Jobs and Careers
AM

Audit Manager - Cybersecurity Operations & Assurance

American Express
United Statesfull_timeVerifiedPosted 8 Jul 2025
💰 $190,000/yr($110,000/yr$190,000/yr)

About the role

Audit Manager - Cybersecurity Operations & Assurance-25011759

Description

 

At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.

Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

How will you make an impact in this role?

We are seeking a highly organized and strategic Manager of Audit and Regulatory Coordination to join our Cyber Readiness team. This role is critical in ensuring our cybersecurity operations and incident response program functions align with internal audit requirements, external regulatory expectations, and industry best practices. The ideal candidate will serve as the primary liaison between all cyber operations teams, internal audit, compliance, and external regulators, ensuring timely and accurate responses to daily audit requests, strong communication across all stakeholders, detailed documentation management, and remediation tracking. 

Key Responsibilities:

Audit & Regulatory Engagement: 

  • Act as the central point of contact for all audit and regulatory inquiries related to cybersecurity incidents and response processes. 
  • Coordinate responses to internal and external audits, regulatory exams, and third-party assessments.
  • Ensure timely delivery of documentation, evidence, and responses to findings or requests.

Governance & Documentation:

  • Maintain and continuously improve documentation related to incident response policies, procedures, and playbooks. 
  • Ensure alignment with global regulatory frameworks such as DORA, OSFI E-21, FFIEC, NIST CSF, and others.
  • Track and report on remediation efforts and control improvements stemming from audit and regulatory findings.

Leadership & Management: 

  • Help oversee and indirectly manage a small team of specialists in audit responses to fulfill daily operations and provide quality assurance support. 
  • Provide leadership direction and development support for colleagues on the team and coordinate with other leaders within the Cyber Readiness team and across other cybersecurity operations groups.

Cross-Functional Collaboration: 

  • Partner with Legal, Compliance, Risk, Privacy and Technology teams to ensure consistent messaging and alignment on regulatory matters. 
  • Support the development of group management-level reporting and senior executive materials related to audit activities for incident response readiness and compliance.

Continuous Improvement: 

  • Monitor changes in the regulatory landscape and proactively assess their impact on incident response operations. 
  • Lead initiatives to enhance audit readiness and regulatory compliance posture 

Minimum Qualifications: 

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field And/ OR equivalent experience. 
  • 5-7+ years of experience in cybersecurity, audit, compliance, or risk management within a large enterprise. 
  • Strong understanding of cybersecurity incident response frameworks and regulatory requirements (e.g., DORA, OSFI, FFIEC, NYDFS, GDPR). 
  • Strong familiarity with GRC tools (e.g., Archer, ServiceNow GRC).
  • Experience managing audits and regulatory exams in a highly regulated industry. 
  • Excellent communication, pr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

American Express

View company profile →