Information Security Analyst I

American Express

Gurugram, Haryana, India Remote Hybrid

Full time



Dec 14

You Lead the Way. We’ve Got Your Back.

At American Express, we know that with the right backing, people and businesses have the power to progress in incredible ways. Whether we’re supporting our customers’ financial confidence to move ahead, taking commerce to new heights, or encouraging people to explore the world, our colleagues are constantly redefining what’s possible — and we’re proud to back each other every step of the way. When you join #TeamAmex, you become part of a diverse community of over 60,000 colleagues, all with a common goal to deliver an exceptional customer experience every day. We back our colleagues with the support they need to thrive, professionally and personally. That’s why we have Amex Flex, our enterprise working model that provides greater flexibility to colleagues while ensuring we preserve the important aspects of our unique in-person culture. Depending on role and business needs, colleagues will either work onsite, in a hybrid model (combination of in-office and virtual days) or fully virtually.

Why American Express?

Talk to our people and you’ll find out what we’re really all about. Open, creative, risk-taking, collaborative and innovative are just some of the expressions you’ll hear. It’s our culture that makes American Express an outstanding place to work, and a big part of why we regularly win best workplace awards all over the world. If you’re ready to take on a challenge and make an impact, you owe it to yourself to launch or grow your career here.

Business Overview :

The Global Risk & Compliance (GRC) group within American Express is responsible for providing oversight and governance of risks to ensure that the company operates in a safe and sound manner within regulatory expectations. In a world increasingly subject to digitalization and the use of technology, technology risk management has become increasingly significant across organizations, becoming one of the key themes at board meetings. Cyberattacks have become increasingly commonplace and the trend continues to move upward.

Role Description :

This individual contributor role is part of the second line technology risk management team within the GRC group, headed by the Chief Risk Officer (CRO) of the company. This is a unique opportunity to work with a team of diverse and talented professionals who are responsible for building the technology risk management program and providing independent risk oversight to the technology, cyber security and business continuity management risks.

Reporting to the Director for Technology Risk oversight, this position is responsible for supporting independent assessments and reporting of risks. The risks identified by this team are reported to the Senior Management, Risk Management Committees, Board of Directors and Regulators. This position will be responsible for effectively collaborating with key stakeholders across lines of business and lines of defense to ensure risks are managed effectively and efficiently in accordance with the company policies and applicable regulatory requirements.

Essential Job Functions:

  • Support independent, proactive risk management and oversight of technology, cyber security and business continuity management risks generated within business processes or that occur due to use of Technology.
  • Learn technology, cyber security and business continuity management processes at American Express, demonstrating strong levels of curiosity and willingness, in order to present an effective credible challenge.
  • Support data-driven reviews focused on technology, cyber security and business continuity management risks.
  • Support development and enhancement of data-driven key risk indicators and key performance indicators that provide real time and meaningful insights into the risk and performance trends.
  • Stay knowledgeable of relevant regulations, guidelines & industry standards.
  • Support the design of independent technology risk oversight program which defines the engagement and integration with various risk management programs, including Process Risk Self Assessments, Business Continuity Management, New Product Approval, Mergers & Acquisitions etc.

Required Qualifications: 

  • Bachelor’s / Masters Degree in computer science / information systems or related domain.
  • 1-3 years of experience in risk management across any of the three lines of defense.
  • Proven ability to identify risks, analyze issues and derive meaningful insights about risk trends by conducting interviews and analyzing large volumes of data.
  • Working knowledge of one or more of the data mining tools/technologies (e.g. Microsoft Excel: Pivot Tables SQL, SAS, Python, R).
  • Experience in risk management across cyber security, information technology, 3rd party, business continuity management.
  • Industry certifications (e.g. CISSP, CISM, CISA, CRISC).
  • Understanding of risk assessment methodologies, frameworks and industry standards (e.g. COSO, COBIT, ISO 27001, FAIR or NIST RMF).
  • Knowledge of relevant policies & regulations (e.g. OCC Heightened Standards, FFIEC IT booklets).
  • Experience with Governance, Risk and Compliance tools (e.g. Archer).

Behavioural Aspects :

  • Excellent analytical skills with high attention to detail and accuracy.
  • Excellent critical thinking and problem solving skills.
  • Excellent verbal, written and interpersonal communication skills.
  • Willingness to challenge traditional thinking by actively engaging in constructive dialogue.

Leadership Outcomes:

  • Put enterprise thinking first, connect the role’s agenda to enterprise priorities and balance the needs of customers, partners, colleagues & shareholders.
  • Lead with an external perspective, challenge status quo, and bring continuous innovation to our existing offerings
  • Demonstrate learning agility, make decisions quickly and with the highest level of integrity
  • Lead with a digital mindset and deliver the world’s best customer experiences every day.

Behavioral Skills/Capabilities:

  • Enterprise Leadership Behaviors
  • Set The Agenda: Define What Winning Looks Like, Put Enterprise Thinking First, Lead with an External Perspective
  • Bring Others With You: Build the Best Team, Seek & Provide Coaching Feedback, Make Collaboration Essential
  • Do It The Right Way: Communicate Frequently, Candidly & Clearly, Make Decisions Quickly & Effectively.

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law. 

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.

Apply for this position Back to job

You must be logged in to to apply to this job.


Your application has been successfully submitted.

Please fix the errors below and resubmit.

Something went wrong. Please try again later or contact us.

Personal Information


View resume