
Information Security Analyst I
1 day ago
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us deine the future of American Express.
The Global Risk & Compliance (GRC) group within American Express is responsible for providing oversight and governance of risks to ensure that the company operates in a safe and sound manner within regulatory expectations. In a world increasingly subject to digitalization and the use of technology, technology risk management has become increasingly significant across organizations, becoming one of the key themes at board meetings. Cyberattacks have become increasingly commonplace and the trend continues to move upward.
This individual contributor role is part of the second line technology risk management team within the GRC group, headed by the Chief Risk Officer (CRO) of the company. This is a unique opportunity to work with a team of diverse and talented professionals who are responsible for building the technology risk management program and providing independent risk oversight to the Information Technology (IT), Information Security (IS) and Business Continuity management (BCM) risks.
Reporting to the Manager for Cybersecurity, Technology, and Resiliency Risk oversight, this position is responsible for supporting independent assessments and reporting of risks. The risks identified by this team are reported to the Senior Management, Risk Management Committees, Board of Directors, and Regulators. This position will be responsible for effectively collaborating with key stakeholders across lines of business and lines of defense to ensure risks are managed effectively and efficiently in accordance with the company policies and applicable regulatory requirements.
Essential Job Functions:
Assist in identifying and assessing IT and IS risks across applications, infrastructure, and third-party vendors.
Support IT and IS risk assessments and recommend mitigation strategies.
Monitor IT and IS risk trends and emerging threats to provide proactive recommendations.
Assist in the testing and validation of IT and IS controls.
Prepare IT and IS risk reports and dashboards for management review.
Support internal and external audits related to IT and IS risk.
Support the implementation of IT and IS risk management frameworks, policies, standards, and procedures.
Maintain IT and IS risk registers and track remediation efforts for identified risks.
Support independent, proactive risk management and oversight of information technology, information security and business continuity management risks generated within business processes or that occur due to use of Technology.
Support data-driven reviews focused on technology, cyber security, and business continuity management risks.
Support development and enhancement of data-driven key risk indicators and key performance indicators that provide real time and meaningful insights into the risk and performance trends.
Stay knowledgeable of relevant regulations, guidelines & industry standards.
Support the design of independent Information Technology risk oversight program which defines the engagement and integration with various risk management programs, including Risk and Control Self Assessments, Business Continuity Management, New Product Approval, Mergers & Acquisitions etc.
Required Qualifications:
Bachelor's Degree in related field.
3 + years of experience in IT and IS risk management across any of the three lines of defense.
Proven ability to identify risks, analyze issues and derive meaningful insights about risk trends.
by conducting interviews and analyzing large volumes of data.
Excellent analytical skills with high attention to detail and accuracy.
Excellent critical thinking and problem-solving skills.
Excellent verbal, written and interpersonal communication skills.
Willingness to challenge traditional thinking by actively engaging in constructive dialogue.
Preferred:
Educational background: Computer Science or Information Systems.
Experience in risk management across cyber security, information technology, third party, business continuity management.
Working knowledge of one or more of the data mining tools/technologies (e.g., Microsoft Excel: Pivot Tables SQL, SAS, Python, R).
Industry certifications (e.g., CISSP, CISM, CISA, CRISC, ITIL, CBCM, CBCP, CBCI).
Understanding of risk assessment methodologies, frameworks, and industry standards (e.g., COSO, COBIT, ISO 27001, ISO/IEC , ISO 22301, FAIR or NIST RMF).
Knowledge of relevant policies & regulations (e.g., OCC Heightened Standards, FFIEC IT booklets).
Experience with Governance, Risk and Compliance tools (e.g., Archer).
American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.
Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.
-
Senior Security Analyst
1 day ago
Gurugram, India Ahead Full timeSOC Analysts at AHEAD monitor customer environments and perform Incident Detection, Validation, and Incident Reporting. SOC Analysts are the frontline of SOC and are customer-facing representatives. SOC Analysts are responsible for triaging events, incidents, and reporting validated incidents to the customer for incident response. Incumbents will possess...
