Senior Manager, Cybersecurity Risk Management

American Express Co
  • Phoenix, AZ
    9 days ago

    Job Description

    The Global Risk & Compliance (GRC) group within American Express is responsible for providing oversight and governance of risks to ensure that the company operates in a safe and sound manner within regulatory expectations. The Technical Risk Management (TRM) organization provides independent risk oversight across Cybersecurity Risk, Technology Risk, Data Risk, Resiliency Risk, and AI Risk. As cyber threats continue to evolve, effective cyber risk management is critical to protecting the company, its customers, and its assets.

    This individual contributor role is part of the Cyber Risk Management team within TRM. The successful candidate will provide independent risk oversight and effective challenge across key cybersecurity domains, including Vulnerability Management, Compute Security, Cloud Security, Application Security, Network Security, and End User Computing (EUC) Security. , This position is responsible for assessing, monitoring, and reporting cybersecurity risks across the enterprise. The role partners closely with cybersecurity, technology, and business stakeholders to evaluate risk exposure, assess control effectiveness, challenge remediation strategies, and provide meaningful risk insights to senior leadership, risk committees, and regulators.

    At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.

    As part of Team Amex, you'll experience our powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

    Minimum Qualifications:

    • Bachelor's Degree in Cybersecurity, Information Systems, Computer Science, Information Technology, Engineering, or a related field.
    • 5+ years of experience in Cyber Risk Management, Information Security, Cybersecurity Governance, Technology Risk Management, Audit, or Operational Risk.
    • Experience in one or more cybersecurity domains including Vulnerability Management, Cloud Security, Application Security, Network Security, Infrastructure/Compute Security, EUC Security, or Exposure Management.
    • Strong understanding of cybersecurity risk management principles, security controls, and industry frameworks.
    • Experience identifying risks, analyzing issues, conducting assessments, and translating complex technical topics into business-focused risk insights.
    • Excellent analytical, critical thinking, problem-solving, and communication skills.
    • Ability to work independently and influence stakeholders through constructive challenges and collaboration.
    • Industry certification required: CISSP, CISM, CRISC, CCSP, CISA, or equivalent cybersecurity/risk management certification.

    Preferred Qualifications:

    • Working knowledge of data analytics and visualization tools including SQL, Python, Power BI, Excel data models, and related technologies.
    • Experience executing or providing oversight of Vulnerability Management, Cloud Security, Application Security, Network Security, and Endpoint/EUC Security.
    • Knowledge of cybersecurity frameworks and standards including NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Controls, ISO 27001, COBIT, MITRE ATT&CK, and FAIR.
    • Knowledge of regulatory expectations and industry guidance, including FFIEC guidance and OCC Heightened Standards.
    • Experience with Governance, Risk, and Compliance (GRC) platforms such as Archer.
    • Experience with AI tools such as ChatGPT and Copilot
    • Experience supporting senior management reporting, risk committees, regulatory examinations, or internal audit engagements.
    • Additional certifications such as GIAC, CCSK, AWS Security Specialty, Azure Security Engineer, or other cloud/security certifications.

    Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.

    Essential Job Functions:

    • Provide independent risk oversight and effective challenge for Vulnerability Management, Compute Security, Cloud Security, Application Security, Network Security, and End User Computing (EUC) Security.
    • Perform risk assessments, thematic reviews, and data-driven analyses to identify emerging cyber risks, control gaps, and trends across the cybersecurity landscape.
    • Analyze cybersecurity, vulnerability, and operational data using tools such as SQL, Python, Power BI, and Excel to develop meaningful risk insights and reporting.
    • Assess control effectiveness, remediation plans, risk acceptance decisions, and residual risk exposure across covered cybersecurity domains.
    • Develop, enhance, and monitor key risk indicators (KRIs), metrics, and executive reporting to provide meaningful visibility into cyber risk posture and trends.
    • Stay current on cyber threats, emerging technologies, industry trends, regulatory expectations, and cybersecurity frameworks.
    • Support risk governance activities, regulatory engagements, audits, committee reporting, and enterprise cybersecurity risk initiatives.
    • Partner effectively across lines of defense to ensure cybersecurity risks are identified, assessed, monitored, and managed in accordance with company policies and regulatory expectations.

    Essential Job Functions:

    • Provide independent risk oversight and effective challenge for Vulnerability Management, Compute Security, Cloud Security, Application Security, Network Security, and End User Computing (EUC) Security.
    • Perform risk assessments, thematic reviews, and data-driven analyses to identify emerging cyber risks, control gaps, and trends across the cybersecurity landscape.
    • Analyze cybersecurity, vulnerability, and operational data using tools such as SQL, Python, Power BI, and Excel to develop meaningful risk insights and reporting.
    • Assess control effectiveness, remediation plans, risk acceptance decisions, and residual risk exposure across covered cybersecurity domains.
    • Develop, enhance, and monitor key risk indicators (KRIs), metrics, and executive reporting to provide meaningful visibility into cyber risk posture and trends.
    • Stay current on cyber threats, emerging technologies, industry trends, regulatory expectations, and cybersecurity frameworks.
    • Support risk governance activities, regulatory engagements, audits, committee reporting, and enterprise cybersecurity risk initiatives.
    • Partner effectively across lines of defense to ensure cybersecurity risks are identified, assessed, monitored, and managed in accordance with company policies and regulatory expectations.

    Numbers & Facts

    LocationPhoenix, AZ

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Auditingunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Control Objectives for Information and related Technology (COBIT)unmatched
    • Corporate Policiesunmatched
    • Customer Support/Serviceunmatched
    • Data Analysisunmatched
    • Data Modelingunmatched
    • Data Visualization Toolsunmatched
    • Emerging Technologyunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • ISO (International Organization for Standardization)unmatched
    • Industry/Trade Analysisunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Management Reportingunmatched
    • Metricsunmatched
    • Microsoft Windows Azureunmatched
    • Network Securityunmatched
    • Operational Auditunmatched
    • Power BIunmatched
    • Problem Solving Skillsunmatched
    • Python Programming/Scripting Languageunmatched
    • Regulationsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • SQL (Structured Query Language)unmatched
    • Safety/Work Safetyunmatched
    • Security Attacksunmatched
    • Software Engineeringunmatched
    • Technical Leadershipunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder