Information Security Analyst I
American Express
You Lead the Way. We’ve Got Your Back.
With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.
At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.
Join Team Amex and let's lead the way together.
How will you make an impact in this role?
The Global Risk & Compliance (GRC) group within American Express is responsible for providing oversight and governance of risks to ensure that the company operates in a safe and sound manner within regulatory expectations. In a world increasingly subject to digitalization and the use of technology, technology risk management has become increasingly significant across organizations, becoming one of the key themes at board meetings. Cyberattacks have become increasingly commonplace and the trend continues to move upward.
This individual contributor role is part of the second line technology risk management team within the GRC group, headed by the Chief Risk Officer (CRO) of the company. This is a unique opportunity to work with a team of diverse and talented professionals who are responsible for building the technology risk management program and providing independent risk oversight to the Information Technology (IT), Information Security (IS) and Business Continuity management (BCM) risks.
Reporting to the Manager for Cybersecurity, Technology, and Resiliency Risk oversight, this position is responsible for supporting independent assessments and reporting of risks. The risks identified by this team are reported to the Senior Management, Risk Management Committees, Board of Directors, and Regulators. This position will be responsible for effectively collaborating with key stakeholders across lines of business and lines of defense to ensure risks are managed effectively and efficiently in accordance with the company policies and applicable regulatory requirements.
Essential Job Functions:
· Assist in identifying and assessing IT and IS risks across applications, infrastructure, and third-party vendors.
· Support IT and IS risk assessments and recommend mitigation strategies.
· Monitor IT and IS risk trends and emerging threats to provide proactive recommendations.
· Assist in the testing and validation of IT and IS controls.
· Prepare IT and IS risk reports and dashboards for management review.
· Support internal and external audits related to IT and IS risk.
· Support the implementation of IT and IS risk management frameworks, policies, standards, and procedures.
· Maintain IT and IS risk registers and track remediation efforts for identified risks.
· Support independent, proactive risk management and oversight of information technology, information security and business continuity management risks generated within business processes or that occur due to use of Technology.
· Support data-driven reviews focused on technology, cyber security, and business continuity management risks.
· Support development and enhancement of data-driven key risk indicators and key performance indicators that provide real time and meaningful insights into the risk and performance trends.
· Stay knowledgeable of relevant regulations, guidelines & industry standards.
· Support the design of independent Information Technology risk oversight program which defines the engagement and integration with various risk management programs, including Risk and Control Self Assessments, Business Continuity Management, New Product Approval, Mergers & Acquisitions etc.
Required Qualifications:
· Bachelor’s Degree in related field.
· 3 + years of experience in IT and IS risk management across any of the three lines of defense.
· Proven ability to identify risks, analyze issues and derive meaningful insights about risk trends.
by conducting interviews and analyzing large volumes of data.
· Excellent analytical skills with high attention to detail and accuracy.
· Excellent critical thinking and problem-solving skills.
· Excellent verbal, written and interpersonal communication skills.
· Willingness to challenge traditional thinking by actively engaging in constructive dialogue.
Preferred:
· Educational background: Computer Science or Information Systems.
· Experience in risk management across cyber security, information technology, third party, business continuity management.
· Working knowledge of one or more of the data mining tools/technologies (e.g., Microsoft Excel: Pivot Tables SQL, SAS, Python, R).
· Industry certifications (e.g., CISSP, CISM, CISA, CRISC, ITIL, CBCM, CBCP, CBCI).
· Understanding of risk assessment methodologies, frameworks, and industry standards (e.g., COSO, COBIT, ISO 27001, ISO/IEC 20000-1, ISO 22301, FAIR or NIST RMF).
· Knowledge of relevant policies & regulations (e.g., OCC Heightened Standards, FFIEC IT booklets).
· Experience with Governance, Risk and Compliance tools (e.g., Archer).
We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:
- Competitive base salaries
- Bonus incentives
- Support for financial-well-being and retirement
- Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- Generous paid parental leave policies (depending on your location)
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities
American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.
Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.