-
Security Analyst
1 day ago
Gurugram, India ADVATIX - Advanced Supply Chain and Logistics Full timeWe are seeking a highly experienced SOC L3 Analyst to strengthen our Security Operations Center. The ideal candidate will have advanced expertise in monitoring, analyzing, and mitigating cybersecurity threats, as well as managing security tools and mentoring junior analysts. This role involves proactive threat hunting, incident response, and collaboration...
-
Information Security Analyst
2 weeks ago
Gurugram, Noida, India Sonata Software Full time ₹ 9,00,000 - ₹ 12,00,000 per yearRole & responsibilitiesProvide senior level support (document and present strategy, develop, plan, execute) the strategic goals of Security Operations deliverables.Act as technical SME in the area of security and daily operation of XDR, IAM, Firewall, Email Gateway, SIEM, DLP, CASB and other security solutions.Provide technical expertise to maintain...
-
Associate Information Security
2 weeks ago
Gurugram, Haryana, India Orange Mantra Full timeGurgaon - 1 - 2 to 4 years - Full Time **Key Responsibilities**: - Conduct Vulnerability Assessments: - Use various tools and techniques to scan and analyze security weaknesses. - Penetration Testing: - Document and report security issues and vulnerabilities identified during testing. - Security Analysis and Reporting: - Help in analyzing assessment and...
-
IND Analyst I
1 day ago
Gurugram, India Aon Full timeJob Title- IND Analyst I - HCS-Ops Solution Line-TS‐ Talent Solutions Position type- Full Time Work Location-Gurgaon Working style-Hybrid Cab Facility- Yes Shift Time -12PM to 9PM People Manager role:No Required education and certifications critical for the role-Graduate (Except technical graduates) Required Years Of Experience -0-1 Year Of Relevant...
-
Business Information Analyst
1 day ago
Gurugram, India Unified Credit Solution Private Limited Full timeOverview:- We are seeking a meticulous and detail-oriented Business Information Analyst to join our team. The Business Information Analyst will be responsible for conducting discreet telephonic inquiries with various organizations to gather comprehensive operational and financial information. This role requires adeptness in navigating through online...
-
Information Security Officer
1 day ago
Gurugram, India Next Gen Paper Solutions Full timeWhat you'll do We are seeking a highly skilled and motivated Information Security Executive to join our team. The ideal candidate will have in-depth knowledge of ISO 27001, ISO 27701, ISO 27002, ISO 27005, GDPR 2016, and DPDP Act 2023. This role involves preparing and maintaining security policies, processes, and procedures, conducting internal audits, and...
-
L3 Security Incident Analyst
4 days ago
Gurugram, India O A Compserve Pvt Ltd Full timeJob Title : L3 Security Incident AnalystLocation : Gurgaon, IndiaShift : Willingness to work in rotational shifts.Job Description : The L3 Security Incident Analyst is responsible for handling complex security incidents and leading incident response efforts. This role involves advanced threat analysis and strategy development to improve the organizations...
-
Senior Analyst I, Gurgaon
1 day ago
Gurugram, India AML RightSource Full timeJob Description:About AML RightSourceWe are AML RightSource, the leading technology-enabled managed services firm focused on fighting financial crime for our clients and the world. Headquartered in Cleveland, Ohio, and operating across the globe, we are a trusted partner to our financial institution, FinTech, money service business, and corporate clients....
-
L2 Cyber Security Analyst
1 day ago
Gurugram, India gtprod Full timeJob Title: Level 2 Cyber Security Analyst Experience Required: 3-6 Years Location: Work from office (Gurugram) Shift Timing: 24x7 Job Responsibilities: Incident Investigation: Conduct thorough investigations of security incidents using IBM QRadar, ensuring timely and accurate identification, analysis, and resolution of security threats. Support Level 1...