous improvements



- Influence Security Control Assessment Automation efforts, for security and compliance at scale.



- Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions

- Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums



About the team

The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:



We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.



We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.



We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.



We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.



We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.



We always favor automated policy enforcement over manual/best intentions policy enforcement.



We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.

Basic Qualifications

Bachelor's Degree in computer science, engineering or related discipline or equivalent experience

Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus

Experience with service-oriented architectures, private and public clouds and web services security.

Excellent communication, work prioritization and analytical skills.

Result oriented, high energy, self-motivated

Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls,

Preferred Qualifications

Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.

AWS knowledge preferred.

Work ethic based on a strong desire to exceed expectations. Experience working successfully in a very fast-paced, results-oriented environment.

Knowledge of technology and payment industry trends

Senior-level written and verbal communication skills

Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units



Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.



Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.



Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
This advertiser has chosen not to accept applicants from your region.

Senior Security & Compliance Specialist,Payments Security Compliance

London, London Amazon

Posted 13 days ago

Job Viewed

Tap Again To Close

Job Description

Description

In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection



We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customeru2019s Trust in Amazon by providing secure, robust, and reliable payment services.



Key job responsibilities

- Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations



- Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer orgu2019s voice heard in the relevant forums



- Communicate clearly and effectively to executive management on the plans, status and critical issues.



- Escalate urgent issues appropriately and driving them to closure in a timely manner



- Oversight on remediation programs impacting regulated region (s) being supported



- Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards



- Represents Security posture of regulated entities, in external regulatory audits



- Review Implementation of Security best practices and standards, drive continuous improvements



- Influence Security Control Assessment Automation efforts, for security and compliance at scale.



- Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions

- Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the u201ctrusted advisoru201d. Also, create and maintain a trusted relationship with regulators and industry forums



About the team

The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazonu2019s WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:



We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.



We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.



We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.



We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.



We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.



We always favor automated policy enforcement over manual/best intentions policy enforcement.



We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.

Basic Qualifications

Bachelor's Degree in computer science, engineering or related discipline or equivalent experience

Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus

Experience with service-oriented architectures, private and public clouds and web services security.

Excellent communication, work prioritization and analytical skills.

Result oriented, high energy, self-motivated

Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls,

Preferred Qualifications

Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.

AWS knowledge preferred.

Work ethic based on a strong desire to exceed expectations. Experience working successfully in a very fast-paced, results-oriented environment.

Knowledge of technology and payment industry trends

Senior-level written and verbal communication skills

Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units



Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.



Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.



Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region youu2019re applying in isnu2019t listed, please contact your Recruiting Partner.
This advertiser has chosen not to accept applicants from your region.

Senior Security Compliance Specialist, Payments Security Compliance

London, London Amazon

Posted 8 days ago

Job Viewed

Tap Again To Close

Job Description

Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customer's Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer org's voice heard in the relevant forums
Communicate clearly and effectively to executive management on the plans, status and critical issues.
Escalate urgent issues appropriately and driving them to closure in a timely manner
Oversight on remediation programs impacting regulated region (s) being supported
Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
Represents Security posture of regulated entities, in external regulatory audits
Review Implementation of Security best practices and standards, drive continuous improvements
Influence Security Control Assessment Automation efforts, for security and compliance at scale.
Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the "trusted advisor". Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazon's WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills. Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations.
Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
This advertiser has chosen not to accept applicants from your region.

