Flag job

Report

Manager- Information Security; Technology Risk Governance

Salary

$110k - $190k

Min Experience

3 years

Location

Sandy, Utah, United States, New York, New York, United States

JobType

full-time

About the job

Info This job is sourced from a job board

About the role

Work Location Options:Hybrid You Lead the Way. We've Got Your Back. With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you'll learn and grow as we help you create a career journey that's unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally. At American Express, you'll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company's success. Together, we'll win as a team, striving to uphold our company values and powerful backing promise to provide the world's best customer experience every day. And we'll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong. Join Team Amex and let's lead the way together. How we serve our customers is constantly evolving and is a challenge we gladly accept. Whether you're finding new ways to prevent identity fraud or enabling customers to start a new business, you can work with one of the most valuable data sets in the world to identify insights and actions that can have a meaningful impact on our customers and our business. And, with opportunities to learn from leaders who have defined the course of our industry, you can grow your career and define your own path. Find your place in risk and analytics on #TeamAmex. How will you make an impact in this role? The Global Risk & Compliance Organization ("GRC") is an independent risk management function, led by the Chief Risk Officer, with the objective of ensuring that American Express operates in a safe, sound, and fully compliant manner within all applicable regulatory expectations. GRC creates and maintains the overall risk management framework, performs independent risk management assessments, and monitors applicable risks. Colleagues at GRC are passionate about our commitment to drive the Company's goals of growth and progress by creating a culture of risk awareness and proactivity around regulatory matters. By partnering closely with business units across the enterprise, we help deliver maximum value to our shareholders and our customers through effective risk management and oversight activities. GRC's Cybersecurity, Technology, and Resiliency Risk Oversight (CTRRO) organization is responsible for independent risk management processes over Information Technology, Information Security, and Resiliency risks at American Express. CTRRO is led by the Head of CTRRO & Vendor Risk Oversight. CTRRO is hiring a Manager who will assist in the establishment of new governance and oversight for Technology Risk Policies and Frameworks across American Express. The Manager will also assist with defining and implementing changes to technology risk committees and other forums. The Manager will report to the Technology Risk Governance Director and be part of the team that will own and maintain the technology risk frameworks and associated policies, standards, and procedures. Responsibilities: Assist in the development and management of second line technology policies, standards, and procedures over cybersecurity and technology risks Support committee governance and reporting while working with first line and second line stakeholders on content, accuracy, and timeliness Assist with second line reporting, including quarterly memo and board reporting Participate in technology governance and risk assessment processes to ensure first line adherence to second line policies and standards Partner with technology oversight teams on risk appetite maintenance and reporting and execution of new governance and policies Collaborate on a global team to ensure accurate and timely results Develop strong working relationships with key stakeholders across the organization, handle and resolve conflict on assigned projects Understand and keeping pace with global regulatory expectations and trends for technology risk governance at large banks Minimum Qualifications: Bachelor's degree in business or technology or equivalent Experience with policy development, risk committees, or risk reporting Three years of risk management experience in cybersecurity or technology across one or more lines of defense Three years of experience in the financial services industry Experience participating on and delivering positive outcomes for a global team Strong written and verbal communication skills Ability to effectively manage multiple and often conflicting priorities under tight timeframes and adapt to frequent change Preferred Qualifications: Degree in Cybersecurity, Information Systems, Computer Science, Data Science, or equivalent A cybersecurity, technology, or risk management certification (CISSP, CCSP, CEH, CISM, etc.) Experience with regulatory and industry cybersecurity frameworks and guidance (CRI Sector Profile, NIST, FFIEC, MITRE ATT&CK)

About the company

At American Express, our culture is built on a 175-year history of innovation, shared values and leadership behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.

Skills

cybersecurity
technology
risk management
policy development
risk committees
risk reporting
information security