Manager- Senior Manager - Technology Risk Oversight


Job company American Express
Size 10001+ employees
Job specification: Why American Express?

There’s a difference between having a job and making a difference.

American Express has been making a difference in people’s lives for over 160 years, backing them in moments big and small, granting access, tools, and resources to take on their biggest challenges and reap the greatest rewards.

We’ve also made a difference in the lives of our people, providing a culture of learning and collaboration, and helping them with what they need to succeed and thrive. We have their backs as they grow their skills, conquer new challenges, or even take time to spend with their family or community. And when they’re ready to take on a new career path, we’re right there with them, giving them the guidance and momentum into the best future they envision.

Because we believe that the best way to back our customers is to back our people.

The powerful backing of American Express.
Don’t make a difference without it.
Don’t live life without it.

General Summary

The Global Risk & Compliance (GRC) group within American Express is responsible for providing oversight and governance of risks to ensure that the company operates in a safe and sound manner within regulatory expectations. In a world increasingly subject to digitalization and the use of technology, technology risk management has become increasingly significant across organizations, becoming one of the key themes at board meetings. Cyberattacks have become increasingly commonplace and the trend continues to move upward.

This individual contributor role is part of the second line technology risk management team within the GRC group, headed by the Chief Risk Officer (CRO) of the company. This is a unique opportunity to work with a team of diverse and talented professionals who are responsible for building the technology risk management program and providing independent risk oversight to the technology, cyber security and business continuity management risks.

Reporting to the Director for Technology Risk oversight, this position is responsible for independently assessing and reporting risks and providing a view of aggregate risks. The risks identified by this team are reported to the Senior Management, Risk Management Committees, Board of Directors and Regulators. This position will be responsible for effectively collaborating with key stakeholders across lines of business and lines of defense to ensure risks are managed effectively and efficiently in accordance with the company policies and applicable regulatory requirements.

Essential Job Functions

Conduct independent, proactive risk management and oversight of technology, cyber security and business continuity management risks generated within business processes or that occur due to use of Technology
Learn technology, cyber security and business continuity management processes at American Express, demonstrating strong levels of curiosity and willingness, in order to present an effective credible challenge.
Perform data-driven reviews focused on technology, cyber security and business continuity management risks
Develop and enhance data-driven key risk indicators and key performance indicators that provide real time and meaningful insights into the risk and performance trends
Stay knowledgeable of relevant regulations, guidelines & industry standards
Support the design of independent technology risk oversight program which defines the engagement and integration with various risk management programs, including Process Risk Self Assessments, Business Continuity Management, New Product Approval, Mergers & Acquisitions etc.

Minimum Qualifications

Required Qualifications:

Bachelor’s Degree in related field
5+ years of experience in risk management across any of the three lines of defense
Proven ability to identify risks, analyze issues and derive meaningful insights about risk trends

by conducting interviews and analyzing large volumes of data

Excellent analytical skills with high attention to detail and accuracy
Excellent critical thinking and problem solving skills
Required self-starter who can work with minimal supervision
Excellent verbal, written and interpersonal communication skills
Willingness to challenge traditional thinking by actively engaging in constructive dialogue


Educational background: Computer Science or Information Systems
Working knowledge of one or more of the data mining tools/technologies (e.g. Microsoft Excel: Pivot Tables SQL, SAS, Python, R)
Experience in risk management across cyber security, information technology, 3rd party, business continuity management
Industry certifications (e.g. CISM, CISA, CRISC)
Understanding of risk assessment methodologies, frameworks and industry standards (e.g. COSO, COBIT, ISO 27001, FAIR or NIST RMF)
Knowledge of relevant policies & regulations (e.g. OCC Heightened Standards, FFIEC IT booklets)
Experience with Governance, Risk and Compliance tools (e.g. Archer)

Employment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions.

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, age, or any other status protected by law.


ReqID: 20008806
Schedule (Full-Time/Part-Time): Full-time
Date Posted: May 14, 2021, 3:36:31 PM

Seniority Level

Mid-Senior level

Financial Services
Employment Type


Job Functions
Analyst Consulting Product Management
More jobs in this location:
Cyber Security Jobs USA
Cyber Security Jobs Remote