
Manager - Information Security
- New York City, NY
- $110,000-190,000 per year
- Permanent
- Full-time
- Drive cross-functional collaboration with internal stakeholders responsible for data risk management to ensure proactive identification, measurement, management, monitoring, and reporting of data security risks.
- Provide effective oversight and credible challenge to the 1st line’s implementation of data-related controls within the Risk and Control Self-Assessment (RCSA) and review the design and operating effectiveness of controls linked to data security, availability, and architecture.
- Contribute to enterprise-wide initiatives focused on enhancing the data risk management framework, information security policies, & security standards. Support development of key risk indicators and key performance indicators that delivers meaningful insights into data security risks and control performance trends.
- Perform data-driven reviews focused on data risk (including data security, data architecture and data storage) and prepare risk review reports for senior stakeholders and governance bodies.
- Stay abreast of applicable regulations, guidelines, and industry standards, and drive continuous enhancement of oversight practices to ensure alignment with evolving regulatory expectations and leading practices.
- Conduct exploratory data analysis on large sets of structure data using industry standard tools (Ex: SQL, Python, Power BI, and Excel data models) to develop meaningful insights on cybersecurity and technology related data.
- Learn technology, cyber security, and business continuity management processes at American Express, demonstrating strong levels of curiosity and willingness, in order to present an effective credible challenge.
- Support the design of independent technology risk oversight program which defines the engagement and integration with various risk management programs, including Risk and Control Self Assessments, operational risk event management, operational risk issue management.
- Help embed a strong risk-aware culture, encouraging proactive risk management behaviors within the organization.
- Minimum five years of experience in data security & risk management within the banking/financial services industry including policy & procedure development, risk appetite, risk control self-assessment and testing, operational event & issue management.
- Proven ability to identify & assess risks, analyze issues and derive meaningful insights about risk trends by conducting interviews and analyzing large volumes of data.
- Strong verbal and written communication skills with an ability to
management. * Ability to work in a highly collaborative environment, excellentrelationship building skills and ability to influence partners with a firm
strategic view. * Excellent analytical skills with high attention to detail and accuracy.
- Excellent critical thinking and problem-solving skills.
- Required self-starter who can work with minimal supervision.
- Willingness to challenge traditional thinking by actively engaging in constructive dialogue.
- Educational background: Bachelor’s in computer science or information systems.
- Working knowledge of one or more of the data mining tools and technologies (SQL, Python, Power BI, Excel data models, pivot tables & DAX queries, R)
- Experience in risk management frameworks and standards across cyber security, data risk, information technology, 3rd party, business continuity management.
- Industry certifications (e.g., CISSP, CISM, CISA, CRISC, CompTIA Security+)
- Understanding of risk assessment methodologies, frameworks, and industry standards (e.g., COSO, COBIT, ISO 27001, FAIR or NIST RMF).
- Knowledge of relevant policies & regulations (e.g., OCC Heightened Standards, FFIEC IT booklets).
- Experience with Governance, Risk and Compliance tools (Ex: Archer).
- Competitive base salaries
- Bonus incentives
- 6% Company Match on retirement savings plan
- Free financial coaching and financial well-being support
- Comprehensive medical, dental, vision, life insurance, and disability benefits
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities