Mediabistro logo
job logo

Healthcare Assurance Specialist , AWS Compliance & Security Assurance

Amazon, Baltimore, MD, United States


Healthcare Assurance Specialist – AWS Compliance & Security Assurance
Job ID: 10402009 | Amazon Web Services, Inc.

Amazon Web Services (AWS) is seeking an Assurance and Compliance Specialist to join our Global Assurance function. The role ensures AWS maintains rigorous adherence to federal patient privacy and data security regulations (HIPAA/HITECH) and industry frameworks (HITRUST) across our cloud services portfolio, supporting customers and regulated entities that depend on AWS infrastructure.

Key Responsibilities

Conduct, document, and manage internal HIPAA compliance audits to identify vulnerabilities across AWS services and infrastructure.

Develop risk assessment frameworks evaluating technical controls, administrative safeguards, and physical security measures against HIPAA requirements and the HITRUST Common Security Framework.

Partner with internal stakeholders to remediate audit findings and maintain robust control environments.

Leverage HITRUST‑certified AWS services and incorporate AWS certifications for applicable controls within the HITRUST Shared Responsibility Matrix, designing and implementing AWS environments that support customer compliance obligations.

Map customer‑specific control responsibilities to the HITRUST SRM to clarify accountability for inherited versus customer‑managed controls, enabling customers to build HIPAA‑compliant architectures that meet HITRUST CSF requirements.

Collaborate with the HIPAA Security Official to oversee compliance with all requirements of the HIPAA Security Rule.

Work with AWS service teams, security architects, and compliance stakeholders to embed HIPAA requirements into product development lifecycles, providing regulatory guidance during service launches, feature releases, and infrastructure changes that impact healthcare customers.

Design and deliver comprehensive training programs that educate AWS employees, service teams, and customer‑facing personnel on patient privacy obligations and data security best practices.

Basic Qualifications

Bachelor’s degree or equivalent in Information Security, Computer Science, Risk Management, Engineering, Math, Statistics, or a related discipline, or equivalent technology experience.

Experience in one or more of the following domains: access‑control systems and methodology, network security, application and system‑development security, security architecture and models, cryptography, and operations security.

Strong written and oral communication skills for technical and non‑technical audiences.

Strong analytical skills, attention to detail, and effective communication abilities, with experience deploying identity and access management systems.

5+ years of progressive experience in compliance roles, including direct ownership of a HIPAA compliance program at a technology company.

Experience maintaining HITRUST compliance.

Preferred Qualifications

Knowledge of AWS or cloud computing.

Experience in auditing, risk management, compliance, program management, or quality management systems.

Experience working with a matrixed team of stakeholders to achieve a common goal.

Experience mentoring, coaching, and influencing colleagues, collaborators, and stakeholders.

Professional certifications such as Certified in Healthcare Privacy Compliance (CHPC), Certified in Healthcare Information Security and Privacy Practitioner (HCISPP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or equivalent.

Experience working with cloud service providers or technology companies serving healthcare customers.

Knowledge of related healthcare regulations including HITECH Act, 21 CFR Part 11, and state privacy laws.

Experience with regulatory examinations, audits, or enforcement actions.Experience implementing or significantly contributing to compliance automation or GRC tooling integrations.

Benefits & Compensation
The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, optional Supplemental life plans), EAP, mental health support, medical advice line, flexible spending accounts, adoption and surrogacy reimbursement coverage, 401(k) matching, paid time off, and parental leave.

Salary ranges by location:

USA, NY, New York – 131,300.00 – 229,700.00 USD annually

USA, VA, Arlington – 119,300.00 – 208,900.00 USD annually

Amazon is an equal‑opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

#J-18808-Ljbffr