American Express-posted 4 months ago
$85,000 - $150,000/Yr
Full-time • Mid Level
Phoenix, AZ
Credit Intermediation and Related Activities

At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express. American Express is on an exciting cloud transformation journey driven today by a successful, high-energy, delivery-focused team that enables our vision of security-as-code and integrations across a diverse set of teams and tools to ensure public cloud security equivalency with on-premises security capabilities, methods, and processes for all cloud service models (IaaS, PaaS, SaaS) and workloads. The Cloud Security Sr. Associate will collaboratively lead the Strategic Program Management, Governance, and Operations functions of the technology risk and cyber security controls and capabilities required to secure the American Express cloud journey, including both our private/public cloud. The Cloud Security Sr. Associate will play a key role in leading cloud security compliance initiatives across American Express's private and public cloud environments. This position will focus on ensuring adherence to regulatory, audit, and internal policy requirements by working collaboratively across security domain teams, technology partners, and external cloud providers. The successful candidate will be responsible for driving cloud compliance strategy, governance, and oversight, with a primary emphasis on preparing and delivering audit responses for cloud security. This includes coordinating with Cloud Engineering, Cloud Operations, Information Security teams, and enterprise risk partners to ensure alignment with a standardized, risk-based compliance model.

  • Lead the implementation of processes and methods for auditing and addressing non-compliance to information security standards and methodologies; facilitate migration of non-compliant environments to compliant environments
  • Leads and prepares materials (reports, presentations, spreadsheets, etc) to enable informed decision-making; guide the verification of completeness, accuracy and relevance of data gathered
  • Maintains internal documentation to ensure that process and other documentation is regularly updated to reflect the latest operational processes and requirements
  • Provides analytical guidance as needed for issue management, project assessments, and reporting
  • Facilitates and collaborates with cross-functional teams for finding remediation efforts
  • Provides advice on controls, standards, processes, and procedures
  • Deliver a broad range of communications including technology strategy updates, and employee communications
  • Drive organizational optimization and business process improvement
  • Act as a mentor and coach for employees and assist them in solving business problems
  • Execute on operational risk activities such as conducting risk assessment with the business, mapping of processes, identification of risks, and definition and testing of controls
  • Engages and Coordinates audit related activities
  • Keeps abreast of Regulatory changes and requirements.
  • 4+ years of experience in Information Security Roles
  • Experience with Cloud Control Matrix and CIS benchmarks for gap assessment
  • Broad understanding of all IS disciplines including, Governance, Cyber Threat, Identity and Access, Infrastructure, Endpoint, Vulnerability, Data Protection, Operations, Application, Incident Response.
  • Experience working with auditors and regulators
  • Understanding of Cloud Fundamentals, including containers, software-defined networks, high availability design, multi-cloud, and serverless compute.
  • Demonstrated experience in Agile environments, application design, software development, and testing.
  • Information Security Certification preferred, CISM or similar.
  • Competitive base salaries
  • Bonus incentives
  • 6% Company Match on retirement savings plan
  • Free financial coaching and financial well-being support
  • Comprehensive medical, dental, vision, life insurance, and disability benefits
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service