American Express · 16 hours ago
Senior Associate - CyberOps & Assurance (Third-party cyber risk)
American Express is a company with a long history of innovation and commitment to its customers and colleagues. The role involves leading the documentation and management of the Third-Party Security’s cyber risk strategy while supporting complex contract negotiations and collaborating with various stakeholders to enhance information security across the organization.
Credit CardsFinanceFinancial ServicesPaymentsTravel
Responsibilities
Assist in the development and maturation of a robust third-party cyber risk strategy that enables the enterprise to develop and implement security solutions and capabilities that are clearly aligned with business, technology, and threat drivers
Collaborate with extended Third-Party Security Team and Technology Risk and Information Security SMEs
Lead forums with key stakeholders to manage, track, and report on different projects and strategic initiatives
Create overview presentations, trackers, and reports to present status of different initiatives
Identifying opportunities to adopt new technologies, including Artificial Intelligence, to improve risk management, streamline processes, and address emerging risks
Evaluate emerging information security developments and help assess the impacts and relevance to American Express to stay ahead of new policies and regulations
Partner with GCO to support negotiation of Information Security (IPCR) terms in contracts with third parties
Analyze multiple sources of information during contract negotiations to identify, understand, and communicate risks, contract requirements, gaps or deficiencies, and mitigating controls
Collaborate across the contract and product review lifecycles as needed, including by identifying mitigating controls, identifying potential control gaps across TRIS domains
Qualification
Required
Proven experience driving strategic initiatives from vision to execution while identifying opportunities for efficiency
Experience in risk and control management functions with strong research and analytical abilities
Experience supporting enterprise-wide risk governance initiatives, including Control Management reporting, Risk Assessment overview, portfolio overviews, etc
Strong communications skills, in both written and verbal form with the ability to communicate effectively across various management levels internally and externally
Strong presentation skills ability to translate complex processes and technical terms into simple concepts, verbally, in writing, and in presentation materials
Strong knowledge of industry standard control frameworks, security assurance auditing standards, best practices guidelines, and third-party regulatory requirements, such as ISO27001, NIST CSF, SSAE16/18, CSA, CIS Top 20, OWASP Top 10, FFIEC, etc
Understanding Information Security risk and differences between Technology, Information Security, Artificial Intelligence, and other types of operational risks
Intellectual curiosity and willingness to learn and understand how different things work to identify risks and mitigating controls
Candidate must make collaboration essential and have a willingness to interact with extended Third-Party Security team to solve complex problems and drive strategic initiatives
Knowledge of network architecture, proxy infrastructure, and programs to support network access and enablement, specifically related to how Third Parties connect to the American Express Network and beyond
2 years of experience managing technology risk
3 years of Control Management and/or Control Testing experience in a large organization
4 years of experience in Information Security operational roles with increase of responsibilities and scope
Preferred
Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or related field
Information Security Certifications including but not limited to; CompTIA Security+, CISSP; CISM; MCTS; MCP; CCNA
Benefits
Competitive base salaries
Bonus incentives
6% Company Match on retirement savings plan
Free financial coaching and financial well-being support
Comprehensive medical, dental, vision, life insurance, and disability benefits
Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
Free and confidential counseling support through our Healthy Minds program
Career development and training opportunities
Company
American Express
American Express is a financial services company that provides credit cards, charge cards, payment solutions, and related services.
Funding
Current Stage
Public CompanyTotal Funding
unknown1978-01-13IPO
Leadership Team
Recent News
thecanadianpressnews.ca
2026-01-14
Company data provided by crunchbase