Talent.com
Manager - Information Security

Manager - Information Security

American ExpressNew York, New York, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you’ll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.

Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

Join Team Amex and let's lead the way together.

The Technical Risk Management (TRM) team, within the Global Risk and Compliance organization and led by the Chief Risk Officer, manage operational risks associated with Information & Cyber Security Risk, BusinessDisruption, TechnologyRisk, DataRisk, & AIRisk Management. The team also ensures that risk management activities are conducted in a manner compliant with regulatory requirements and expectations. The team aggregates and reports on key risk management and oversight activities to the relevant management and Board risk committees.

Functional Description :

This individual contributor role is part of the second line technology risk management team within the GRC group, headed by the Chief Risk Officer (CRO) of the company. This is a unique opportunity to work with a team of diverse and talented professionals who are responsible for building the technology risk management program and providing independent risk oversight to the technology, cyber security and data risks.

Reporting to the Director for Technology Risk oversight, this position is responsible for independently assessing, reporting, and aggregating data risks (including data security, data architecture and data storage).The risks identified by this team are reported to the Senior Management, Risk Management Committees, Board of Directors, and Regulators. This position will be responsible for effectively collaborating with key stakeholders across lines of business and lines of defense to ensure data risks are managed effectively and efficiently in accordance with the company policies and applicable regulatory requirements.

Essential Job Functions :

  • Drive cross-functional collaboration with internal stakeholders responsible for data risk management to ensure proactive identification, measurement, management, monitoring, and reporting of data security risks.
  • Provide effective oversight and credible challenge to the 1st line’s implementation of data-related controls within the Risk and Control Self-Assessment (RCSA) and review the design and operating effectiveness of controls linked to data security, availability, and architecture.
  • Contribute to enterprise-wide initiatives focused on enhancing the data risk management framework, information security policies, & security standards. Support development of key risk indicators and key performance indicators that delivers meaningful insights into data security risks and control performance trends.
  • Perform data-driven reviews focused on data risk (including data security, data architecture and data storage) and prepare risk review reports for senior stakeholders and governance bodies.
  • Stay abreast of applicable regulations, guidelines, and industry standards, and drive continuous enhancement of oversight practices to ensure alignment with evolving regulatory expectations and leading practices.
  • Conduct exploratory data analysis on large sets of structure data using industry standard tools (Ex : SQL, Python, Power BI, and Excel data models) to develop meaningful insights on cybersecurity and technology related data.
  • Learn technology, cyber security, and business continuity management processes at American Express, demonstrating strong levels of curiosity and willingness, in order to present an effective credible challenge.
  • Support the design of independent technology risk oversight program which defines the engagement and integration with various risk management programs, including Risk and Control Self Assessments, operational risk event management, operational risk issue management.
  • Help embed a strong risk-aware culture, encouraging proactive risk management behaviors within the organization.

Minimum Qualifications :

  • Minimum five years of experience in data security & risk management within the banking / financial services industry including policy & procedure development, risk appetite, risk control self-assessment and testing, operational event & issue management.
  • Proven ability to identify & assess risks, analyze issues and derive meaningful insights about risk trends by conducting interviews and analyzing large volumes of data.
  • Strong verbal and written communication skills with an ability to
  • explain complex problems and ideas clearly and succinctly to senior

    management.

  • Ability to work in a highly collaborative environment, excellent
  • relationship building skills and ability to influence partners with a firm

    strategic view.

  • Excellent analytical skills with high attention to detail and accuracy.
  • Excellent critical thinking and problem-solving skills.
  • Required self-starter who can work with minimal supervision.
  • Willingness to challenge traditional thinking by actively engaging in constructive dialogue.
  • Preferred :

  • Educational background : Bachelor’s in computer science or information systems.
  • Working knowledge of one or more of the data mining tools and technologies (SQL, Python, Power BI, Excel data models, pivot tables & DAX queries, R)
  • Experience in risk management frameworks and standards across cyber security, data risk, information technology, 3rd party, business continuity management.
  • Industry certifications (e.g., CISSP, CISM, CISA, CRISC, CompTIA Security+)
  • Understanding of risk assessment methodologies, frameworks, and industry standards (e.g., COSO, COBIT, ISO 27001, FAIR or NIST RMF).
  • Knowledge of relevant policies & regulations (e.g., OCC Heightened Standards, FFIEC IT booklets).
  • Experience with Governance, Risk and Compliance tools (Ex : Archer).
  • Salary Range : $110,000.00 to $190,000.00 annually + bonus + equity (if applicable) + benefits

    The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

    We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally :

  • Competitive base salaries
  • Bonus incentives
  • 6% Company Match on retirement savings plan
  • Free financial coaching and financial well-being support
  • Comprehensive medical, dental, vision, life insurance, and disability benefits
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities
  • serp_jobs.job_alerts.create_a_job

    Information Security Manager • New York, New York, United States

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Delivery Manager- Informatics

    Delivery Manager- Informatics

    ZifoTarrytown, NY, US
    serp_jobs.job_card.full_time
    This is a hybrid role that will require regular presence on-site at the client location in Tarrytown, NY.This position is not eligible for relocation assistance. The Informatics Delivery Manager (DM...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Chief Information Security Officer

    Chief Information Security Officer

    Credit GenieNew York, NY, US
    serp_jobs.job_card.full_time
    Credit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future. We leverage artificial intelligence to provide personalized insights a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Infrastructure Project Manager

