Director Information Security

3 weeks ago


Bengaluru, Karnataka, India American Express Full time

You Lead the Way. We've Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you'll learn and grow as we help you create a career journey that's unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you'll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company's success. Together, we'll win as a team, striving to uphold our and powerful backing promise to provide the world's best customer experience every day. And we'll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together .

Responsible for owning the development and/or delivery of information security initiatives, projects, or programs that have objectives associated with preserving the confidentiality, integrity, and availability of systems and data across the enterprise. Responsible for designing and implementing processes to understand, measure, and improve the organization's ability to avoid data exfiltration, corruption, or other exploitation.

Develops and executes end-to-end information security and IT risk management processes that are optimized for maturity. Works across many organizations, both internal and external, to meet business needs and compliance goals. Leads cross department initiatives, covering a wide range
of business/technical functions.

How will you make an impact in this role?

American Express is on an exciting Cloud transformation led by a high-energy, delivery-focused teamdelivering security as code and integration to enable on-premise equivalent security models for cloud workloads. The Cloud Security Engineeringgroup builds and deliverstechnology which enables shift left security integration through partnership and collaboration across Technology Risk and Information Security, as well as multiple Technology teams. The Director Cloud Security Engineeringwill lead the program, design, and develop tools to deliver security controls for the enterprise, and will ensure the success of the American Express journey towards hybrid multi cloud.The Director and their team will be accountable for securely enabling the cloud journey through a delivery-based programbased on automation and guardrail-based approaches.

To be successful, you and your team will work very closely with other Technology Risk and Information Security functions, as well as Cloud Security Governance, Cloud Security Architecture, Cloud Operations, and many other Technology and non-Technology teams to identify, solution, and deliver security code elements. You will mature a program which aims to drive automation, zero touch, and idempotency through "everything-as-code" across cloud platforms and infrastructure components. This position demands a well-organized; action-oriented team player with the ability to prioritize daily work; work on multiple initiatives simultaneously; establish and maintain an outward looking view on new and evolving network edge technologies; and an ability to mature and operate business critical, end-to-end processes and solutions – while ensuring a great colleague user experience.

Design and mature a Cloud Security Engineering program created to deliver security code elements across private and public multi-cloud Provide security and engineering expertise and guidance to the Cloud Programs, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Secure Software Development Lifecycle, and Cloud Application Architecture subprograms. Collaborate with platform engineers, enterprise architects and SMEs to deliver complete security controls for public cloud, Kubernetes, and software supply chains, architecture solutions. Lead Cloud Security engineering team which designs and develops tools to delivery security requirements for the enterprise. Own all technical aspects of software development (architecture, design and development of systems) for assigned applications. Lead a team who delivers hands-on software development, typically spending about 80% of time writing code, APIs, doing proof of concepts and conducting code reviews Identify exciting opportunities for adopting new technologies to solve existing needs and predicting future challenges.

Minimum Qualifications

 7+ years of software development experience using any of the following languages: Java, JavaScript (Node.js), Python, Golang (2+ years minimum). Must have a deep understanding of the language and its ecosystem. 3+ years of experience in Information Security roles with increase of responsibilities and scope. 5 years of experience using one or more prominent software frameworks. Demonstrated experience in a manager-level role. Understanding of classical or cloud-native design patterns is required. Kubernetes and Infrastructure as Code is required.  Understanding of Cloud Native security controls, including organizational policies.  Knowledge of security configuration management, container security, endpoint security and secrets management as they are applied to cloud applications. Knowledge of network architecture, proxy infrastructure, and programs to support network access and enablement. Knowledge of secure software development lifecycles and secure software supply chains. Demonstrated ability to manage large financial portfolios, specifically managing year-over-year budget for BAU operations, new investments and contract renewals. Capture requirements; build functional specifications, timelines, adoption plans and other artifacts to support security implementation. Partner with Architecture teams to build cloud-optimized security patterns and contribute to Enterprise Architecture governance. Partner with and support the Governance team to drive and execute results in a timely manner. Experience with multiple Information Security domains, such as Infrastructure Vulnerability, Data Loss Prevention, End User Security, Network Security, Internet Security, Identity & Access Management, etc. Bachelor's Degree in computer science, computer engineering, or related field; or equivalent experience. Information Security or Cloud Certification preferred - CISSP, CISM, CCSP, CKS or similar. Cloud Engineering or Security Certification preferred – AWS Certified DevOps Engineer Professional, AWS Certified Security Specialty, GCP Cloud DevOps Engineer, GCP Cloud Security Engineer or similar 

