AE
Posted 1 week ago
( Senior Information Security Manager ) Remote Jobs American Express, Amex Work From Home @ Get[...]
American Express
Columbia, SC
IT & TechnologyRemoteHybrid
Job description
Senior Information Security Manager
Responsibilities
- Partner with the Director of Third-Party Security Strategy & Governance to lead strategic third‑party cyber risk projects.
- Build and maintain a robust third‑party cyber risk working version.
- Drive program compliance through continuous reporting on cyber risk metrics and provide consulting to internal stakeholders.
- Identify and champion opportunities to mature Amex’s third‑party risk management practices.
- Evolve key threat metrics to measure third‑party cyber readiness across business portfolios and thousands of third‑party entities.
- Develop and oversee a reporting framework, generating monthly metrics and delivering actionable reports to senior leadership, risk committees, and cross‑functional teams.
- Assess third‑party alignment with program objectives and recommend standardized methodologies to achieve risk appetite alignment.
- Collaborate with cross‑functional partners to improve processes and ensure compliance with global regulatory requirements for third‑party data security risk.
- Create educational materials, workflows, and communication plans to support program execution organization‑wide.
- Define requirements for, and support the development of, tools, automation scripts, and internal solutions to improve risk management effectiveness.
- Own the third‑party cyber risk strategic roadmap and portfolio management.
- Provide domain expertise and advice to business customers across the organization.
Qualifications
- Proven experience managing critical cyber risk initiatives from planning through execution.
- Strong capability to identify proactive opportunities for improvement and articulate actionable plans.
- Experience driving complex, large‑scale change in matrixed organizations.
- Excellent organization, prioritization, and multitasking skills—capable of handling multiple initiatives simultaneously.
- High attention to detail and strong analytical mindset; ability to diagnose issues and drive consensus solutions.
- Excellent written and verbal communication skills.
Technical Expertise & Requirements
- Demonstrated track record delivering data‑driven security solutions with a customer‑first mindset.
- Deep understanding of data protection risks, including vulnerability management, asset threat profiles, and breach vectors, especially in third‑party contexts.
- Familiarity with enterprise security frameworks and audit requirements (ISO27001, NISTCSF, SSAE16/18, CSA, CIS Benchmark20, OWASPTop10, FFIEC, etc.).
- Experience with core security controls: vulnerability scanning, penetration testing, encryption, anti‑malware, endpoint protection, data loss prevention (DLP).
- Balance of risk‑management expertise, technical know‑how, and business acumen.
- Strong quantitative and qualitative analytical abilities.
- Ability to lead multidisciplinary initiatives with a governance‑focused approach.
- Proficiency in written and oral communications.
Compensation & Benefits
- Annual salary range: $110,000 – $190,000, plus bonus and benefits.
- 6% company match on retirement savings plan.
- Unlimited professional development and training opportunities.
- Flexible work arrangements and hybrid options.
- 20+ weeks paid parental leave for all parents.
- Unlimited access to worldwide health and wellness resources, including psychiatrists and counseling services.
- Comprehensive medical, dental, vision, and disability coverage.
- Educational and financial wellness support.
American Express is an equal‑opportunity employer.