AE

Posted 1 week ago

( Senior Information Security Manager ) Remote Jobs American Express, Amex Work From Home @ Get[...]

American Express

Columbia, SC

IT & TechnologyRemoteHybrid

Job description

Senior Information Security Manager

Responsibilities

  • Partner with the Director of Third-Party Security Strategy & Governance to lead strategic third‑party cyber risk projects.
  • Build and maintain a robust third‑party cyber risk working version.
  • Drive program compliance through continuous reporting on cyber risk metrics and provide consulting to internal stakeholders.
  • Identify and champion opportunities to mature Amex’s third‑party risk management practices.
  • Evolve key threat metrics to measure third‑party cyber readiness across business portfolios and thousands of third‑party entities.
  • Develop and oversee a reporting framework, generating monthly metrics and delivering actionable reports to senior leadership, risk committees, and cross‑functional teams.
  • Assess third‑party alignment with program objectives and recommend standardized methodologies to achieve risk appetite alignment.
  • Collaborate with cross‑functional partners to improve processes and ensure compliance with global regulatory requirements for third‑party data security risk.
  • Create educational materials, workflows, and communication plans to support program execution organization‑wide.
  • Define requirements for, and support the development of, tools, automation scripts, and internal solutions to improve risk management effectiveness.
  • Own the third‑party cyber risk strategic roadmap and portfolio management.
  • Provide domain expertise and advice to business customers across the organization.

Qualifications

  • Proven experience managing critical cyber risk initiatives from planning through execution.
  • Strong capability to identify proactive opportunities for improvement and articulate actionable plans.
  • Experience driving complex, large‑scale change in matrixed organizations.
  • Excellent organization, prioritization, and multitasking skills—capable of handling multiple initiatives simultaneously.
  • High attention to detail and strong analytical mindset; ability to diagnose issues and drive consensus solutions.
  • Excellent written and verbal communication skills.

Technical Expertise & Requirements

  • Demonstrated track record delivering data‑driven security solutions with a customer‑first mindset.
  • Deep understanding of data protection risks, including vulnerability management, asset threat profiles, and breach vectors, especially in third‑party contexts.
  • Familiarity with enterprise security frameworks and audit requirements (ISO27001, NISTCSF, SSAE16/18, CSA, CIS Benchmark20, OWASPTop10, FFIEC, etc.).
  • Experience with core security controls: vulnerability scanning, penetration testing, encryption, anti‑malware, endpoint protection, data loss prevention (DLP).
  • Balance of risk‑management expertise, technical know‑how, and business acumen.
  • Strong quantitative and qualitative analytical abilities.
  • Ability to lead multidisciplinary initiatives with a governance‑focused approach.
  • Proficiency in written and oral communications.

Compensation & Benefits

  • Annual salary range: $110,000 – $190,000, plus bonus and benefits.
  • 6% company match on retirement savings plan.
  • Unlimited professional development and training opportunities.
  • Flexible work arrangements and hybrid options.
  • 20+ weeks paid parental leave for all parents.
  • Unlimited access to worldwide health and wellness resources, including psychiatrists and counseling services.
  • Comprehensive medical, dental, vision, and disability coverage.
  • Educational and financial wellness support.

American Express is an equal‑opportunity employer.

#J-18808-Ljbffr
Apply now at American Express