Talent.com
Technology Audit Director - Cybersecurity

Technology Audit Director - Cybersecurity

AMEXPhoenix, Arizona, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Job Description

Work Location Options :

Hybrid

At American Express, our culture is built on a 175-year history of innovation, shared and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.

Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

How will you make an impact in this role?

American Express Internal Audit Group (IAG) has reinvented our audit process and is leading the financial services industry with our Audit NextGen, Data-Driven Continuous Auditing, and Auditor of the Future initiatives. Each uniquely support our Winning Aspiration to be a world class internal audit function that :

  • Provides data-driven and technology-enabled assurance
  • Delivers timely risk insights that are business-aware and forward-looking
  • Supports our colleagues with experiences that prepare them to be enterprise leaders

Collectively, IAGs strategic initiatives, combined with our greatest asset our people enable IAG to utilize advanced data analysis capabilities, provide greater and continuous assurance, and help ensure quality products and services are provided to American Express customers.

IAGs innovative Data-Driven Continuous Auditing approach has led to patent-pending technology assets over our uniquely developed audit methodology and technology enablers.

We are looking for those who share our mission and aspirations and are passionate about the use of data and technology in a collaborative, people-focused environment.

About the Internal Audit Group at American Express

Our Internal Audit Group is a worldwide function with 300+ team members and offices across nine countries within American Express. Our mission is to protect and enhance organizational value by providing independent, objective, risk-based assurance, advisory services and to influence the way the company manages risk.

We are committed to growing our audit staff significantly as we continue to expand and enhance the Internal Audit Group. Our assurance and risk professionals have diverse backgrounds including internal controls, consumer compliance, technology, operational risk, financial accounting, data analytics, and banking operations. Our audit teams align to key risk areas and business units to ensure IAG can provide comprehensive and risk-based audit coverage. In addition, IAG has a Professional Practices group responsible for managing audit operations, quality, and standards; regulatory relations; reporting; training and professional development; and key internal capabilities and technologies.

About the Role :

Our Internal Audit group is seeking an eager Cybersecurity Audit Director to help advance and grow our audit coverage across our cybersecurity audit portfolio. In this role, the ideal candidate will be the team leader for auditors to provide assurance over areas such as application security, infrastructure security, cybersecurity incident readiness and response, encryption management, and cloud services. This is an exceptional opportunity for you to showcase and further expand your audit skills, and knowledge!

About the Team :

The cybersecurity audit portfolio spans the information technology through the enterprise. Audit coverage includes auditing first-line information security processes. The cybersecurity audit team is heavily focused on utilizing a data driven auditing approach across the audit portfolio.

The Key Responsibilities of the role include :

  • Lead a team of approximately five technology audit colleagues provide internal audit assurance over first-line information security processes, and deliver cybersecurity thought leadership to the team
  • Plan and lead execution of cybersecurity audits on the company annual audit plan
  • Ensure that audits delivery assurance and objectives by setting the audit scope, developing test plans, and leading colleagues to evaluate the design and operating effectiveness of cybersecurity controls, including testing control effectiveness with analytics-based testing
  • Analyze regulatory and industry cybersecurity requirements and frameworks over risk management, technology, and information security
  • Maintain the team's resources, training program, recruiting pipeline, and execute the screening and selection process
  • Monitor a portfolio of cybersecurity audit analytics, assess results, & use data to tell the business story, and work with audit and business colleagues to validate findings
  • Evaluate cybersecurity audit results, synthesize audit findings across the project, draft audit reports and ensure effective and efficient execution of audits in conformance with professional and department standards, budgets, and timelines
  • Present audit objectives, scope, and results to senior management and technology subject matter experts, clearly articulating the potential impact of control gaps in a highly professional and proficient manner
  • Assist other team leaders, senior auditors, and staff auditors in accomplishing team objectives and producing results
  • Execute multiple simultaneous global audit projects of all sizes and complexity across multiple business areas including integrated audits that consider financial, operational, compliance and technology risk
  • Effectively coach, teach, mentor and develop junior colleagues and co-sourced resources in geographically diverse locations across all aspects of their role, the audit and analytic lifecycle, audit methodology, and technology processes & controls
  • Monitor industry cybersecurity trends and emerging risks and propose potential changes to the IAG audit universe to ensure audit coverage evolves with the risk environment
  • Occasionally lead a team of approximately five technology audit colleagues provide internal audit assurance over first-line information technology general control processes
  • Assume full performance management responsibility for assigned staff
  • Minimum Qualifications

