
Information Security Manager
3 days ago
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express
The Technical Risk Management (TRM) team, within the Global Risk and Compliance organization and led by the Chief Risk Officer, manage operational risks associated with Information & Cyber Security Risk, Business Disruption, Technology Risk, Data Risk, & AI Risk Management. The team also ensures that risk management activities are conducted in a manner compliant with regulatory requirements and expectations. The team aggregates and reports on key risk management and oversight activities to the relevant management and Board risk committees.
Functional Description:
This individual contributor role is part of the second line technology risk management team within the GRC group, headed by the Chief Risk Officer (CRO) of the company. This is a unique opportunity to work with a team of diverse and talented professionals who are responsible for building the technology risk management program and providing independent risk oversight to the technology, cyber security and data risks.
Reporting to the Director for Technology Risk oversight, this position is responsible for independently assessing, reporting, and aggregating data risks (including data security, data architecture and data storage). The risks identified by this team are reported to the Senior Management, Risk Management Committees, Board of Directors, and Regulators. This position will be responsible for effectively collaborating with key stakeholders across lines of business and lines of defense to ensure data risks are managed effectively and efficiently in accordance with the company policies and applicable regulatory requirements.
Essential Job Functions:
- Drive cross-functional collaboration with internal stakeholders responsible for data risk management to ensure proactive identification, measurement, management, monitoring, and reporting of data security risks.
- Provide effective oversight and credible challenge to the 1st line's implementation of data-related controls within the Risk and Control Self-Assessment (RCSA) and review the design and operating effectiveness of controls linked to data security, availability, and architecture.
- Contribute to enterprise-wide initiatives focused on enhancing the data risk management framework, information security policies, & security standards. Support development of key risk indicators and key performance indicators that delivers meaningful insights into data security risks and control performance trends.
- Perform data-driven reviews focused on data risk (including data security, data architecture and data storage) and prepare risk review reports for senior stakeholders and governance bodies.
- Stay abreast of applicable regulations, guidelines, and industry standards, and drive continuous enhancement of oversight practices to ensure alignment with evolving regulatory expectations and leading practices.
- Conduct exploratory data analysis on large sets of structure data using industry standard tools (Ex: SQL, Python, Power BI, and Excel data models) to develop meaningful insights on cybersecurity and technology related data.
- Learn technology, cyber security, and business continuity management processes at American Express, demonstrating strong levels of curiosity and willingness, in order to present an effective credible challenge.
- Support the design of independent technology risk oversight program which defines the engagement and integration with various risk management programs, including Risk and Control Self Assessments, operational risk event management, operational risk issue management.
- Help embed a strong risk-aware culture, encouraging proactive risk management behaviors within the organization.
Minimum Qualifications:
· Minimum five years of experience in data security & risk management within the banking/financial services industry including policy & procedure development, risk appetite, risk control self-assessment and testing, operational event & issue management.
- Proven ability to identify & assess risks, analyze issues and derive meaningful insights about risk trends by conducting interviews and analyzing large volumes of data.
- Strong verbal and written communication skills with an ability to
explain complex problems and ideas clearly and succinctly to senior
management. - Ability to work in a highly collaborative environment, excellent
relationship building skills and ability to influence partners with a firm
strategic view. - Excellent analytical skills with high attention to detail and accuracy.
- Excellent critical thinking and problem-solving skills.
- Required self-starter who can work with minimal supervision.
- Willingness to challenge traditional thinking by actively engaging in constructive dialogue.
Preferred:
- Educational background: Bachelor's in computer science or information systems.
- Working knowledge of one or more of the data mining tools and technologies (SQL, Python, Power BI, Excel data models, pivot tables & DAX queries, R)
- Experience in risk management frameworks and standards across cyber security, data risk, information technology, 3rd party, business continuity management.
- Industry certifications (e.g., CISSP, CISM, CISA, CRISC, CompTIA Security+)
- Understanding of risk assessment methodologies, frameworks, and industry standards (e.g., COSO, COBIT, ISO 27001, FAIR or NIST RMF).
- Knowledge of relevant policies & regulations (e.g., OCC Heightened Standards, FFIEC IT booklets).
- Experience with Governance, Risk and Compliance tools (Ex: Archer).