Senior Security & Compliance Specialist, Payments Security Compliance

London, London Amazon

Posted 13 days ago

Job Viewed

Tap Again To Close

Job Description

Description
In compliance with regulatory requirements, and in alignment with business teams, Payments Security Compliance (PSC) team supports Amazon payments entities in select regions. Security Compliance Specialists have varying scope of responsibility in each region, depending on the nature of regulatory licenses to be maintained, number of regulators, the number of systems and teams in scope (blast radius of regulatory compliance), and the degree of stringency the local regime places on Security and Data protection
We are seeking an experienced, self-motivated Senior Security Compliance Specialist with strong Security and Compliance background. This candidate will be an innovative and forward thinking individual who possess in-depth knowledge and will be identifying Information Security compliance risks, drive Security Governance, Security Assurance and Risk Management efforts, manage regional regulatory compliance and contribute to emerging regulations and technology standards globally, partnering with Security Experts of Global Amazon Information Security teams. Your work directly impacts Customer's Trust in Amazon by providing secure, robust, and reliable payment services.
Key job responsibilities
- Positively impact how Amazon builds, consumes and operate software securely and in compliance with standards and regulations
- Contribute on emerging regulations and technology standards joining forces with AWS, Public Policy team and others, making Amazon Consumer org's voice heard in the relevant forums
- Communicate clearly and effectively to executive management on the plans, status and critical issues.
- Escalate urgent issues appropriately and driving them to closure in a timely manner
- Oversight on remediation programs impacting regulated region (s) being supported
- Be recognized as thought leader in Regulatory Security Compliance and Security best practices/standards
- Represents Security posture of regulated entities, in external regulatory audits
- Review Implementation of Security best practices and standards, drive continuous improvements
- Influence Security Control Assessment Automation efforts, for security and compliance at scale.
- Skilled in security risk analysis and making complex business/risk trade-off recommendations and decisions
- Maintaining C-level relationships with peers, stakeholders, boardrooms, and/or customers, often becoming the "trusted advisor". Also, create and maintain a trusted relationship with regulators and industry forums
About the team
The objective of Payments Security Compliance (PSC) is to oversee & manage Information Security Governance, Risk and Compliance (IS-GRC) for the Payments entities globally as part of Amazon's WW SRC team. The tenets for Payments Security Compliance team (Unless you know better ones) are:
We provide timely and accurate security, compliance, and risk data to the business to make decisions. We hold ourselves accountable for accuracy of the data and businesses accountable for timely customer trustworthy decisions.
We escalate appropriately to ensure that security and compliance issues are resolved promptly and with high judgment. If in doubt, we escalate and are clinical, precise, and complete in our escalation.
We are business-risk driven in security and compliance decisions. We exercise judgement and partner with businesses in managing risk.
We make it easy to be compliant. We eliminate, automate, provide self-service for customer compliance activities and in that order. Only where absolutely necessary we have manual activities.
We interpret unclear external regulations, industry standards or Amazon policies in favor of our businesses protecting customer trust.
We always favor automated policy enforcement over manual/best intentions policy enforcement.
We are slow and deliberate when adding new policies, quick to fix policy issues and quick to eliminate irrelevant policies. When we add or update policies we ensure they are enforceable.
Basic Qualifications
Bachelor's Degree in computer science, engineering or related discipline or equivalent experience
Familiarity with common attack patterns, exploitation techniques and remediation techniques will be plus
Experience with service-oriented architectures, private and public clouds and web services security.
Excellent communication, work prioritization and analytical skills.
Result oriented, high energy, self-motivated
Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls,
Preferred Qualifications
Have a record of delivery of large scale security programs and/or technology solutions for major tech companies.
AWS knowledge preferred.
Work ethic based on a strong desire to exceed expectations. Experience working successfully in a very fast-paced, results-oriented environment.
Knowledge of technology and payment industry trends
Senior-level written and verbal communication skills
Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( ) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Security compliance Jobs in London !

Security Compliance Engineer

£45000 - £85000 annum Kuba

Posted 576 days ago

Job Viewed

Tap Again To Close

Job Description

Permanent

The Security Compliance Engineer is a crucial member of our security team, responsible for ensuring our organisation's adherence to PCI standards and other relevant security regulations. This role involves implementing and maintaining secure payment environments, managing key encryption and decryption processes, and providing technical guidance for security compliance projects. The ideal candidate will have a strong understanding of PCI-DSS, PCI-PTS, PCI Software Security Framework, Secure Software Standard, Secure SLC Standard, and Amazon Web Services (AWS). They will also have excellent problem-solving skills, a hands-on approach to work, and the ability to communicate complex security concepts to a non-technical audience. Relevant certifications in information security and AWS are a plus.


About Kuba

We are a fast-growing SaaS company with offices in the UK, France, South Africa, Italy and the US. We believe that efficient public transport is key to delivering positive, sustainable change.

