AWS Third-Party Risk Management (TPRM) is seeking a Risk Specialist to join our team within Risk Management Excellence (RMX). In this role, you will serve as a key operator within the TPRM program, responsible for monitoring, assessing, and reporting on risks associated with AWS's critical third-party ecosystem.
You will manage ongoing risk surveillance through the Sentinel platform, produce executive-level risk intelligence reports, support regulatory audits, lead financial viability assessments, and coordinate incident response documentation. This is a highly cross-functional role that partners with AWS service teams, legal, compliance, supply chain, and external vendors to ensure third-party risks are identified, measured, and mitigated.
The ideal candidate is a self-starter with strong analytical skills, an eye for process improvement, and comfort navigating ambiguity in a fast-moving cloud infrastructure environment.
Key job responsibilities
You will monitor third-party risk alerts and escalate issues as they arise, ensuring risks are identified and addressed quickly. You will own the monthly risk report from draft through executive distribution, and track key metrics that measure program health. You will produce on-demand risk profiles for internal stakeholders using financial intelligence platforms and AI-assisted tooling. You will lead financial viability assessments for critical vendors-collecting due diligence reviews, distributing risk surveys, and scoring financial health-while partnering with engineering to automate data collection. You will serve as the team's point of contact for regulatory and customer audits, and document third-party incidents in coordination with security operations. You will also drive vendor reassessments, process risk nominations for new and existing third parties, and participate in launch reviews for new AWS services. Throughout, you will look for ways to streamline operations through automation, tooling improvements, and well-maintained runbooks.
A day in the life
You start the day triaging Sentinel alerts and actioning third-party risk indicators-executing overrides, updating logs, and filing tickets. Midday, you shift to project work: pulling financial health data for a viability assessment, drafting a risk summary for a stakeholder request, or coordinating audit evidence with a program manager. You may join a cross-functional call with Legal or Supply Chain on an open incident. Afternoons are for reporting and improvement-updating reassessment trackers, compiling the flash report, or partnering with engineering on an automation that saves the team hours each week.
BASIC QUALIFICATIONS
- Bachelor's degree or equivalent
- 3+ years of compliance program management, legal, governance, audit, risk/loss prevention, or equivalent experience
- Demonstrated understanding of ERM and/or TPRM frameworks
PREFERRED QUALIFICATIONS
- Professional auditing qualification, or similar risk or compliance credentials
- Experience with SQL and Excel
- Familiarity with one or more of the following regulatory regimes: DORA, UKCTP, US Federal Banking Agency requirements, or equivalent financial services regulations
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, VA, Arlington - 74,200.00 - 129,800.00 USD annually
USA, WA, Seattle - 82,700.00 - 129,800.00 USD annually