    Infrastructure Project Manager

    Vertex Solutions Inc.Mineola, NY, United States
    serp_jobs.job_card.temporary
    PM wanted for a 6-12 month contract in the healthcare domain managing infrastructure projects.Will be required to work onsite 3 days a week in Mineola, NY and the other days remote.Project Manager ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Chief Information Security Officer

    Chief Information Security Officer

    City of New YorkNew York, NY, US
    serp_jobs.job_card.full_time
    Chief Information Security Officer.The Department of Records and Information Services is seeking to hire a Computer Systems Manager Non-Manager to serve as the Chief Information Security Officer (C...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Director, Compliance - Testing Team Lead, TD Securities

    Director, Compliance - Testing Team Lead, TD Securities

    TD BankJamaica, NY, US
    serp_jobs.job_card.full_time
    Director Compliance Testing Team Lead.TD has enhanced its Regulatory Compliance Management Framework (RCM) and is implementing new enhancements to existing programs to support a strong risk cultur...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Security Analyst

    Information Security Analyst

    TradeJobsWorkForce10104 New York, NY, US
    serp_jobs.job_card.full_time
    Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Managing Director, Information Risk Management

    Senior Managing Director, Information Risk Management

    Webster BankStamford, CT, US
    serp_jobs.job_card.full_time
    Smd, Information Risk Management.The SMD, Information Risk Management is responsible for the overall design, development, and implementation of the Information Risk Management Framework for Webster...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Director of Information Technology

    Director of Information Technology

    Emerge Talent CloudWhite Plains, NY, US
    serp_jobs.job_card.full_time
    Director Of Information Technology.Must live within commutable distance to White Plains, NY.We are a leading consumer healthcare company focused on building a portfolio of powerful brands that addr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Chief Information Security Officer

    Chief Information Security Officer

    NYC JobsNew York, NY, US
    serp_jobs.job_card.full_time +1
    Computer Systems Manager Non-Manager.The Department of Records and Information Services is seeking to hire a Computer Systems Manager Non-Manager to serve as the Chief Information Security Officer ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Manager, Compliance - Trade Surveillance

    Manager, Compliance - Trade Surveillance

    TD BankFresh Meadows, NY, US
    serp_jobs.job_card.full_time
    The TD Securities US Compliance team is looking for Vice President candidates to join the trade surveillance team, specializing in Fixed Income Products, Foreign Exchange and Commodities, Equities ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Chief Information Security Officer

    Chief Information Security Officer

    Persistent SystemsNew York, NY, US
    serp_jobs.job_card.full_time
    Chief Information Security Officer (CISO).Persistent Systems is seeking a Chief Information Security Officer (CISO) to join our leadership team. The CISO will lead the development and implementation...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineering Lead, Audible Security, Audible Security

    Security Engineering Lead, Audible Security, Audible Security

    Amazon.comNew Brunswick, NJ, USA
    serp_jobs.job_card.full_time
    At Audible, we believe stories have the power to transform lives.It’s why we work with some of the world’s leading creators to produce and share audio storytelling with our millions of global liste...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Chief Information Officer

    Chief Information Officer

    University HospitalNewark, NJ, US
    serp_jobs.job_card.full_time
    The Chief Information Officer (CIO) ensures that technology systems and procedures at University Hospital lead to positive outcomes in line with business, patient, and service goals.The role of the...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Manager, Internal Controls

    Senior Manager, Internal Controls

    KyoceraFairfield, NJ, US
    serp_jobs.job_card.full_time
    When you join Kyocera Document Solutions America, Inc.Philosophy of "doing what is right as a human being".Through this philosophy, our employees are passionate about providing best in class custom...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Information Security Risk Compliance Manager

    Information Security Risk Compliance Manager

    GovServicesHubNew York, NY, us
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Information Security Risk Compliance Manager.Seeks an Information Security Risk Compliance Manager who will have the responsibility for several functions associated with IT security – from ensuring...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Director of Information Security

    Director of Information Security

    MDMS Recruiting LLCNew York, NY, us
    serp_jobs.job_card.full_time +1
    serp_jobs.filters_job_card.quick_apply
    This is a full time / direct hire role.Director of Information Security.This position is responsible for leading and managing all functions within the Information Security Program that involves dev...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Chief Information Security Officer

    Chief Information Security Officer

    DriveWealthNew York, NY, US
    serp_jobs.job_card.full_time
    Chief Information Security Officer.DriveWealth is a global B2B financial technology organization dedicated to democratizing access to financial independence around the world.Our mission is realized...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Technology Incident Manager / Lead

    Technology Incident Manager / Lead

    Capital GroupNew York, New York, United States
    serp_jobs.job_card.full_time
    I can succeed as aTechnology Incident Manager / Lead at Capital Group.As one of our global Operations Command Center (OCC) Technology Incident Managers / Leads you work in a dynamic and challenging env...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.new
    Apptad - Information Security Analyst

    Apptad - Information Security Analyst

    Apptad IncNewark, NJ, United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Information Security Analyst Location - Newark NJ (local preferred) ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Chief Technology Officer (USA)

    Chief Technology Officer (USA)

    Trexquant Investment LPStamford, CT, US
    serp_jobs.job_card.full_time
    We are seeking an experienced technologist to lead and enhance our firm's technology infrastructure.This individual will oversee multiple technology teams, ensuring the implementation of scalable, ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days