Information Security Manager

20 hours ago


India American Express Full time

You Lead the Way Weve Got Your Back With the right backing people and businesses have the power to progress in incredible ways When you join Team Amex you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers communities and each other Here youll learn and grow as we help you create a career journey thats unique and meaningful to you with benefits programs and flexibility that support you personally and professionally At American Express youll be recognized for your contributions leadership and impactxe2x80x94every colleague has the opportunity to share in the companys success Together well win as a team striving to uphold our and powerful backing promise to provide the worlds best customer experience every day And well do it with the utmost integrity and in an environment where everyone is seen heard and feels like they belong Join Team Amex and let s lead the way together The Information Security Manager role is part of the third-party security team within Technology Risk Information Security TRIS and is responsible for security control enforcement awareness and enablement of American Express standard controls at 3rd party environment This position reporting to the Director of Information Security is responsible for assessing the information security risk associated with Third Parties and facilitating and or performing information security assessments of those Third Parties The person in this position will be responsible for managing third party security risk specifically focused on aspects of assessing monitoring providing risk expertise on security control domains process uplift recommendations and providing professional guidance to key stakeholders of the program on information security aspects The ideal candidate for this role has an extensive background in risk management Audit Information Security They are dynamic with the ability to manage a fluctuating workload with competing deadlines The candidate is highly inquisitive with a healthy dose of cautiousness has a broad-based perspective and thrives on building a network of internal and external alliances S he has highly developed communication skills excellent time management and an acute attention to detailResponsibilities Partner with the BU to complete third party risk assessments and ensure adherence to program requirements Assist with risk analysis and security posture evaluations of Third Parties to support security assessment activities including vulnerability threat assessments Execute or facilitate execution of information security assessments for in-scope third parties assess the quality of assessments conducted by External Assessors define risk ratings as appropriate to the control failures etc Review and evaluate the security controls of third-party vendors to ensure they align with the AXPs security standards and explains control requirements to the business colleagues and third parties as appropriate Partner with other colleagues in third party security team in sharing inputs towards third party assessment questionnaires and Guidance documents Conduct training and awareness sessions for internal stakeholders on third-party security risks and best practices Be an Information Security Risk Expert for team and other stakeholders Foster strong relationships with Business colleagues and TLM team to promote security best practices and collaboration Support with security and compliance initiatives as led by third party security team Requirements Qualification Thorough knowledge of information security components principles practices and procedures Information security specialist with 8 years of experience A broad understanding of the IT controls and best practices across key risk domains including risk assessment methodology application security network and infrastructure security Data loss prevention and incident management is recommended Prior experience managing risk assessments including background in audit information security Third Party Risk Oversight or other risk control functions Strong knowledge of information security frameworks e g NIST ISO 27001 and regulatory requirements Proficiency in risk assessment methodologies and third-party risk management tools Attention to Detail Careful evaluation of vendor security practices and documentation Excellent communication negotiation and stakeholder management skills able to effectively communicate at all levels within the organization Being flexible and able to adjust to new needs and new technologies and be comfortable with ambiguity Strategic Thinking Ability to align third-party security with broader organizational objectives Relevant certifications such as CISSP CISM CISA CRISC ISO 27001 are preferred Compliance LanguageWe back our colleagues and their loved ones with benefits and programs that support their holistic well-being That means we prioritize their physical financial and mental health through each stage of life Benefits include Competitive base salaries Bonus incentives Support for financial-well-being and retirement Comprehensive medical dental vision life insurance and disability benefits depending on location Flexible working model with hybrid onsite or virtual arrangements depending on role and business need Generous paid parental leave policies depending on your location Free access to global on-site wellness centers staffed with nurses and doctors depending on location Free and confidential counseling support through our Healthy Minds program Career development and training opportunities American Express is an equal opportunity employer and makes employment decisions without regard to race color religion sex sexual orientation gender identity national origin veteran status disability status age or any other status protected by law Offer of employment with American Express is conditioned upon the successful completion of a background verification check subject to applicable laws and regulations We back our colleagues and their loved ones with benefits and programs that support their holistic well-being That means we prioritize their physical financial and mental health through each stage of life Benefits include Competitive base salaries Bonus incentives Support for financial-well-being and retirement Comprehensive medical dental vision life insurance and disability benefits depending on location Flexible working model with hybrid onsite or virtual arrangements depending on role and business need Generous paid parental leave policies depending on your location Free access to global on-site wellness centers staffed with nurses and doctors depending on location Free and confidential counseling support through our Healthy Minds program Career development and training opportunities American Express is an equal opportunity employer and makes employment decisions without regard to race color religion sex sexual orientation gender identity national origin veteran status disability status age or any other status protected by law Offer of employment with American Express is conditioned upon the successful completion of a background verification check subject to applicable laws and regulations