Kuba is in the transport sector, but we are a technology provider that enables Ticketing-as-a-Service (TaaS). We offer cutting-edge ticketing technology coupled with broad practical sector experience.

It's an exciting time to work at Kuba as we are accelerating into an incredible period of growth, and you'll have a chance to grow with us.


Responsibilities
  • Implement and maintain secure payment environments, including data encryption, secure networks, and secure transaction systems in compliance with PCI-DSS, PCI-PTS, PCI Software Security Framework, Secure Software Standard, Secure SLC Standard, and AWS best practices.
  • Conduct regular audits to ensure secure handling of cardholder data and compliance with PCI, AWS, and other relevant security standards.
  • Develop and implement security policies and procedures related to data protection, network security, and incident management to ensure compliance with PCI standards, AWS best practices, and other relevant regulations.
  • Manage key encryption and decryption processes, ensuring secure key management.
  • Provide technical guidance and support for all security compliance projects.
  • Collaborate with various teams to ensure security standards are met across all projects.
  • Stay updated on the latest security standards, systems, and authentication protocols, including AWS security services and features.
  • Participate in the creation and or maintenance of the Information Security Management System.

Requirements

  • Proven experience in a technical role managing security compliance, preferably with a focus on PCI standards and AWS. Experience in roles such as Security Analyst, Security Engineer, or similar is preferred.
  • Strong knowledge of PCI-DSS, PCI-PTS, PCI Software Security Framework, Secure Software Standard, Secure SLC Standard, and AWS.
  • Expertise in key management, encryption/decryption processes, and AWS security services and features.
  • Familiarity with various network architectures, cloud services, system management practices, process improvement strategies, and AWS infrastructure.
  • Strong problem-solving skills and a hands-on approach to tackling challenges.
  • Excellent communication skills, with the ability to explain complex security concepts to non-technical team members.
  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or AWS Certified Security - Specialty are a plus.

Benefits

Salary and benefits commensurate with position

This advertiser has chosen not to accept applicants from your region.

Security and Compliance Manager (London)

London, London Deskpro

Posted 204 days ago

Job Viewed

Tap Again To Close

Job Description

Permanent

Deskpro, a leading provider of help desk software, is seeking a Security and Compliance Manager to join our team. As a Security and Compliance Manager at Deskpro, you will be responsible for ensuring the security and compliance of our software and systems, as well as implementing and enforcing policies and procedures to safeguard sensitive data.

We take security seriously, and we work with many enterprise and government clients. In this role, you will have the opportunity to make an impact and contribute to the continued success of Deskpro as a trusted provider of secure help desk solutions.

Responsibilities:

  • Manage all existing security and compliance security policies, practices, procedures and systems
  • Where required, develop and implement additional security policies, practices and procedures
  • Ensure compliance with relevant industry standards and regulations
  • Monitor and assess potential security risks and vulnerabilities
  • Design and implement security controls, including authentication, encryption, and access controls
  • Perform regular security audits and vulnerability assessments
  • Engage with customers and prospects regarding custom security and compliance requests
  • Conduct security incident response and investigations
  • Educate and train employees on security best practices
  • Maintain awareness of emerging security threats and solutions
  • Collaborate with cross-functional teams to implement security measures
  • Stay up-to-date with industry trends and best practices in security and compliance

Requirements

  • Proven experience in a similar role, with a focus on security and compliance
  • Deep knowledge of relevant industry standards and regulations (e.g., SOC 2, ISO 27001, GDPR, HIPAA)
  • Strong understanding of security principles, technologies, and best practices
  • Experience in developing and implementing security policies and procedures
  • Familiarity with security tools and technologies, such as intrusion detection systems, firewalls, and data encryption
  • Ability to assess and mitigate security risks
  • Excellent communication and interpersonal skills
  • Ability to work independently and collaboratively in a fast-paced environment
  • Attention to detail and strong analytical skills
  • Relevant certifications (e.g., CISSP, CISM, CRISC) are a plus

Benefits

Competitive benefits package including stock options. Specifics will be dependent on location (either London, UK or Austin, TX, USA).

This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Security Compliance Jobs View All Jobs in London