Job DescriptionJoining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Technology organization enables and accelerates the company's growth strategies, delivering global capabilities and services in support of Amex's customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.
At American Express, our mission is to deliver the world's best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage-empowering you to innovate, grow, and help shape the future of a Fortune 100 company.
Trust. Service. Security.We are seeking an experienced and results-oriented
Sr Associate, Cyber Ops & Assurance to join the Identity Access and Lifecycle Management team to ensure first-line defense cybersecurity operational goals are met, work with cross-functional teams and utilize AI tools to strengthen the effectiveness of controls through metrics. The ideal candidate will have a strong background in control management, automation of testing through metric creation, stakeholder engagement, with AI data skills that sit at the intersection of risk, controls and process automation, and the ability to navigate a fast-paced, matrixed environment.
ResponsibilitiesControl Documentation Review & Risk & Control Self-Assessment (RCSA) Readiness- Review cybersecurity control documentation to ensure completeness, clarity, and alignment prior to RCSA submission.
- Validate that controls are properly designed, testable, and mapped to relevant risks, regulatory requirements, and policies.
- Identify documentation gaps, inconsistencies, or unclear control language; partner with control owners to remediate.
- Ensure documentation is audit-ready, with appropriate evidence and traceability.
Automated Metrics Development- Evaluate and drive opportunities through the design of automated metrics for strengthening control effectiveness.
- Partner with data and technology teams to source and validate data used in metrics.
- Support implementation of continuous control monitoring capabilities through data-driven approaches.
- Define and track KPIs/KRIs such as control performance trends, exception volumes, and remediation timeliness.
Data Analysis, Insights & Reporting- Analyze control testing outputs and cybersecurity telemetry to identify trends, anomalies, and emerging risks.
- Produce dashboards and reports that provide clear visibility into control health and operational risk posture.
- Communicate insights and recommendations to control owners in a concise, risk-informed manner.
Continuous Improvement & Automation- Identify opportunities to enhance documentation quality and standardization in accordance with RCSA framework.
- Support the enhancement of metrics frameworks and reporting capabilities.
- Partner with engineering and tooling teams to scale automated testing and monitoring solutions.
- Contribute to automation and efficiency initiatives related to documentation review and monitoring, and metric design to support effectiveness of controls.
Qualifications- 3+ years of experience in control management, cybersecurity, or audit response.
- Highly organized with strong design thinking and delivery for automated control testing.
- Understanding of the RCSA control processes and operational risk management concepts.
- Demonstrated ability to recognize opportunities and deliver automation of data metrics to support effectiveness of controls.
- Understanding of how AI/ML can be used to analyze control performance data and detect anomalies.
- Experience using AI tools to assist in the design of metrics and reviewing and validating control documentation and improve efficiency (e.g., NLP for completeness and consistency checks).
- Ability to interpret AI-generated outputs and apply them within a risk and governance context.
- Experience leveraging NLP or generative AI to standardize, summarize, and enhance control documentation.
- Strong Proficiency with Amex and analytical tools (e.g., Excel, PowerPoint, Archer, Service Now, SQL, Python, UI Path) and collaboration platforms (e.g., Confluence, SharePoint, Slack/Teams).
- Bachelor's degree required in Computer Science, Information Systems, Cybersecurity, and/or comparable experience.
Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.