Assurance Specialist - Healthcare, AWS Compliance & Security Assurance
Amazon · New York City, NY · Project/Program/Product Management--Non-Tech
About this role
Amazon is hiring a mid-level Security Analyst based in New York City, NY. The posting calls out experience with AWS, Networking, Security, Encryption. Compensation is listed at $131,300–$229,700 per year.
- Role
- Security Analyst
- Function
- security
- Level
- mid
- Track
- Individual contributor
- Employment
- Full-time
- Location
- New York City, NY
- Department
- Project/Program/Product Management--Non-Tech
- Posted
- Apr 23, 2026
More roles at Amazon
Job description
from Amazon careersAmazon Web Services (AWS) is seeking an Assurance and Compliance Specialist to join our Global Assurance function to provide assurance to Healthcare and Lifesciences customers. This role will ensure AWS maintains rigorous adherence to federal patient privacy and data security regulations (HIPAA/HITECH) and industry frameworks (HITRUST) across our cloud services portfolio, supporting customers and regulated entities that depend on AWS infrastructure. Key job responsibilities Risk Assessment and Audit Management — Conduct, document, and manage internal HIPAA compliance audits to identify vulnerabilities across AWS services and infrastructure. Develop risk assessment frameworks that evaluate technical controls, administrative safeguards, and physical security measures against both HIPAA requirements and the HITRUST Common Security Framework (HITRUST CSF). Partner with internal stakeholders to ensure audit findings are remediated effectively, and control environments remain robust. Leverage HITRUST-certified AWS services and inherit AWS certifications for applicable controls under the HITRUST Shared Responsibility Matrix (SRM) to design and implement AWS environments that support customer compliance obligations. Map customer-specific control responsibilities to the HITRUST SRM to ensure clear accountability for inherited AWS controls versus customer-managed controls, enabling customers to build HIPAA-compliant architectures that meet HITRUST CSF requirements while optimizing their certification timelines and audit scope. HIPAA Security Rule Compliance Support…