Manager-CyberOps & Assurance- Third Party Security
American ExpressAbout the role
Description
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
The Third-Party Security (TPS) team within American Express’s Technology Risk and Information Security (TRIS) organization is a high-energy, results-driven group dedicated to minimizing cybersecurity risk across the company’s third-party ecosystem. TPS leads key functions including information security due diligence, contracting, ongoing monitoring, and reporting. This role sits on the Contracts & Strategy team and plays a critical part in advancing TPS’s cybersecurity risk strategy and roadmap while supporting complex contract negotiations. In this role, you will drive negotiations of Information Protection Contract Requirements (IPCR) with third parties and build strong partnerships with the General Counsel’s Office (GCO) and TRIS. You will advise stakeholders on contract-related risks and collaborate cross-functionally with Business Unit leaders, Executive Relationship Owners (EROs), Third-Party Relationship Managers (TRMs), Global Supply Management (GSM), and Line of Defense teams. You will also shape and execute the TPS cyber risk strategy and three-year roadmap, working across the organization to strengthen Amex’s overall third-party security posture.
Responsibilities Include:
- Partner with the General Counsel Organization (GCO) to support negotiation of Information Security (IPCR) terms in contracts with third parties.
- Analize multiple sources of information during contract negotiations to identify, understand, and communicate risks, contract requirements, gaps or deficiencies, and mitigating controls.
- Collaborate with extended Third-Party Security Team
- Collaborate across the contract and product review lifecycles as needed, including by identifying mitigating controls, identifying potential control gaps across TRIS domains.
- Lead forums with key stakeholders to enhance third party security diligence oversight, contracting, documentation and risk memo processes.
- Identify exciting opportunities for adopting new technologies to solve existing needs and predicting future challenges.
- Evaluate emerging information security developments and help assess the impacts and relevance to American Express to stay ahead of new policies and regulations.
- Partner with GCO to ensure up-to-date protections are in place for data protection and Information Security in third party contracts.
- Assist in the strategic development and maturation of a robust third-party cyber risk operating model that enables the enterprise to develop and implement security solutions and capabilities that are clearly aligned with business, technology, and threat drivers.
- Serve as the IS expert to assist key stakeholders, business unit leaders, and others in understanding the IS processes and requirements for third parties.
Minimum Qualifications:
- Strong communications skills, in both wri
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s