Information Security Manager

4 weeks ago


Karnataka, India American Express Full time

Description

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

Information Security Managers know information technology risk is a top priority for our business, our partners, and customers. As technology risks increase and compliance is rigorously enforced, they strive to stay ahead of what’s next to protect our brand and future. The Risk ID, Assessment & Testing team partners across technology groups to identify risks and assist with control development and metrics to enable continuous control monitoring for business units. It is the Controls Management team’s responsibility to conduct risk assessments across processes and systems as part of enterprise-wide programs such as PRSA and will enable the enterprise to create relevant control types for risk mitigation.

You don’t just see the problem—you’ll drive the solution.

Daily you will be asked to:

  • Partner with technology teams to understand their business processes and corresponding IT process flows to determine risks as well as ensure adequate controls are designed and implemented to mitigate risk.

  • Partner with our second line function to ensure technology teams perform risk identification, assessments, and control implementations to meet second line’s deadlines.

  • Identify and proactively flag areas of high risk for intervention (e.g., automated alerts for near-threshold breach)

  • Utilizing reports, work with our internal clients (technology teams) to meet certification, testing, and other required deadlines.

  • Ensure various compliance requirements (SOX, GLBA, etc.) are met through implementation of controls.

  • Perform Process Risk Self-Assessments on existing new processes within technology business units.

  • Serve as a Subject Matter Expert (SME) for Information Security and Data Protection and Technology risk pillars identified through the Process Risk Self-Assessment activities—provide consulting services on mitigative controls, quality control and other activities to support our Operational Risk Framework

  • Work closely with senior leaders and their representatives to ensure appropriate risk management, mitigation and/or elimination activities are taken, to ensure that deliverables and milestones satisfy objectives and expectations of a variety of stakeholders, including the CIO, CISO, VP and other senior leaders and external stakeholders.

  • Accurately identify, measure, and mitigate areas of process and operational risk.

  • Drive creative thinking to generate process improvements for our team regarding accelerators for our internal clients as well as internal team processes.

Requirements

  • Bachelors in related field

  • CISA, CISM, or CRISC

  • 5 years of relevant experience

  • Requires deep understanding of compliance, risk management and internal IT control frameworks.

  • Expertise with GRC Archer a plus

  • Proven ability to lead without authority.

  • Exceptional ability to engage, educate, influence, and collaborate across the enterprise.

  • Experience with either waterfall or agile software delivery lifecycles.

  • Experience in data analytics to enable process improvement.

  • Strong ability to synthesize large amounts of data into short key messages and identify and analyze related trends.

  • Proven ability to adjust quickly to shifting priorities, multiple demands, ambiguity, and rapid change.

  • Strong interpersonal and collaboration skills / ability to develop relationships with peers in business unit and central operational risk management group.

  • Audit and compliance experience.

  • Ability to meet deadlines in a multi-tasked environment.

  • Exceptional communication skills, both written and presentation

  • ISO 270001 LA / LI preferred.

At the core of Information Security.

Every member of our team must be able to demonstrate the following technical, functional, leadership and business core competencies, including:

  • Agile best practices (understanding the framework and how to apply new controls within such a framework)

  • Emerging technologies (cloud, blockchain, etc.)

  • Analytical thinking (analyzing complex information and/or requests, and identifying the most relevant details)

  • Process improvement

  • Information & Operational risk management

  • Collaboration

  • Industry and company knowledge

  • NIST, ISO, PCI, etc.

  • RSA Archer tool competencies

  • Risk Assessments

  • Stakeholder outreach, engagement, and partnership

Qualifications

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

  • Competitive base salaries

  • Bonus incentives

  • Support for financial-well-being and retirement

  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)

  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need

  • Generous paid parental leave policies (depending on your location)

  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)

  • Free and confidential counseling support through our Healthy Minds program

  • Career development and training opportunities

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.

Job: Technology

Primary Location: India-Karnataka-Bengaluru Urban

Schedule Full-time

Req ID: 24008923



  • Karnataka, India American Express Full time

    Description You Lead the Way. We’ve Got Your Back. With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we...

  • Information Security

    2 weeks ago


    Bengaluru, Karnataka, India Virtusa Full time

    P1,C3,STS Qualifications: 5+ years of relevant professional work experience in Information Security and Technology Risk Management Deep knowledge of compliance, risk management and internal IT control frameworks Broad understanding of information security disciplines with emphasis on vulnerability management, data protection, identity and access, incident...


  • Karnataka, India Aditya Birla Group Full time

    **Updated**:February 08, 2023 **Location**:Karnataka, India **Organization**:Apparels **Key Result Areas** **Supporting Actions** **Information Security Awareness** - Improve Information security among all users **Data Backup Compliance** - Monitor backup of all critical data - Ensure backup of critical data during **Fine Tuning of the Security...


  • Bengaluru, Karnataka, India Vontier Full time

    As the Information Security Architect, you will be an enterprise and technical security architect responsible for helping Vontier and Operating Companies perform security architecture assessment and security consultancy. You will bring enterprise business security architecture principles and best practices to the operating companies' community through...


  • Bengaluru, Karnataka, India Altisource Full time

    **Company Description** At Altisource (NASDAQ: ASPS) we build world-class technologies and services for the mortgage and real estate industry, and are well poised to help revolutionize how homes are bought, sold and managed. In the US, we partner with **7 out of the top 10** mortgage servicers, operate **one of the top three** real estate auction websites,...


