Search
Information Security Analyst-Third Party Security

Information Security Analyst-Third Party Security

locationPhoenix, AZ, USA
PublishedPublished: 11/14/2024
Public Services
Full Time

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

As part of our diverse tech team, you can architect, code and ship software that makes us an essential part of our customers’ digital lives.Here, you can work alongside talented engineers in an open, supportive, inclusive environment where your voice is valued, and you make your own decisions on what tech to use to solve challenging problems.American Express offers a range of opportunities to work with the latest technologies and encourages you to back the broader engineering community through open source.And because we understand the importance of keeping your skills fresh and relevant, we give you dedicated time to invest in your professional development.Find your place in technology on #TeamAmex.

As part of Amex Technology Risk and Information Security, Third Party Security is responsible for driving cyber risk reduction at Amex third parties to minimize exposure or disruption across the Amex enterprise and external partners. Our organizational objective is to reduce third party risk while increasing the visibility of the program and subsequent controls.

The Amex Third Party Security Overwatch and Executive Escalations & Reporting Team is responsible for managing our third-party cyber health program across a large portfolio of third parties, as well as manage reporting and customer concerns to senior leaders across the Blue Box.

Primary Job Responsibilities:

  • Support an evolving reporting framework, generates metrics on third party cyber risk, and delivers meaningful reports to leadership across Business units and market areas, risk management committees, and other internal collaborators
  • Evaluates third party adherence to program and find opportunities and standard methodologies to influence alignment with risk appetite
  • Support development of training materials, process flows, and communication plans for socializing efforts to support execution of the Program across the organization
  • Support development of materials for executive audiences
  • Identify and drive opportunities for maturing the Amex third party cyber risk program
  • Support the evolution of key risk metrics to effectively evaluate third party cyber health across Business portfolios and thousands of Amex third parties
  • Support the Third-Party Security products including data management, validation, enhancement support, and support to collaborators
  • Advises leadership and business partners on technical cyber risk as it relates to third parties

Qualifications & Required Skills

  • Demonstrated ability to analyze datasets and produce metrics and standardized reporting
  • Knowledge & understanding of cyber security threats, risks, and vulnerabilities.
  • Understanding of what information or assets are of value to threat actors and how organizations are breached.
  • Known to work at driving thought-provoking central initiatives from vision to execution
  • Must be able to identify proactive opportunities for improvement & efficiencies and to articulate plans required to reach objectives
  • Experience with matrix organizations consisting of multi-functional teams and experience in driving complex, large-scale change efforts
  • Must pay strong attention to detail and demonstrate a natural disposition to diagnose issues, mediate differing opinions, and converge on solutions
  • Must have strong verbal and written communication skills, interpersonal collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences across various levels including executive leadership
  • Proven problem solver with ability to provide in-depth analysis of complex problems, manage risk and make quick decisions.
  • Must possess the ability to multitask, prioritize, and manage time effectively.

Preferred Skills

  • Experience with Cyber Attack Surface Management solutions, specifically BitSight and Security Scorecard
  • Familiarity with industry standard control frameworks, security assurance auditing standards, guidelines, and third-party regulatory requirements, such as ISO27001, NIST CSF, SSAE16/18, CSA, CIS Top 20, OWASP Top 10, FFIEC, etc.

Salary Range: $85,000.00 to $150,000.00 annually + bonus + benefits

The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

  • Competitive base salaries 
  • Bonus incentives 
  • 6% Company Match on retirement savings plan 
  • Free financial coaching and financial well-being support 
  • Comprehensive medical, dental, vision, life insurance, and disability benefits 
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need 
  • 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy 
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location) 
  • Free and confidential counseling support through our Healthy Minds program 
  • Career development and training opportunities

For a full list of Team Amex benefits, visit our Colleague Benefits Site.

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.

We back our colleagues with the support they need to thrive, professionally and personally. That's why we have Amex Flex, our enterprise working model that provides greater flexibility to colleagues while ensuring we preserve the important aspects of our unique in-person culture. Depending on role and business needs, colleagues will either work onsite, in a hybrid model (combination of in-office and virtual days) or fully virtually.

US Job Seekers/Employees - Click here to view the “Know Your Rights” poster and the Pay Transparency Policy Statement.

If the links do not work, please copy and paste the following URLs in a new browser window: https://www.dol.gov/agencies/ofccp/posters to access the three posters.

Employment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions.