
Healthcare Assurance Specialist , AWS Compliance & Security Assurance
Amazon Web Services (AWS), Arlington, VA, United States
Overview
AWS is seeking an Assurance and Compliance Specialist to join the Global Assurance function to provide assurance to Healthcare and Lifesciences customers, ensuring adherence to federal patient privacy and data security regulations (HIPAA/HITECH) and industry frameworks (HITRUST) across the cloud services portfolio.
Key Responsibilities
Conduct, document, and manage internal HIPAA compliance audits to identify vulnerabilities across AWS services and infrastructure.
Develop risk assessment frameworks that evaluate technical controls, administrative safeguards, and physical security measures against HIPAA requirements and the HITRUST CSF.
Partner with stakeholders to ensure audit findings are remedied and control environments remain robust.
Leverage HITRUST-certified AWS services and AWS certifications under the HITRUST Shared Responsibility Matrix to design AWS environments supporting customer compliance obligations.
Map customer-specific control responsibilities to the HITRUST SRM to ensure accountability for inherited vs customer‑managed controls, enabling HIPAA‑compliant architectures that meet HITRUST CSF requirements and optimise certification timelines.
Partner with the HIPAA Security Official to oversee AWS compliance with all requirements of the HIPAA Security Rule.
Collaborate with AWS service teams, security architects, and compliance stakeholders to embed HIPAA requirements into product development lifecycles.
Provide regulatory guidance during service launches, feature releases, and infrastructure changes impacting healthcare customers.
Design and deliver comprehensive training programs that educate employees, service teams, and customer‑facing personnel on patient privacy obligations and data security best practices.
Basic Qualifications
Bachelor's degree or equivalent in Information Security, Computer Science, Risk Management, Engineering, Math, Statistics, or related discipline, or equivalent technology experience.
Experience in one or more of the following domains: access control system and methodology, network security, application and system‑development security, security architecture and models, cryptography, and operations security.
Experience creating and delivering written and oral communications for technical and non‑technical audiences.
Strong analytical skills, attention to detail, and effective communication abilities, including experience deploying identity and access management systems.
5+ years of progressive experience in compliance roles, including direct ownership of a HIPAA compliance program at a technology company.
Experience with maintaining HITRUST compliance.
Preferred Qualifications
Knowledge of AWS or cloud computing.
Experience in auditing, risk management, compliance, program management, or quality management systems.
Experience working with a matrixed team of stakeholders to achieve a common goal or equivalent.
Experience mentoring, coaching, and influencing colleagues, collaborators, and stakeholders.
Professional certifications such as CHPC, HCISPP, CISA, CISM, CISSP, or equivalent.
Experience working with cloud service providers or technology companies serving healthcare customers.
Knowledge of related healthcare regulations including HITECH Act, 21 CFR Part 11, and state privacy laws.
Experience with regulatory examinations, audits, or enforcement actions.
Experience implementing or significantly contributing to compliance automation or GRC tooling integrations.
Benefits & Compensation
The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, NY, New York – 131,300.00 – 229,700.00 USD annually
USA, VA, Arlington – 119,300.00 – 208,900.00 USD annually
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information.
Company: Amazon Web Services, Inc.
Job ID: A10402009
#J-18808-Ljbffr
AWS is seeking an Assurance and Compliance Specialist to join the Global Assurance function to provide assurance to Healthcare and Lifesciences customers, ensuring adherence to federal patient privacy and data security regulations (HIPAA/HITECH) and industry frameworks (HITRUST) across the cloud services portfolio.
Key Responsibilities
Conduct, document, and manage internal HIPAA compliance audits to identify vulnerabilities across AWS services and infrastructure.
Develop risk assessment frameworks that evaluate technical controls, administrative safeguards, and physical security measures against HIPAA requirements and the HITRUST CSF.
Partner with stakeholders to ensure audit findings are remedied and control environments remain robust.
Leverage HITRUST-certified AWS services and AWS certifications under the HITRUST Shared Responsibility Matrix to design AWS environments supporting customer compliance obligations.
Map customer-specific control responsibilities to the HITRUST SRM to ensure accountability for inherited vs customer‑managed controls, enabling HIPAA‑compliant architectures that meet HITRUST CSF requirements and optimise certification timelines.
Partner with the HIPAA Security Official to oversee AWS compliance with all requirements of the HIPAA Security Rule.
Collaborate with AWS service teams, security architects, and compliance stakeholders to embed HIPAA requirements into product development lifecycles.
Provide regulatory guidance during service launches, feature releases, and infrastructure changes impacting healthcare customers.
Design and deliver comprehensive training programs that educate employees, service teams, and customer‑facing personnel on patient privacy obligations and data security best practices.
Basic Qualifications
Bachelor's degree or equivalent in Information Security, Computer Science, Risk Management, Engineering, Math, Statistics, or related discipline, or equivalent technology experience.
Experience in one or more of the following domains: access control system and methodology, network security, application and system‑development security, security architecture and models, cryptography, and operations security.
Experience creating and delivering written and oral communications for technical and non‑technical audiences.
Strong analytical skills, attention to detail, and effective communication abilities, including experience deploying identity and access management systems.
5+ years of progressive experience in compliance roles, including direct ownership of a HIPAA compliance program at a technology company.
Experience with maintaining HITRUST compliance.
Preferred Qualifications
Knowledge of AWS or cloud computing.
Experience in auditing, risk management, compliance, program management, or quality management systems.
Experience working with a matrixed team of stakeholders to achieve a common goal or equivalent.
Experience mentoring, coaching, and influencing colleagues, collaborators, and stakeholders.
Professional certifications such as CHPC, HCISPP, CISA, CISM, CISSP, or equivalent.
Experience working with cloud service providers or technology companies serving healthcare customers.
Knowledge of related healthcare regulations including HITECH Act, 21 CFR Part 11, and state privacy laws.
Experience with regulatory examinations, audits, or enforcement actions.
Experience implementing or significantly contributing to compliance automation or GRC tooling integrations.
Benefits & Compensation
The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, NY, New York – 131,300.00 – 229,700.00 USD annually
USA, VA, Arlington – 119,300.00 – 208,900.00 USD annually
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information.
Company: Amazon Web Services, Inc.
Job ID: A10402009
#J-18808-Ljbffr