  • 7+ years of relevant technology audit experience
  • 4+ years Experience leading audit teams at a Big 4 public accounting firm within the financial services industry OR at a category I, II or III global systematically important bank (GSIB)
  • Experience testing all IT General Control technology control domains
  • BA, BS, or equivalent degree in accounting or technology related field
  • Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP)
  • An industry recognized cloud certification, e.g., ICS2 CCSP, or complete within 12 months of hire date.
  • Knowledge and experience in the application of control theory and professional auditing practices including the audit lifecycle
  • Strong knowledge of information security and infrastructure related terminology and concepts (e.g., zero trust, defense in depth, hybrid cloud, infrastructure as code, virtualization, public key infrastructure (PKI), etc.)
  • Prior experience in applying cybersecurity concepts and controls / countermeasures in public cloud environments (Amazon Web Services, Google Cloud, etc.).
  • Prior experience in analyzing regulatory and industry cybersecurity frameworks (NIST, FFIEC, CRI, MITRE ATT&CK) and applying guidance to audits of cybersecurity controls
  • Demonstrated ability to serve as a cybersecurity mentor or coach to junior team members, including prior experience in creating training materials and delivering cybersecurity training to audit teams and departments
  • Ability to break-down a complex problem into components, solve them using data analysis, process knowledge and risk / control knowledge, and communicate results and control recommendations with transparency and integrity
  • Strong written and verbal communication skills that deliver quality, actionable and beneficial feedback to management on potential control issues and solutions to close gaps.
  • Effectively leads a team in a fast-paced environment to drive business results, utilizing related project management skills, employing creative thinking, and the ability to work on competing priorities
  • Preferred Qualifications

  • Financial services industry strongly preferred
  • 10+ years of relevant technology audit experience
  • BA or BS in Cybersecurity, Information Systems, Computer Science, or related field
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Experience leading teams in technology, cybersecurity, or information security risk management
  • Experience with using data analytic tools, data visualization, key risk indicators (KRIs), key performance indicators (KPIs), and scorecards / dashboards
  • Background in information systems, data analytics or information technology
  • Non-considerations for sponsorship : Employment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions.

    Salary Range : $130,000.00 to $205,000.00 annually + bonus + equity (if applicable) + benefits

    The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, well consider your location, experience, and other job-related factors.

    We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally :

    Competitive base salaries

    Bonus incentives

    6% Company Match on retirement savings plan

    Free financial coaching and financial well-being support

    Comprehensive medical, dental, vision, life insurance, and disability benefits

    Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need

    20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy

    Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)

    Free and confidential counseling support through our Healthy Minds program

    Career development and training opportunities

    For a full list of Team Amex benefits, visit our .

    American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law. American Express will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable state and local laws, including, but not limited to, the California Fair Chance Act, the Los Angeles County Fair Chance Ordinance for Employers, and the City of Los Angeles Fair Chance Initiative for Hiring Ordinance. For positions covered by federal and / or state banking regulations, American Express will comply with such regulations as it relates to the consideration of applicants with criminal convictions.

    We back our colleagues with the support they need to thrive, professionally and personally. That's why we have Amex Flex, our enterprise working model that provides greater flexibility to colleagues while ensuring we preserve the important aspects of our unique in-person culture. Depending on role and business needs, colleagues will either work onsite, in a hybrid model (combination of in-office and virtual days) or fully virtually.