* Guardian
We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:
- Competitive base salaries
- Bonus incentives
- Support for financial-well-being and retirement
- Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- Generous paid parental leave policies (depending on your location)
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities
American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.
Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.
-
Information Security Investigator
4 days ago
Gurgaon, Haryana, India beBeeSecurityInvestigator Full time ₹ 90,00,000 - ₹ 1,20,00,000Job Summary:The role of an Information Security Investigator is a critical one, as they are responsible for analyzing and investigating security incidents escalated by various security tools and services. The primary function of this position is to determine whether a security event is an incident, and if so, coordinate with the IT and cross-functional teams...
-
Information Security Analyst
2 days ago
Gurgaon, Haryana, India Bill Gosling Outsourcing Full time US$ 90,000 - US$ 1,20,000 per yearJoin a Team That's Passionate About Making Lives BetterAt Bill Gosling Outsourcing, we believe that success starts with an amazing team. We are a global leader in outsourcing solutions, we focus on making lives better, one connection at a time. We provide tailored solutions to businesses around the globe, specializing in customer care, sales, and financial...
-
Specialist – Information Security
2 days ago
Gurgaon, Haryana, India Sun Life Full time ₹ 9,00,000 - ₹ 12,00,000 per yearYou are as unique as your background, experience and point of view. Here, you'll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll...
-
Manager Information Security
2 days ago
Gurgaon, Haryana, India Glan Management Consultancy Full timeJob Title Manager Information Security - ITJob Purpose Acting in a key technical management execution capacity to provide a conduit between IT teams and key business stakeholders in your functional area of IT Security to ensure information technology needs are managed consistently following professional IT and global standards and delivered with a high...
-
Senior Information Security Professional
3 days ago
Gurgaon, Haryana, India beBeeInformationSecurity Full time ₹ 9,00,000 - ₹ 12,00,000Senior Information Security AnalystWe are seeking a seasoned professional to join our team in India as a Senior Information Security Analyst. The ideal candidate will possess extensive experience in managing security risks and implementing effective security measures to protect organizational data and assets.ResponsibilitiesConduct risk assessments and...
-
Information Security Analyst
14 hours ago
Gurgaon, Haryana, India Amdocs Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob ID: Required Travel :Minimal Managerial - NoLocation: India- Pune (Amdocs Site) Who are we? Every day, billions of transactions, calls and messages that hold the world's communications fabric together run on systems that Amdocs has helped to create. Because we work with some of the largest and most innovative companies on the planet, our work...
-
Chief Information Security Specialist
2 days ago
Gurgaon, Haryana, India beBeeSecurity Full time ₹ 1,20,00,000 - ₹ 2,50,00,000Job SummaryThis role is responsible for managing third-party risk management, assisting in ISMS activities, and protecting systems and assets from external and internal threats.Key ResponsibilitiesUnderstand the product and its features.End-to-end ownership of responding to client security assessment questionnaires and Information Security Assurance...
-
Chief Information Security Position
3 days ago
Gurgaon, Haryana, India beBeeSecurity Full time ₹ 2,00,00,000 - ₹ 2,50,00,000About Chief Information Security Officer Role">..Develop and implement security strategies aligned with business objectives.Assess and manage risk to protect our organization's assets and reputation.Ensure compliance with relevant laws, regulations, and industry standards.Lead incident response and management efforts to minimize impact.Monitor and detect...
-
Information Security Consultant II
2 days ago
Gurgaon, Haryana, India NCR Corporation Full time US$ 1,50,000 - US$ 2,00,000 per yearAbout NCR VOYIXNCR VOYIX Corporation (NYSE: VYX) is a leading global provider of digital commerce solutions for the retail, restaurant and banking industries. NCR VOYIX is headquartered in Atlanta, Georgia, with approximately 16,000 employees in 35 countries across the globe. For nearly 140 years, we have been the global leader in consumer transaction...
-
Chief Information Security Officer
2 weeks ago
Gurgaon, Haryana, India Michael Page Full timeBe recognised as a Senior Leader in a leading Insurance OrganizationYou'll join a high-performing business, backing talented individualsAbout Our ClientA Listed Indian Heath Insurance Company. Certified Great Place to Work for the 3rd year running and aims to become one of the best workplaces in the BFSI industry.Job DescriptionSecurity Strategy...