Information Security Manager

1 week ago


Gurgaon, Haryana, India AMEX Full time

You Lead the Way. Weve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, youll learn and grow as we help you create a career journey thats unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, youll be recognized for your contributions, leadership, and impactevery colleague has the opportunity to share in the companys success. Together, well win as a team, striving to uphold our and powerful backing promise to provide the worlds best customer experience every day. And well do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

Functional Description: The Global Risk & Compliance (GRC) group within American Express is responsible for providing oversight and governance of risks to ensure that the company operates in a safe and sound manner within regulatory expectations. In a world increasingly subject to digitalization and the use of technology, technology risk management has become increasingly significant across organizations, becoming one of the key themes at board meetings. Cyberattacks have become increasingly commonplace and the trend continues to move upward.

Roles & Responsibilities: This individual contributor role is part of the second line technology risk management team within the GRC group, headed by the Chief Risk Officer (CRO) of the company. This is a unique opportunity to work with a team of diverse and talented professionals who are responsible for building the technology risk management program and providing independent risk oversight to the technology, cyber security and business continuity management risks.

Reporting to the Director for Cybersecurity, Technology, and Resiliency Risk Oversight (CTRRO), this position is responsible for independently assessing and reporting risks and providing a view of aggregate risks. The risks identified by this team are reported to the Senior Management, Risk Management Committees, Board of Directors and Regulators. This position will be responsible for effectively collaborating with key stakeholders across lines of business and lines of defense to ensure risks are managed effectively and efficiently in accordance with the company policies and applicable regulatory requirements.

Conduct independent, proactive risk management and oversight of technology, cybersecurity and business continuity management risks generated within business processes or that occur due to use of Technology. Learn technology, cybersecurity, and business continuity management processes at American Express, demonstrating strong levels of curiosity and willingness, in order to present an effective credible challenge. Perform data-driven reviews focused on technology, cybersecurity, and business continuity management risks. Develop and enhance data-driven key risk indicators and key performance indicators that provide real time and meaningful insights into the risk and performance trends. Stay knowledgeable of relevant regulations, guidelines & industry standards. Support the design of independent technology risk oversight program which defines the engagement and integration with various risk management programs, including Process Risk Self Assessments, Business Continuity Management, New Product Approval, Mergers & Acquisitions etc.

Minimum Qualifications: Bachelors Degree in related field 5+ years of experience in risk management across any of the three lines of defense Proven ability to identify risks, analyze issues and derive meaningful insights about risk trends by conducting interviews and analyzing large volumes of data Excellent analytical skills with high attention to detail and accuracy Excellent critical thinking and problem solving skills with minimal supervision Excellent verbal, written and interpersonal communication skills Willingness to challenge traditional thinking by actively engaging in constructive dialogue Educational background: Computer Science or Information Systems Working knowledge of one or more of the data mining tools/technologies (e.g. Microsoft Excel: Pivot Tables SQL, SAS, Python, R) Experience in risk management across cyber security, information technology, 3rd party, business continuity management Industry certifications (e.g. CISM, CISA, CRISC) Understanding of risk assessment methodologies, frameworks and industry standards (e.g. COSO, COBIT, ISO 27001, FAIR or NIST RMF) Knowledge of relevant policies & regulations (e.g. OCC Heightened Standards, FFIEC IT booklets) Experience with Governance, Risk and Compliance tools (e.g. Archer)

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

Competitive base salaries Bonus incentives Support for financial-well-being and retirement Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location) Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need Generous paid parental leave policies (depending on your location) Free access to global on-site wellness centers staffed with nurses and doctors (depending on location) Free and confidential counseling support through our Healthy Minds program Career development and training opportunities

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.



  • Gurgaon, Haryana, India CodeChavo Full time

    Company Description Code Chavo is a global digital transformation solutions provider based in Gurugram.We work closely with the best technology companies to make a real impact through transformation.Powered by technology, inspired by people, and led by purpose, our team partners with clients from design to operation.With deep domain expertise and a...


  • Gurgaon, Haryana, India CodeChavo Full time

    Company DescriptionCodeChavo is a global digital transformation solutions provider based in Gurugram. We work closely with the best technology companies to make a real impact through transformation. Powered by technology, inspired by people, and led by purpose, our team partners with clients from design to operation. With deep domain expertise and a...


  • Gurgaon, Haryana, India Huquo Full time

    JOB TITLE: Information Security SpecialistAre you an experienced Information Security professional looking for an opportunity to make a difference in an organization? We are seeking a dedicated individual with hands-on experience in designing security architecture and implementing various information security technologies. If you are a continuous learner,...


  • Gurgaon, Haryana, India RARR Technologies Full time

    Job Details - Information Security:Job ID: ZISPL Job No 123Job Title: Information SecurityJob Type: PermanentJob Location: GurgaonTotal Experience:YearsSkills: Information SecurityPosted 21/06/2023Job Description:Senior Specialist - Information SecurityReporting to the Associate Director - Security Advisory Services, the Information Security Analyst will be...


  • Gurgaon, Haryana, India Orange Full time

    Manage continuous assessment of security risks. Define and promote security improvement plans and roadmaps. Contribute to improvement and update of OINIS security policy. Monitor and report compliance to security policies and action plans (audits, scans, penetration tests, KPI, document reviews). Assess the sensitivity level of each project. Define security...


