American Express
Manager Technology Cybersecurity Compliance 1LOD Compliance Function
American Express, Charlotte, North Carolina, United States, 28245
You lead the way. We've got your back.
At American Express, our culture is built on a 175-year history of innovation, shared and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
American Express is seeking a dynamic and detail-oriented Technology and / or Cybersecurity Compliance Manager to join the First Line of Defense (1LOD) Compliance Function. This position will contribute to overseeing regulatory change management for Enterprise Technology Services, ensuring that day-to-day business operations are compliant with regulatory standards and internal policies.
The role requires strong execution capability, a solid understanding of regulatory frameworks, and a collaborative mindset to support cross-functional compliance needs. The role holder will be dedicated to ensuring adherence to a complex array of global and domestic laws and regulations, industry standards, internal policies, and bridging the gap between technological advancement and regulatory imperatives. The ideal candidate will possess a deep understanding of cybersecurity & technology industry frameworks, banking & financial regulations, and risk management principles.
Key Responsibilities
Regulatory interpretation & implementation :
Execute compliance risk identification, assessment, and mitigation processes within the 1LOD Compliance function.
Partner with 2LOD Compliance and Legal teams for policy interpretation, regulatory developments, and incident response.
Drive the regulatory change management efforts by evaluating applicability, conducting impact assessments, identifying potential gaps, coordinating with stakeholders, and implementing required changes.
Countermeasures & advisory :
Advise on the design and implementation of controls to address emerging risks or regulatory updates.
Monitor and test key compliance controls in collaboration with operations and risk partners.
Maintain up-to-date compliance documentation, including policies, procedures, and control descriptions.
Assurance :
Prepare and deliver compliance metrics and risk reporting for governance forums and senior leadership.
Contribute to audit and exam readiness and support internal and external reviews.
Minimum Qualifications :
3+ years of experience in technology and / or cybersecurity compliance, regulatory risk, or related control roles in financial services.
Solid understanding of and experience with technology and cybersecurity regulatory and industry frameworks :
Gramm-Leach-Bliley Act (GLBA)
NYDFS Cybersecurity Regulation (23 NYCRR Part 500)
FFIEC IT Handbooks (e.g., Development and Acquisition, Business Continuity, Outsourcing, Cybersecurity)
OCC Bulletins and Consent Orders related to technology
FRB guidance on technology risk management
Global and domestic data privacy regulations (e.g., GDPR, CCPA, state-specific privacy laws)
Operational Resilience frameworks (e.g., from FRB, OCC, FDIC, other supra-national and national regulatory bodies)
NIST Cybersecurity Framework (CSF)
ISO 27001 / 27002
PCI DSS
Experience in issue management, regulatory change implementation, or control enhancement.
Preferred Qualifications :
Bachelor’s degree in computer science, cybersecurity, law, or related discipline.
Compliance, technology or cybersecurity certifications (e.g., CRCM, CAMS, CCEP, CISSP, CISM, CIS, CISA, CRISC, CGEIT).
Familiarity with GRC tools (e.g., ServiceNow, Archer, OpenPages).
Experience working in a centralized or business-aligned 1LOD Compliance or control team.
Proven ability to collaborate across functions in a matrixed environment.
Strong analytical and critical thinking skills
Effective written and verbal communication
Ability to manage multiple compliance workstreams simultaneously
Strong attention to detail and organizational discipline
Relationship-building and influence across business and risk stakeholders
Judgment to elevate issues appropriately and guide remediation
Guardian
Salary Range :
$123,000.00 to $215,250.00 annually + bonus + benefits
The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.
We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally :
Competitive base salaries
Bonus incentives
6% Company Match on retirement savings plan
Free financial coaching and financial well-being support
Comprehensive medical, dental, vision, life insurance, and disability benefits
Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
Free and confidential counseling support through our Healthy Minds program
Career development and training opportunities
#J-18808-Ljbffr
At American Express, our culture is built on a 175-year history of innovation, shared and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
American Express is seeking a dynamic and detail-oriented Technology and / or Cybersecurity Compliance Manager to join the First Line of Defense (1LOD) Compliance Function. This position will contribute to overseeing regulatory change management for Enterprise Technology Services, ensuring that day-to-day business operations are compliant with regulatory standards and internal policies.
The role requires strong execution capability, a solid understanding of regulatory frameworks, and a collaborative mindset to support cross-functional compliance needs. The role holder will be dedicated to ensuring adherence to a complex array of global and domestic laws and regulations, industry standards, internal policies, and bridging the gap between technological advancement and regulatory imperatives. The ideal candidate will possess a deep understanding of cybersecurity & technology industry frameworks, banking & financial regulations, and risk management principles.
Key Responsibilities
Regulatory interpretation & implementation :
Execute compliance risk identification, assessment, and mitigation processes within the 1LOD Compliance function.
Partner with 2LOD Compliance and Legal teams for policy interpretation, regulatory developments, and incident response.
Drive the regulatory change management efforts by evaluating applicability, conducting impact assessments, identifying potential gaps, coordinating with stakeholders, and implementing required changes.
Countermeasures & advisory :
Advise on the design and implementation of controls to address emerging risks or regulatory updates.
Monitor and test key compliance controls in collaboration with operations and risk partners.
Maintain up-to-date compliance documentation, including policies, procedures, and control descriptions.
Assurance :
Prepare and deliver compliance metrics and risk reporting for governance forums and senior leadership.
Contribute to audit and exam readiness and support internal and external reviews.
Minimum Qualifications :
3+ years of experience in technology and / or cybersecurity compliance, regulatory risk, or related control roles in financial services.
Solid understanding of and experience with technology and cybersecurity regulatory and industry frameworks :
Gramm-Leach-Bliley Act (GLBA)
NYDFS Cybersecurity Regulation (23 NYCRR Part 500)
FFIEC IT Handbooks (e.g., Development and Acquisition, Business Continuity, Outsourcing, Cybersecurity)
OCC Bulletins and Consent Orders related to technology
FRB guidance on technology risk management
Global and domestic data privacy regulations (e.g., GDPR, CCPA, state-specific privacy laws)
Operational Resilience frameworks (e.g., from FRB, OCC, FDIC, other supra-national and national regulatory bodies)
NIST Cybersecurity Framework (CSF)
ISO 27001 / 27002
PCI DSS
Experience in issue management, regulatory change implementation, or control enhancement.
Preferred Qualifications :
Bachelor’s degree in computer science, cybersecurity, law, or related discipline.
Compliance, technology or cybersecurity certifications (e.g., CRCM, CAMS, CCEP, CISSP, CISM, CIS, CISA, CRISC, CGEIT).
Familiarity with GRC tools (e.g., ServiceNow, Archer, OpenPages).
Experience working in a centralized or business-aligned 1LOD Compliance or control team.
Proven ability to collaborate across functions in a matrixed environment.
Strong analytical and critical thinking skills
Effective written and verbal communication
Ability to manage multiple compliance workstreams simultaneously
Strong attention to detail and organizational discipline
Relationship-building and influence across business and risk stakeholders
Judgment to elevate issues appropriately and guide remediation
Guardian
Salary Range :
$123,000.00 to $215,250.00 annually + bonus + benefits
The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.
We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally :
Competitive base salaries
Bonus incentives
6% Company Match on retirement savings plan
Free financial coaching and financial well-being support
Comprehensive medical, dental, vision, life insurance, and disability benefits
Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
Free and confidential counseling support through our Healthy Minds program
Career development and training opportunities
#J-18808-Ljbffr