    US Job Seekers - Click to view the poster. If the link does not work, you may access the poster by copying and pasting the following URL in a new browser window :

    Other Jobs You May Be Interested In

    IT Audit Manager

    New York, New York, United States

    Audit Director - Global Commercial Services

    New York, New York, United States

    Audit Director - Change Management

    New York, New York, United States and 2 more

    Senior Manager (m / f / d) Internal Audit, Frankfurt am Main

    Frankfurt am Main, Germany, Germany

    Senior Manager - Sales Process Optimization & Conduct Governance

    New York, New York, United States

    Audit Manager - Financial Crime, Compliance & Conduct

    Madrid, Madrid, Spain

    Manager SOX IT Risk Advisory

    New York, New York, United States

    Senior Manager, GMNS Issues, Events & Remediation

    New York, New York, United States and 1 more

    Senior Manager, GMNS Issues, Events & Remediation

    New York, New York, United States and 1 more

    Slide 1 of 3When you become part of our Talent Community, well keep you posted about future job opportunities that you may be a match for, as well as career-related events.

    serp_jobs.job_alerts.create_a_job

    Director Cybersecurity • Phoenix, Arizona, United States

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Director of Advanced Analytics

    Director of Advanced Analytics

    Arizona State UniversityScottsdale, AZ, US
    serp_jobs.job_card.full_time
    Director Of Advanced Analytics.The Director Of Advanced Analytics Is A Strategic Leadership Role Responsible For Overseeing The Development And Execution Of Advanced Analytics Initiatives To Inform...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Compliance Program Director

    Compliance Program Director

    Sun HealthSurprise, AZ, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Compliance Program Director - Join Our Big-Hearted Team.Are you ready to make a meaningful impact in a vibrant, compassionate community? Join our vibrant team at the. The Compliance Program Director...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Team Manager

    Security Team Manager

    Securitas Security Services USA, Inc.Goodyear, AZ, United States
    serp_jobs.job_card.full_time
    Position : Security Team Manager.Reports To : Datacenter Physical Security Campus Security Manager.The Security Team Manager (STM) serves as the day-to-day manager of a site security team that includ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    System Director TLC Delivery Enablement

    System Director TLC Delivery Enablement

    Common Spirit HealthPhoenix, AZ, US
    serp_jobs.job_card.full_time
    System Director TLC Delivery Enablement.CommonSpirit Health is building a healthier future for all through its integrated health services. As one of the nation's largest nonprofit Catholic healthcar...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Chief Information Security Manager

    Chief Information Security Manager

    StaffingMesa, AZ, US
    serp_jobs.job_card.full_time
    Chief Information Security Manager.Address : Mesa, AZ (Hybrid) Full Time Position Scope of Work : The vCISO shall provide expert virtual cybersecurity services during normal business hours except in ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Team Lead (Warehouse) 2nd Shift

    Team Lead (Warehouse) 2nd Shift

    KOHLERCasa Grande, AZ, US
    serp_jobs.job_card.full_time
    We are growing! Kohler is nearing completion on a new 1 million-square-foot manufacturing facility on 200 acres in the industrial corridor of Casa Grande, AZ. We are looking for passionate talent to...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Data Center Project Manager

    Data Center Project Manager

    IES CommunicationsGoodyear, AZ, United States
    serp_jobs.job_card.full_time
    Must have Data center experience the infrastructure not the running of one.The Project Manager is the overall manager for assigned project(s). The Project Manager ensures that all contracted work is...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Director, Tech Management / ENTECH

    Director, Tech Management / ENTECH

    Banner HealthPhoenix, AZ, United States
    serp_jobs.job_card.full_time
    Director, Tech Management / ENTECH page is loaded## Director, Tech Management / ENTECHlocations : Banner Health Corp Phoenix (2901 N Central Ave) : Banner Boswell Med Ctr (10401 W Thunderbird Blvd)ti...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Vice President of Information Technology

    Vice President of Information Technology

    Sun HealthSun City West, AZ, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Vice President of Information Technology - Join Our Big-Hearted Team.Are you ready to make a meaningful impact in a vibrant, compassionate community? Join our vibrant team at.The Vice President of ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Infrastructure Security Engineer

