Director, Independent Risk Assessment – Information Security and Information Technology Oversight

Get Referred

Job Description

The position, located in Phoenix, is part of the Global Risk, Banking & Compliance organization and reports to the Vice President of Information Security and Information Technology Oversight. Strong information technology and information security are key contributors to loyalty, trust and customer experience, and the American Express brand. Properly assessing, managing, and overseeing global information technology and information security risk is critical to the Company’s business. The successful candidate will have deep information security and information technology expertise, including industry knowledge and awareness of emerging technologies and threats which impact cyber security. The position requires a demonstrated ability to manage information security and information technology risk, and a team player who is comfortable working across a range of functions including compliance, legal, operational excellence, privacy, risk oversight, and many other partners to promote best information security throughout the enterprise.


The successful candidate will have demonstrated the ability to manage information security risk, both strategically and tactically, and will understand the role of a strong governance framework and risk management program. The role includes leading a team of information security and information technology oversight professionals and working to improve risk management and control strength by providing independent assessment of, and effective challenge to, key components of the information security and information technology program through testing, reviews and ongoing effective monitoring.


Responsibilities:
  1. Conduct enterprise independent risk assessment (SLoD) of the information security and information technology programs and provide effective challenge to the design and execution of technical and procedural controls
  2. Conduct data-driven triggered risk assessments and coordinate risk-based investigations of controls.
  3. Conduct industry benchmarking, regulatory requirement gathering and peer-based analysis of available controls, risk assessment methodologies and risk mitigation practices to assess for coverage gaps.
  4. Assist in the development of information security and information technology metrics (e.g. KRIs and KPIs) to continuously monitor and oversee program level risks.
  5. Lead and develop a team of information technology and information security professionals with global responsibility
  6. Provide periodic updates, reports, and recommendations to management, regarding best practice information security and information technology controls, risk assessment and risk remediation strategies
  7. Support interfaces with international regulators through updates on information security and information technology oversight activities.
  8. Actively test and monitor information security and information technology controls.

Qualifications

  1. Minimum five years of experience in an information security or information technology role is required
  2. Superior problem-solving, strong analytical skill, strong learning agility and willingness to embrace new challenges
  3. Risk management experience (SLoD) is preferred, particularly in a financial services or highly regulated environment
  4. Thought leadership and ability to influence business partners
  5. Attention to details with strong strategic view
  6. Strong verbal and written communication skills and excellent relationship building skills
  7. Knowledge of relevant information security standards and frameworks, including NIST
  8. Knowledge of US federal financial guidelines, examples include: FFIEC, OCC, & FDIC and other cybersecurity standards and frameworks
  9. Bachelor's degree in Computer Science, Information Systems, Business Administration or other related field (or equivalent work experience).  Advanced degree preferred.
  10. Professional certification is preferred (e.g. CISA, CISSP, CISM, CPCB, etc.)
  11. Experience with information security risk process improvement
  12. Deep knowledge of information security systems/platforms and data and processes adopted by the Company is preferred
  13. Experience in leading and growing information security or information technology teams is preferred


Why American Express?


There’s a difference between having a job and making a difference.

 

American Express has been making a difference in people’s lives for over 160 years, backing them in moments big and small, granting access, tools, and resources to take on their biggest challenges and reap the greatest rewards.

 

We’ve also made a difference in the lives of our people, providing a culture of learning and collaboration, and helping them with what they need to succeed and thrive. We have their backs as they grow their skills, conquer new challenges, or even take time to spend with their family or community. And when they’re ready to take on a new career path, we’re right there with them, giving them the guidance and momentum into the best future they envision.

 

Because we believe that the best way to back our customers is to back our people.

 

The powerful backing of American Express.

Don’t make a difference without it.

Don’t live life without it.

 

Employment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions.



ReqID: 19018442
Schedule (Full-Time/Part-Time): Full-time
Date Posted: Oct 9, 2019, 2:42:01 AM