Director - Tech Compliance Regulatory Change Management (Banking Regulations/ First Line of Defense (1LOD))
American ExpressAbout the role
Description
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
Technology Control & Compliance is seeking an experienced and strategic Director – First Line of Defense (1LOD) Compliance professional to lead our efforts in ensuring all technological & cybersecurity operations, systems, and innovations within the bank adhere to applicable laws, regulations, and internal policies.
This role is responsible for developing, implementing, and overseeing the bank's 1LoD technology & cybersecurity compliance change program, ensuring adherence to a complex array of global and domestic laws and regulations, industry standards, internal policies, and bridging the gap between technological advancement and regulatory imperatives. The ideal candidate will possess a deep understanding of cybersecurity & technology industry frameworks, banking & financial regulations, and risk management principles. You will be a proactive leader, capable of translating complex regulatory requirements into actionable compliance strategies and fostering a culture of security and compliance throughout the organization.
Key Responsibilities:
- Strategic Leadership: Develop and execute the enterprise technology & cybersecurity compliance change strategy, aligning with business objectives and evolving regulatory requirements (e.g., FFIEC, GLBA, Dodd-Frank, OCC bulletins, FRB guidance, GLBA, NYDFS, GDPR, CCPA, etc).
- Regulatory Interpretation & Implementation: Monitor, interpret, and disseminate information on new and updated technology and cybersecurity regulations, laws, and industry standards relevant to the financial & banking sectors. Translate these requirements into practical, implementable controls and policies. Conduct a gap analysis of the current control framework against new regulatory requirements and drive the action required to achieve adherence.
- Emerging Technology Compliance: Proactively assess and provide guidance on the compliance implications of adopting new and emerging technologies (e.g., AI/ML, blockchain, RPA, advanced analytics).
- Advisory: Proactively identify and assess technology & cybersecurity compliance risks inherent in products, services, processes, and controls.
- Countermeasures: Consult with business leadership and second line compliance to design and implement effective controls and mitigation strategies.
- Assurance: Support the execution of business-level compliance risk assessments and control self-assessments.
Qualifications:
- 7–10+ years of compliance, legal, or regulatory advocacy & industry engagement experience within a financial institution, preferably in a business-aligned or first line of defense role.
- Deep expertise in banking regulations and compliance frameworks, including but not limited to:
- Gramm-Leach-Bliley Act (GLBA)
- NYDFS Cybersecurity Regulation (23 NYCRR Part 500)
· FFIEC IT Handbooks (e.g., Operations, Audit, Development and Acquisition, Business Continuity, Outsourcing, Cybersecurity)
· OCC Bulletins and Consent Orders related to technology
·
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s