  • India WTW Full time

    202505928 - India - Mumbai, Maharashtra, India - Bevorzugt **Description**: - Build and maintain effective relationship with technology teams and ICS stakeholders - Foster a culture of information and cyber security best practices though awareness and support - Hold good understanding of Application & Infrastructure testing methodology & support...


  • India NConsulting Full time

    Role Information Security EngineerLocation Gurugram Gr Noida HYD Pune BangaloreExperience 6 YearsNotice 15 DaysFTE or SubconISO Ceritified with 1 certification is mandatory CISSP CCSP GSEC C EH CSSLP OSCP Assists and or leads various information security projects and initiatives throughout the year which may include scoping execution ...


  • India Siemens Healthineers Full time

    jobid - 467663 jobfamily - Cybersecurity company - Siemens Healthcare Private Limited organization - Siemens Healthineers jobType - Full-time experienceLevel - Experienced Professional contractType - Permanent **Siemens Healthineers**develops MedTech products that support better patient outcomes with greater efficiencies, giving providers confidence...


  • India beBeeInformationSecurity Full time ₹ 1,43,68,000 - ₹ 2,03,44,000

    As a strategic Business Analyst, you will play a pivotal role in bridging the gap between technical and business environments. Leveraging data analytics, you will enhance information security services by evaluating the effectiveness of existing measures.Key Responsibilities:Collecting and analyzing data to assess the efficiency of information security...


  • India beBeeCybersecurity Full time ₹ 1,50,00,000 - ₹ 2,50,00,000

    We are seeking a seasoned Cyber Security professional to join our organization in Gurgaon. As a key member of our team, you will be responsible for developing and implementing comprehensive security strategies to protect our IT infrastructure.Key ResponsibilitiesLeverage existing cybersecurity tools and identify open-source solutions to discover threat agent...


  • India Angel broking Full time

    **About Us**: **About The Role**: About Angel one: We have a flat structure, with ample opportunity to showcase your talent and a growth path for engineers to the very top. We are aggressively hiring Engineers, Product Managers & Data science rockstars across India. Join our team and experience the best of both worlds at Angel One! Check out our careers...


  • India beBeeInformation Full time ₹ 6,00,000 - ₹ 15,00,000

    Job Title: Information Security ProfessionalKey Responsibilities:Monitor and analyze security events and incidents using various security tools, including Checkpoint EDPR (Endpoint Detection, Prevention and Response) tool, Data Leakage Prevention (DLP) security events monitoring and response, and other security monitoring platforms.Analyze security alerts...


  • India beBeeCybersecurity Full time ₹ 2,00,00,000 - ₹ 2,50,00,000

    About our organization:We provide comprehensive title insurance, closing/settlement, property data and technology solutions.Our goal is to create quality solutions for our customers by combining software, back office and knowledge processing operations to fulfill our business requirements.Our priorities are our employees, customers, and stakeholders - in...

  • Executive Ii

    2 weeks ago


    India Asian Paints Full time

    **Business Responsibility Areas**: - Lead the SOC Delivery along with Partner. End to End Security Event Analysis and Troubleshooting. - New Device Integration, Validating Current Use Cases and Improvising. - Well Verse with EDR, UEBA, Network & Security Event Analysis. - Next Generation SOC Evaluation and Implementation. - Automating Security threats to...


  • India Paramount Computer Systems Full time

    Job DescriptionJob Description:1. The Associate Infosec Consultant is responsible for supporting the development, implementation, and management of Information Security Management Systems (ISMS), UAE ISR, BCMS, Statutory requirements and GRC frameworks for client organizations.2. This role involves conducting risk assessments, ensuring compliance with...