Director - Risk and Information Security
Location: Charlotte
Posted on: June 23, 2025
|
|
Job Description:
The Global Risk & Compliance Organization (“GRC”) is an
independent risk management function, led by the Chief Risk
Officer, with the objective of ensuring that American Express
operates in a safe, sound, and fully compliant manner within all
applicable regulatory expectations. GRC creates and maintains the
overall risk management framework, performs independent risk
management assessments, and monitors applicable risks. Colleagues
at GRC are passionate about our commitment to drive the Company’s
goals of growth and progress by creating a culture of risk
awareness and proactivity around regulatory matters. By partnering
closely with business units across the enterprise, we help deliver
maximum value to our shareholders and our customers through
effective risk management and oversight activities. GRC’s
Cybersecurity, Technology, and Resiliency Risk Oversight (CTRRO)
organization is responsible for independent risk management
processes over Information Technology, Information Security, and
Resiliency risks at American Express. CTRRO is led by the Head of
CTRRO & Vendor Risk Oversight. CTRRO is hiring a new Director who
will support and provide 2nd line oversight for Information
Security and Technology Risk Policies and Frameworks across
American Express. The Director will provide reporting to technology
risk committees and other forums. The Director will lead a team of
direct reports responsible for executing their assigned oversight
processes and programs. Responsibilities : • Support oversight of
second line technology policies, standards, and procedures over
cybersecurity and technology risks • Support committee governance
and reporting while working with first line and second line
stakeholders on content, accuracy, and timeliness • Support second
line reporting, including quarterly memo and board reporting • Lead
assigned reviews of first line control effectiveness over
information security processes. • Consulting with technology
oversight teams over processes to ensure first line adherence to
second line policies and standards • Partner with technology
oversight teams on risk appetite maintenance and reporting and
execution of new governance and policies • Lead and nurture a
global team of direct reports and maintain performance management •
Develop strong working relationships with all levels of the
organization, handle and resolve conflict, to achieve results and
enact wide-scale impact across the organization • Understand and
keep pace with global regulatory expectations and trends for
technology risk governance at large banks Minimum Qualifications: •
8 years of risk management experience in cybersecurity or
technology across one or more lines of defense • Bachelor’s degree
in business or technology or equivalent • Experience leading and
delivering positive outcomes for a global team • Strong written and
verbal communication skills Preferred Qualifications: • Second-line
risk management experience within a large financial services
organization • A cybersecurity, technology, or risk management
certification (CISSP, CCSP, CEH, CISM, CISA, etc.) Salary Range:
$170,000.00 to $255,000.00 annually bonus equity (if applicable)
benefits The above represents the expected salary range for this
job requisition. Ultimately, in determining your pay, we’ll
consider your location, experience, and other job-related factors.
We back you with benefits that support your holistic well-being so
you can be and deliver your best. This means caring for you and
your loved ones physical, financial, and mental health, as well as
providing the flexibility you need to thrive personally and
professionally: • Competitive base salaries • Bonus incentives • 6%
Company Match on retirement savings plan • Free financial coaching
and financial well-being support • Comprehensive medical, dental,
vision, life insurance, and disability benefits • Flexible working
model with hybrid, onsite or virtual arrangements depending on role
and business need • 20 weeks paid parental leave for all parents,
regardless of gender, offered for pregnancy, adoption or surrogacy
• Free access to global on-site wellness centers staffed with
nurses and doctors (depending on location) • Free and confidential
counseling support through our Healthy Minds program • Career
development and training opportunities
Keywords: , Greenville , Director - Risk and Information Security, IT / Software / Systems , Charlotte, South Carolina