Platzhalter Bild

Cybersecurity Audit Manager chez American Express

American Express · Phoenix, États-Unis d'Amérique · Hybrid

$89,250.00  -  $150,250.00

Postuler maintenant

At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.

Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

About the Internal Audit Group at American Express 

Our Internal Audit Group is a worldwide function with 300+ team members and offices across nine countries within American Express. Our mission is to protect and enhance organizational value by providing independent, objective, risk-based assurance, advisory services and to influence the way the company manages risk.

We are committed to growing our audit staff significantly as we continue to expand and enhance the Internal Audit Group. Our assurance and risk professionals have diverse backgrounds including internal controls, consumer compliance, technology, operational risk, financial accounting, data analytics, and banking operations. Our audit teams align to key risk areas and business units to ensure IAG can provide comprehensive and risk-based audit coverage. In addition, IAG has a Professional Practices group responsible for managing audit operations, quality, and standards; regulatory relations; reporting; training and professional development; and key internal capabilities and technologies.

 

About the Role

Our Internal Audit group is seeking an eager Cybersecurity Audit Manager in New York City, Phoenix, or Sandy to help advance and grow our audit coverage across our cybersecurity audit portfolio. The cybersecurity audit portfolio spans across information technology throughout the enterprise and includes auditing first-line information security processes. The ideal candidate will have strong problem- solving skills, excellent attention to detail, and the ability to communicate audit results effectively. 

 

Key Responsibilities

·         Serve as Auditor in Charge (AIC) on audits, managing the audit engagement end-to-end, planning audit projects, defining objectives and scope, and coordinating with control groups, external auditors, stakeholders, and regulators to ensure effective execution; conduct L1 reviews; serve as the primary audit client contact

·         Analyze / review audit results and documentation to evaluate effectiveness and efficiency, synthesizing audit findings

·         Lead audit client meetings and walkthroughs

·         Develop test plans, audit findings, and the audit report in accordance with IAG policies and procedures

·         Guide team on how to validate and execute corrective actions / Management Action Plans (MAPs) are impactful, sustainable, and improve the control environment of the business unit

·         Support business monitoring activities with audit leadership, tracking key metrics to identify control issues and trends; stay up to date with evolving industry trends, external news and regulatory changes, and analyze the impact to the business

·         Delegate tasks to team members; guide auditors in assessing risks, evaluating control design, and executing audit tests; review and provide feedback on work papers

·         Effectively coach, teach, mentor, and develop less experienced colleagues and co-sourced resources in geographically diverse locations across all aspects of their role, the audit and analytic lifecycle, audit methodology and best practices

·         Conduct post-audit feedback discussions with audit team members to provide actionable feedback, support development, and recognize accomplishments

·         Guide team to proactively and routinely communicate task status, roadblocks, challenges, suggesting potential solutions to the team

 

Minimum Qualifications

·         5+ years of audit experience

·         Prior experience working at a Big Four / G-SIB

·         Demonstrates strong written and verbal communication skills to deliver deliverables with quality, and actionable value-add feedback to management on issues, opportunity areas, and deficiency solutions 

·         Effectively leads a team in a fast-paced environment to drive business results, utilizing related project management skills, employing creative thinking, and the ability to work on competing priorities

·         Applies critical thinking to break-down complex problems into components, and solve using data analysis, process, risk control knowledge, and experience to drive risk-based conclusions and decisions

·         Applies control theory and professional auditing practices throughout the audit lifecycle

·         Understands regulations, regulatory risks, accounting, and financial industry best practices relevant to the business, including emerging technology and data considerations, and incorporates into the audit approach to enhance outcomes

·         Strong knowledge of information security and infrastructure related terminology and concepts and experience in applying cybersecurity concepts and controls/countermeasures in public cloud environments (e.g., zero trust, defense in depth, infrastructure as code, virtualization, container management, public key infrastructure (PKI), etc.)

·         Prior experience in analyzing regulatory and industry cybersecurity frameworks (NIST, FFIEC, CRI, MITRE ATT&CK) and applying guidance to audits of cybersecurity controls

 

Preferred Qualifications

·         Experience with data analytic tools, data visualization, key risk indicators (KRIs), key performance indicators (KPIs), information systems / technology, and scorecards / dashboards, etc.