    Senior Infrastructure Security Engineer

    Vaco by HighspringAvondale, Arizona, United States
    serp_jobs.job_card.full_time
    Vaco has partnered with a Phoenix based client on to support key projects in their technology group.We are seeking a highly skilled, Senior Security / Infrastructure Engineer to lead and support secu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Team Manager (Goodyear)

    Security Team Manager (Goodyear)

    Securitas Security Services USA, Inc.Goodyear, AZ, US
    serp_jobs.job_card.part_time
    Position : Security Team Manager.Reports To : Datacenter Physical Security Campus Security Manager.The Security Team Manager (STM) serves as the day-to-day manager of a site security team that includ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Director of Quality, Performance, Risk, Shared Governance, Az. wide

    Director of Quality, Performance, Risk, Shared Governance, Az. wide

    Southern Medical RecruitersGoodyear, AZ, US
    serp_jobs.job_card.full_time
    Director of Quality, Performance, Risk, Shared Governance, Az.Southern Medical Recruiters is a healthcare / hospital recruitment organization with clients nationwide seeking the best in healthcare ta...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Rad Tech Lead OR FT Days

    Rad Tech Lead OR FT Days

    Abrazo West CampusGoodyear, AZ, United States
    serp_jobs.job_card.full_time
    Up to $15,000 Bonus Based on Eligibility.Welcome to Abrazo Health Network, where making a real difference in people's lives is at the heart of everything we do. Beyond just medical treatments, we be...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Director, Clinical Operations

    Director, Clinical Operations

    ConfidentialMESA, AZ, United States
    serp_jobs.job_card.full_time
    The Director, Clinical Operations is responsible for the clinical operations within the Clinical Contact Center team.Directs all Clinical Contact Center operations. Implements direction and performa...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Director, Enterprise Knowledge Platforms

    Director, Enterprise Knowledge Platforms

    Automatic Data ProcessingTempe, AZ, US
    serp_jobs.job_card.full_time
    Director, Enterprise Knowledge Platforms.Locations : Tempe AZ, Miami FL, Orlando FL, Louisville KY, El Paso TX, Augusta GA, Alpharetta GA, Norfolk VA, Roseland NJ. Are you passionate about delivering...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Network Systems Integrator (OT / IT)

    Network Systems Integrator (OT / IT)

    Vaco by HighspringParadise Valley, Arizona, United States
    serp_jobs.job_card.permanent
    Now backed by a global technology powerhouse, they are actively modernizing their own infrastructure while continuing to deliver innovative solutions to customers. This is not a “keep the lights on”...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_hour
    • serp_jobs.job_card.promoted
    Director, Clinical Operations

    Director, Clinical Operations

    Molina HealthcareMesa, Arizona, US
    serp_jobs.job_card.full_time
    Job Description Job Summary The Director, Clinical Operations is responsible for the clinical operations within the Clinical Contact Center team. Job Duties - Directs all Clinical Contact Center ope...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Network Admin / Engineer

    Network Admin / Engineer

    Vaco by HighspringMaricopa, Arizona, United States
    serp_jobs.job_card.permanent
    We’re partnering with a Christian nonprofit with 50+ years of global impact, to hire a.This role blends hands-on infrastructure work with mission-driven service. They are looking for someone who thr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_hour
    • serp_jobs.job_card.promoted
    Automated AP Specialist

    Automated AP Specialist

    Vaco by HighspringRio Verde, Arizona, United States
    serp_jobs.job_card.full_time
    Automated AP Specialist (HYBRID).Vaco is seeking a detail-oriented and reliable Automated AP Specialist to join our client’s accounting team. The Automated AP Specialist is responsible for managing ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Data Center Project Manager (Goodyear)

    Data Center Project Manager (Goodyear)

    IES CommunicationsGoodyear, AZ, US
    serp_jobs.job_card.part_time
    Must have Data center experience the infrastructure not the running of one.The Project Manager is the overall manager for assigned project(s). The Project Manager ensures that all contracted work is...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days