  • Gurgaon, Haryana, India Serving Skill Full time

    Position: Network Security SpecialistCompany: SecureTech SolutionsMust have strong expertise in Cloud Security, SOC Experience, Data & Application Security, Incident Management, Identity Theft, NIST, and Baseline Security standards, including Email Security.Relevant certifications such as CISSP, OSCP, CCSP, etc., are mandatory.Proficiency in Data Loss...


  • Gurgaon, Haryana, India OnGrid Full time

    Job Title: Information Security SpecialistCompany: SecureTech SolutionsMain Responsibilities:Develop strong strategies to safeguard the system, network infrastructure, data, and information systems from potential cyber threatsRegularly conduct threat analysis, system evaluations, and security assessmentsDefine and revise information security standards and...


  • Gurgaon, Haryana, India Airtel Full time

    JD for Consultant (Information Security Risk & Compliance) KEY RESPONSIBILITIES & JOB DESCRIPTION Review of policy and procedure with implementation across organization In depth knowledge of risk management with good knowledge of handling external and internal risks Work with cyber risk quantification and integrate with existing risk management...


  • Gurgaon, Haryana, India Beam Suntory Full time

    What makes this a great opportunity? The Cloud Security Analyst is a key member of the Global Information Security team reporting to the Cloud Security Manager. The Cloud Security Analyst will interface with peers in the security team as well as other members of the broader technology team. Beam Suntory is a world class employer that develops talented,...


  • Gurgaon, Haryana, India Ameriprise Financial Full time

    Part of a team that establishes, supports and continuously improves the enterprise information security policies, practices and standards. Participate in on-going operational activities that serve to establish appropriate access to and provide the appropriate protection, confidentiality, integrity and availability of enterprise systems and data through...


  • Gurgaon, Haryana, India Suntory Global Spirits Full time

    Why is this role exciting?The position of Cloud Security Analyst is crucial within the Global Information Security team under the supervision of the Cloud Security Manager. This role involves collaborating with colleagues in the security department and across the wider technology team. Beam Suntory is renowned for nurturing skilled and high-performing...


  • Gurgaon, Haryana, India Suntory Global Spirits Full time

    Why is this role exciting?The position of Cloud Security Analyst is crucial within the Global Information Security team under the supervision of the Cloud Security Manager. This role involves collaborating with colleagues in the security department and across the wider technology team. Beam Suntory is renowned for nurturing skilled and high-performing...


  • Gurgaon, Haryana, India Junglee Games Full time

    As our AVP - Information Security you will foster a security-first culture within the company and help implement solutions that will enhance their overall security posture and user experience by providing adequate awareness training, workshops, information sessions etc.Responsibilities: Lead and manage the Product and Infrastructure security function at...


  • Gurgaon, Haryana, India Sun Life Full time

    Job Description : Information Security Analyst (Band 5) The Information Security Analyst will be responsible for supporting Senior Information Security Advisors within the team in their day-to-day duties. Support work will include, but is not limited to analysis of security documentation/questionnaires from both vendor and internal teams, following up...


  • Gurgaon, Haryana, India Bootes Impex Tech Ltd. Full time

    Company DescriptionBOOTES - India's 1st NET-ZERO Company is a leading construction company based in Gurugram. We are dedicated to accelerating India's transition towards a sustainable and self-sufficient future. Our expertise lies in turn-key projects, from design to project management, and we are at the forefront of the industry's shift towards sustainable...


  • Gurgaon, Haryana, India Canara HSBC Life Insurance Full time

    The primary function of this role is to assist in the development, implementation & enforcement of our privacy policies & procedures within organization in-line with business requirements and prevailing regulatory directions. The role also requires the individual to assist in the design of Information Security controls and ensure that all relevant risks are...


  • Gurgaon, Haryana, India Canara HSBC Life Insurance Full time

    The primary function of this role is to assist in the development, implementation & enforcement of our privacy policies & procedures within organization in-line with business requirements and prevailing regulatory directions. The role also requires the individual to assist in the design of Information Security controls and ensure that all relevant risks are...


  • Gurgaon, Haryana, India Milliman Full time

    Job Summary: We are hiring an Information Security Engineer for our Security Operations team at Milliman. If you are passionate about cybersecurity operations and have a strong knowledge of SIEM technologies, come join us and help us protect our clients and their data from emerging threats while advancing your career in the field of Information Security....


  • Gurgaon, Haryana, India dunnhumby Full time

    dunnhumby is the global leader in Customer Data Science, empowering businesses everywhere to compete and thrive in the modern data-driven economy. We always put the Customer First. Our mission: to enable businesses to grow and reimagine themselves by becoming advocates and champions for their Customers. With deep heritage and expertise in retail –...


  • Gurgaon, Haryana, India Milliman Full time

    Job SummaryWe are looking for a Senior Information Security Analyst with expertise in Network Security, Information Security compliance, control measures, IT infrastructure, and systems administration. As part of the Joint IT Infrastructure team and under the guidance of the IT Manager, the Senior IS Analyst will collaborate closely with both local and...