Amazon logo

Sr. Product Manager - Technical, AWS Governance

Amazon • Seattle, Washington, United States


No Relocation

Posted: October 2, 2026

Description
  • Are you passionate about helping organizations manage governance, risk, and compliance (GRC) at cloud scale? AWS is building a new AI-powered GRC service that delivers continuous compliance, real-time
Description
  • Are you passionate about helping organizations manage governance, risk, and compliance (GRC) at cloud scale? AWS is building a new AI-powered GRC service that delivers continuous compliance, real-time risk quantification, and governance for AI agent workloads. We are seeking a Senior Product Manager – Technical (PMT) to own and drive critical product areas as we scale this service for enterprise adoption. About the Opportunity The GRC market is $60B+ and undergoing a fundamental transformation. Point-in-time audits are becoming untenable as enterprises operate across multi-cloud and hybrid environments that change daily. AI agents are proliferating faster than compliance programs can adapt. No incumbent GRC vendor has a credible solution for continuous, AI-native governance. AWS is uniquely positioned to win here — and we're building the team to make it happen. In this role, you will own the product strategy, roadmap, requirements, and go-to-market for a core set of capabilities within a new cloud-native GRC service. You will work backwards from enterprise GRC buyers — compliance officers, risk managers, CISOs, and audit teams — to define what we build and why. You will partner with engineering, science, UX, marketing, sales, and legal to deliver capabilities that win in a competitive and rapidly evolving market. This is a high-ownership role. You will define the product vision for your area, author PRFAQs and requirements documents, make pricing and packaging decisions, and drive adoption post-launch. You will operate at the intersection of deep domain expertise in compliance/audit/risk and strong technical product management fundamentals. Key job responsibilities Leverage deep audit and compliance expertise — direct experience conducting, managing, or overseeing audits — to define product requirements that solve real practitioner pain points Own the product strategy and roadmap for a core domain within a new AI-powered GRC service — from vision through delivery and adoption Work backwards from enterprise GRC customers to define requirements, acceptance criteria, and prioritization Author PRFAQs, pricing narratives, and requirements documents that align engineering execution with customer outcomes Partner with engineering leads to make architecture tradeoffs, scope MVPs, and drive sprint-level execution through a multi-pod organization Define and drive go-to-market strategy including positioning, sales enablement, customer onboarding, and partner ecosystem plays Leverage deep domain knowledge of compliance standards (SOC 2, ISO 27001, PCI-DSS, HIPAA, NIST, EU AI Act), audit workflows, and risk management to inform product decisions Analyze market trends, competitive landscape, and customer telemetry to identify opportunities and inform prioritization Work cross-functionally with marketing, field sales, solution architects, professional services, and GSI partners to drive enterprise adoption Represent the service in customer meetings, industry events, and executive reviews Influence cross-AWS strategy by collaborating with adjacent governance and security teams to deliver integrated experiences A day in the life On a typical day, you might review customer feedback from a Fortune 500 enterprise, author a requirements for a new capability, meet with engineering to finalize scope for the next release train, join a customer call with a solution architect to understand an auditor's workflow, analyze service telemetry to identify adoption blockers, and sync with marketing on positioning for an upcoming industry event. You will work across time zones with a globally distributed team. The pace is fast, the problems are complex, and the opportunity is massive — you'll be defining a new category in cloud-native GRC.
Basic Qualifications
  • - Bachelor's degree - 7+ years of hands-on experience in audit, compliance, or risk management — conducting audits, managing compliance programs, implementing GRC frameworks (SOC 2, ISO 27001, PCI-DSS, HIPAA, NIST CSF, FedRAMP), or leading enterprise GRC functions - 3+ years of product management or product strategy experience (or demonstrated trajectory into product roles) - Deep practitioner knowledge of audit workflows, evidence collection, control testing, and remediation processes - Experience with enterprise SaaS tools in the GRC space (as a user, buyer, or implementer) - Strong written communication skills with experience authoring strategy documents for senior leadership
Preferred Qualifications