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

Competitive base salaries  Bonus incentives  Support for financial-well-being and retirement  Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)  Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need  Generous paid parental leave policies (depending on your location)  Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)  Free and confidential counseling support through our Healthy Minds program  Career development and training opportunities

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.



  • Bengaluru, Karnataka, India Vervent Full time

    Job DescriptionWe are seeking an experienced and skilled Director of Information Security to join our team at Vervent. As a leading fintech company, we deliver expertise, technology, and services to our industry-leading partners. Our goal is to empower companies to accelerate business, drive compliance, and maximize service.The Director of Information...


  • Bengaluru, Karnataka, India Trilegal Full time

    JOB TITLE: Director - Information SecurityLocation: Bengaluru/ Mumbai/ DelhiRole Summary:The Chief Information Security Officer (CISO) will lead the organization's information security strategy, ensuring the protection of data, systems, and networks. CISO will provide technical and administrative guidance on information security concerns and advocate for...


  • Bengaluru, Karnataka, India Trilegal Full time

    Director - Information Security The Chief Information Security Officer (CISO) will lead the organization's information security strategy, ensuring the protection of data, systems, and networks. CISO will provide technical and administrative guidance on information security concerns and advocate for strategies to minimize business risks for the firm and its...


  • Bengaluru, Karnataka, India Vervent Full time

    Position Overview:- We are seeking a highly skilled and experienced Director - Information Security to lead and manage our comprehensive Information Security Program.- This pivotal role will report directly to the Chief Technology Officer (CTO) and will be responsible for establishing, maintaining, and overseeing the company's information security...


  • Bengaluru, Karnataka, India Vervent Full time

    Position Overview:We are seeking a highly skilled and experienced Director – Information Security to lead and manage our comprehensive Information Security Program. This pivotal role will report directly to the Chief Technology Officer (CTO) and will be responsible for establishing, maintaining, and overseeing the company's information security strategies,...


  • Bengaluru, Karnataka, India Cerulean Information Technology Pvt Ltd Full time

    Key ResponsibilitiesThe Senior Information Security Engineer will be responsible for evaluating and reviewing security risks for enterprise networks in a fast-paced environment.Perform network security assessments and architecture reviews, identifying weaknesses and proposing solutions to address them.Continuously monitor and assess the security posture of...


  • Bengaluru, Karnataka, India ANSR Full time

    Role OverviewThe Security Operations Director will be responsible for leading the development and implementation of ANSR's overall security strategy, ensuring the protection of its people, assets, and facilities across India.Main Responsibilities:Develop and implement a comprehensive security program that aligns with business objectives and ensures...


  • Bengaluru, Karnataka, India Nike Full time

    Rejoignez l'équipe NIKE, Inc. Loin de se contenter d'équiper les plus grands athlètes mondiaux, NIKE, Inc. explore les potentiels, abolit les frontières et repousse les limites du possible. L'entreprise recherche des personnes capables d'évoluer, de réfléchir, de rêver et de créer. L'épanouissement de sa culture repose sur son ouverture à la...

