Logo
American Express

Manager Technology Cybersecurity Compliance 1LOD Compliance Function

American Express, Charlotte, North Carolina, United States, 28245

Save Job

You lead the way. We've got your back.

At American Express, our culture is built on a 175-year history of innovation, shared and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.

Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

How will you make an impact in this role?

American Express is seeking a dynamic and detail-oriented Technology and / or Cybersecurity Compliance Manager to join the First Line of Defense (1LOD) Compliance Function. This position will contribute to overseeing regulatory change management for Enterprise Technology Services, ensuring that day-to-day business operations are compliant with regulatory standards and internal policies.

The role requires strong execution capability, a solid understanding of regulatory frameworks, and a collaborative mindset to support cross-functional compliance needs. The role holder will be dedicated to ensuring adherence to a complex array of global and domestic laws and regulations, industry standards, internal policies, and bridging the gap between technological advancement and regulatory imperatives. The ideal candidate will possess a deep understanding of cybersecurity & technology industry frameworks, banking & financial regulations, and risk management principles.

Key Responsibilities

Regulatory interpretation & implementation :

Execute compliance risk identification, assessment, and mitigation processes within the 1LOD Compliance function.

Partner with 2LOD Compliance and Legal teams for policy interpretation, regulatory developments, and incident response.

Drive the regulatory change management efforts by evaluating applicability, conducting impact assessments, identifying potential gaps, coordinating with stakeholders, and implementing required changes.

Countermeasures & advisory :

Advise on the design and implementation of controls to address emerging risks or regulatory updates.

Monitor and test key compliance controls in collaboration with operations and risk partners.

Maintain up-to-date compliance documentation, including policies, procedures, and control descriptions.

Assurance :

Prepare and deliver compliance metrics and risk reporting for governance forums and senior leadership.

Contribute to audit and exam readiness and support internal and external reviews.

Minimum Qualifications :

3+ years of experience in technology and / or cybersecurity compliance, regulatory risk, or related control roles in financial services.

Solid understanding of and experience with technology and cybersecurity regulatory and industry frameworks :

Gramm-Leach-Bliley Act (GLBA)

NYDFS Cybersecurity Regulation (23 NYCRR Part 500)

FFIEC IT Handbooks (e.g., Development and Acquisition, Business Continuity, Outsourcing, Cybersecurity)

OCC Bulletins and Consent Orders related to technology

FRB guidance on technology risk management

Global and domestic data privacy regulations (e.g., GDPR, CCPA, state-specific privacy laws)

Operational Resilience frameworks (e.g., from FRB, OCC, FDIC, other supra-national and national regulatory bodies)

NIST Cybersecurity Framework (CSF)

ISO 27001 / 27002

PCI DSS

Experience in issue management, regulatory change implementation, or control enhancement.

Preferred Qualifications :

Bachelor’s degree in computer science, cybersecurity, law, or related discipline.

Compliance, technology or cybersecurity certifications (e.g., CRCM, CAMS, CCEP, CISSP, CISM, CIS, CISA, CRISC, CGEIT).

Familiarity with GRC tools (e.g., ServiceNow, Archer, OpenPages).

Experience working in a centralized or business-aligned 1LOD Compliance or control team.

Proven ability to collaborate across functions in a matrixed environment.

Strong analytical and critical thinking skills

Effective written and verbal communication

Ability to manage multiple compliance workstreams simultaneously

Strong attention to detail and organizational discipline

Relationship-building and influence across business and risk stakeholders

Judgment to elevate issues appropriately and guide remediation

Guardian

Salary Range :

$123,000.00 to $215,250.00 annually + bonus + benefits

The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally :

Competitive base salaries

Bonus incentives

6% Company Match on retirement savings plan

Free financial coaching and financial well-being support

Comprehensive medical, dental, vision, life insurance, and disability benefits

Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need

20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy

Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)

Free and confidential counseling support through our Healthy Minds program

Career development and training opportunities

#J-18808-Ljbffr