  • Bengaluru, Karnataka, India HyringNinja Full time

    **Responsibilities** - Implement, manage, and maintain information security related compliances such as ISO 27001, GDPR, SOC 2 & 3, PCIDSS, etc. - Conduct periodic risk assessments and internal audits. - Maintain compliance related documents across all scoped functions; Provide continuous support to the teams in their compliance journey. - Perform ongoing...


  • Bengaluru, Karnataka, India Exeevo Full time

    **Job description** **Company Overview**: Exeevo is a global cloud solutions provider for life sciences companies to improve how they interact with customers across their organization to provide exceptional experiences that drive commercial objectives and improve patients’ lives. The Exeevo Customer Experience platform leverages Microsoft Cloud for...


  • Bengaluru, Karnataka, India Personnel Search Services Group Full time

    **Posted On**: 12-Feb-2024 **Function**: Technology - IT & Information Security **Industry**: Insurance **Location**: Bengaluru **Employment Type**: Full Time **About the Client**: PSS has been mandated to hire a CISO for a fast-growing Insurance company. **Job Purpose**:Looking for someone responsible for establishing the right security and governance...


  • Bengaluru, Karnataka, India Hewlett Packard Full time

    HP is the world’s leading personal systems and printing company, we create technology that makes life better for everyone, everywhere. Our innovation springs from a team of individuals, each collaborating and contributing their own perspectives, knowledge, and experience to advance the way the world works and lives. We are looking for visionaries, like...

  • Information Security

    2 weeks ago


    Bengaluru, Karnataka, India Applied Materials Full time

    **About Applied** Applied Materials is the leader in materials engineering solutions used to produce virtually every new chip and advanced display in the world. Our expertise in modifying materials at atomic levels and on an industrial scale enables customers to transform possibilities into reality. At Applied Materials, our innovations make possible the...


  • Bengaluru, Karnataka, India Unisys Full time

    **What success looks like in this role**: Responsible for the development, adoption, compliance, and governance of the security strategy, roadmap, and policies that are aligned to the organization’s overall security objectives within a Business Unit (BU). The BISO is a senior leader who is the single point of contact for information security related...


  • Bengaluru, Karnataka, India Altisource Full time

    **Company Description** At **Altisource (NASDAQ: ASPS)** we build world-class technologies and services for the mortgage and real estate industry and are well poised to help revolutionize how homes are bought, sold, and managed. In the US, we partner with** 7 out of the top 10 mortgage** servicers, operate** one of the top three real estate auction**...


  • Bengaluru, Karnataka, India BNP Paribas Full time

    INFORMATION SECURITY PROFESSIONAL (JOB NUMBER: CIB008240) About BNP Paribas India Solutions: Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India...


  • Bengaluru, Karnataka, India Western Digital Full time

    **Company Description** At Western Digital, our vision is to power global innovation and push the boundaries of technology to make what you thought was once impossible, possible. At our core, Western Digital is a company of problem solvers. People achieve extraordinary things given the right technology. For decades, we’ve been doing just that. Our...


  • Bengaluru, Karnataka, India Eurofins Spectro Full time

    **Company Description**: **About Eurofins - the global leader in bio-analysis** Eurofins is Testing for Life. The Eurofins network of companies believes that it is the global leader in food, environment, pharmaceutical and cosmetic product testing and in discovery pharmacology, forensics, advanced material sciences and agroscience contract research...


  • J. P. Nagar, Bengaluru, Karnataka, India TeamPlus Staffing Solution Pvt Ltd Full time

    Troubleshooting L1/L2/L3 tickets and submitting the RCA. Implementing information Security products and submitting the reports. Presenting the appropriate solutions at customer meetings. Keeping well informed of general technical developments, company products and services. Maintaining accurate up to date reporting using the company systems and providing...


  • HSR Layout, Bengaluru, Karnataka, India Acuver Consulting Full time

    **InfoSec Architect** **We are looking for**: - A seasoned and hands-on professional with 6+ years of relevant experience in the IT - InfoSec space - Understands the business requirements, security risks; auditing controls, providing recommendations, and implementing controls to ensure compliance at all times. - An individual having the attitude of a...


  • Bengaluru, Karnataka, India Lowe's Full time

    **About Lowe’s** Lowe's Companies, Inc. (NYSE: LOW) is a FORTUNE® 50 home improvement company serving approximately 17 million customer transactions a week in the U.S. With total fiscal year 2022 sales of over $97 billion, approximately $92 billion of sales were generated in the U.S., where Lowe's operates over 1,700 home improvement stores and employs...


  • Bengaluru, Karnataka, India Lowe's Full time

    **About Lowe’s** Lowe's Companies, Inc. (NYSE: LOW) is a FORTUNE® 50 home improvement company serving approximately 17 million customer transactions a week in the U.S. With total fiscal year 2022 sales of over $97 billion, approximately $92 billion of sales were generated in the U.S., where Lowe's operates over 1,700 home improvement stores and employs...


  • Bengaluru, Karnataka, India Lowe's Full time

    **Job Summary** The primary problem that the Associate Analyst faces is to ensure that while conducting penetration testing and vulnerability testing, those test do not cause harm to any business functionality. Additionally, the Associate Analyst will be challenged with executing standard operating procedures and timelines of engagements as to not conflict...