·         Interest in working with data, interpreting results, analytic best practices and experience with data analytics tools and data visualization

·         Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) and within 12 months of hire date an industry recognized cloud certification, e.g., ICS2 CCSP


%3Cp%3E%3Cspan style=%22font-size:16px;%22%3ESalary Range: %2489,250.00 to %24150,250.00 annually + bonus + benefits%3C/span%3E%3C/p%3E%3Cp%3E%3Cspan style=%22font-size:16px;%22%3EThe above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.%3C/span%3E%3C/p%3E%3Cp%3E%3Cspan style=%22font-size:16px;%22%3EWe back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones%27 physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:%3C/span%3E%3C/p%3E%3Cul%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3ECompetitive base salaries%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3EBonus incentives%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3E6% Company Match on retirement savings plan%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3EFree financial coaching and financial well-being support%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3EComprehensive medical, dental, vision, life insurance, and disability benefits%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3EFlexible working model with hybrid, onsite or virtual arrangements depending on role and business need%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3E20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3EFree access to global on-site wellness centers staffed with nurses and doctors (depending on location)%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3EFree and confidential counseling support through our Healthy Minds program%26nbsp;%3C/span%3E%3C/li%3E%3Cli%3E%3Cspan style=%22font-size:16px;%22%3ECareer development and training opportunities%3C/span%3E%3C/li%3E%3C/ul%3E%3Cp%3E%3Cspan style=%22font-size:16px;%22%3EFor a full list of Team Amex benefits, visit our %3C/span%3E%3Ca target=%22_blank%22 rel=%22noopener noreferrer%22 href=%22https://www.americanexpress.com/en-us/colleagues/benefits%22%3E%3Cspan style=%22font-size:16px;%22%3E%3Cu%3EColleague Benefits Site%3C/u%3E%3C/span%3E%3C/a%3E%3Cspan style=%22font-size:16px;%22%3E.%3C/span%3E%3C/p%3E%3Cp%3E%3Cspan style=%22font-size:16px;%22%3EAmerican Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law. American Express will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable state and local laws, including, but not limited to, the California Fair Chance Act, the Los Angeles County Fair Chance Ordinance for Employers, and the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance. For positions covered by federal and/or state banking regulations, American Express will comply with such regulations as it relates to the consideration of applicants with criminal convictions.%3C/span%3E%3C/p%3E%3Cp%3E%3Cspan style=%22font-size:16px;%22%3EWe back our colleagues with the support they need to thrive, professionally and personally. That%27s why we have Amex Flex, our enterprise working model that provides greater flexibility to colleagues while ensuring we preserve the important aspects of our unique in-person culture. Depending on role and business needs, colleagues will either work onsite, in a hybrid model (combination of in-office and virtual days) or fully virtually.%3C/span%3E%3C/p%3E%3Cp%3E%3Cspan style=%22font-size:16px;%22%3EUS Job Seekers - Click to view the “%3C/span%3E%3Ca target=%22_blank%22 rel=%22noopener noreferrer%22 href=%22https://www.eeoc.gov/poster%22%3E%3Cspan style=%22color:#0563c1;font-size:16px;%22%3E%3Cu%3EKnow Your Rights%3C/u%3E%3C/span%3E%3C/a%3E%3Cspan style=%22font-size:16px;%22%3E” poster. If the link does not work, you may access the poster by copying and pasting the following URL in a new browser window: %3C/span%3E%3Ca style=%22color:#0563c1;%22 target=%22_blank%22 rel=%22noopener noreferrer%22 href=%22https://www.eeoc.gov/poster%22%3E%3Cspan style=%22font-size:16px;%22%3E%3Cu%3Ehttps://www.eeoc.gov/poster%3C/u%3E%3C/span%3E%3C/a%3E%3C/p%3E%3Cp class=%22MsoNormal%22%3E%3Cspan style=%22font-family:%26quot;Arial%26quot;,sans-serif;font-size:16px;%22%3EEmployment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions%3C/span%3E%3Cspan style=%22font-family:%26quot;Arial%26quot;,sans-serif;%22%3E%3Co:p%3E%3C/o:p%3E%3C/span%3E%3C/p%3E
*!

 

Postuler maintenant

Plus d'emplois