  • Director, IT Security

    4 weeks ago


    Bengaluru, Karnataka, India Allucent Full time

    t Allucent, we are dedicated to helping small-medium biopharmaceutical companies efficiently navigate the complex world of clinical trials to bring life-changing therapies to patients in need across the globe.We are looking for a Director, IT Security & Network to join our A-team (hybrid*). The Director, Network and Security will be responsible for...


  • Bengaluru, Karnataka, India e-Hireo Global Solutions Full time

    e-Hireo Global Solutions is seeking a highly skilled Cyber Security Director to oversee and manage the activities of our cybersecurity team. The ideal candidate will have extensive experience in digital forensic analysis, incident response, and threat detection.The successful Cyber Security Director will be responsible for coordinating efforts across various...


  • Bengaluru, Karnataka, India Four Seasons Hotels Full time

    About Four Seasons Four Seasons is powered by our people We are a collective of individuals who crave to become better to push ourselves to new heights and to treat each other as we wish to be treated in return Our team members around the world create amazing experiences for our guests residents and partners through a commitment to luxury with genuine...


  • Bengaluru, Karnataka, India Tableau Full time

    About UsSalesforce is a global leader in customer relationship management, helping businesses of all sizes connect with their customers, partners, and employees in a whole new way. Our mission is to empower every business on earth to achieve its dreams through our technology.The Network Security team is responsible for designing, building, and maintaining...


  • Bengaluru, Karnataka, India CorroHealth Full time

    Job DescriptionGreetings from Corrohealth,COMPANY PROFILE:CorroHealth is the leading provider of clinically led healthcare analytics and technology-driven solutions, dedicated to positively impacting the financial performance for physicians, hospitals, and health plans. With over 12,000+ employees worldwide, CorroHealth offers integrated solutions, proven...


  • Bengaluru, Karnataka, India MAX Security Full time

    About UsMAX Security is a leading global risk management organization with a strong presence in Tel Aviv, Israel, and our Asia-Pacific headquarters in Mumbai. Our team consists of highly experienced professionals from various backgrounds, including the Israeli Military Special Forces, Intelligence, Cyber, and Secret Services.We operate in over 160 countries...


  • Bengaluru, Karnataka, India Oracle Full time

    Job SummaryWe are seeking an Information Security Professional to join our team. The ideal candidate will have a strong background in information security, with expertise in designing and implementing secure systems and applications.ResponsibilitiesDevelop and maintain information security policies and proceduresCollaborate with cross-functional teams to...


  • Bengaluru, Karnataka, India Trilegal Full time

    As an experienced Information Security Leader, you will be responsible for overseeing information security, data privacy, and BYOD policies at Trilegal. You will ensure that our security standards align with industry best practices and develop comprehensive information security strategies, policies, and procedures.Responsibilities:Information Security...


  • Bengaluru, Karnataka, India HyrEzy Talent Solutions Full time

    Roles & Responsibilities (BSc. IT, BE) with Information Security Certifications - CISM, CISSP EXPERIENCE : - Candidate must have strong experience in Information Security Management system, Policy & procedures creation, implementation - ISO27001 assessment - Specification for a framework of policies procedures that include all technical & operational...


  • Bengaluru, Karnataka, India State Street Corporation Full time

    Job Overview:We are seeking an experienced Information Security Administrator to join our team at State Street Corporation. The ideal candidate will have a strong background in information security, excellent communication skills, and the ability to work effectively in a fast-paced environment.Main Responsibilities: Collaborate with business units to ensure...


  • Bengaluru, Karnataka, India myGwork Full time

    This job is with State Street, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. Role Summary & Role Description The Information Security Administrator (ISA) will support business units in their efforts to comply with GCS security policy and required...


  • Bengaluru, Karnataka, India State Street Corporation Full time

    Job DescriptionRole Summary & Role DescriptionThe Information Security Administrator (ISA) will support business units in their efforts to comply with GCS security policy and required controls. Working with direction from the Senior Information Security Officer (Sr. ISO) or ISO, the ISA will provide critical support for the first line of defense (employees...