Manager, Tech Risk and Control

1 week ago


Sydney, Australia American Express Full time

At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.

Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

**How will you make an impact in this role?**

The Manager - Tech Risk and Control function resides within the Regional Information Security Office and is responsible for control enforcement, cybersecurity awareness, reporting and enablement for American Express in Australia and New Zealand. The incumbent will be responsible for helping design and execute a regionalized information security risk management strategy closely informed by the APAC regulatory landscape and AXP business interests, including third party service providers, affiliates, and legal entities.

**Key responsibilities include**:

- Assist with the interconnection between core enterprise information security functions and American Express Asia-pacific legal entities
- Contribute to the first line information security risk management and reporting
- Assess the design and operating effectiveness of information security controls upon which the American Express Asia-pacific legal entities rely to protect Confidentiality, Availability, and Integrity of Information and Systems
- Collaborate with General Counsel, Market Compliance, and the American Express Privacy Office to support market regulatory requirements
- Lead the information security related aspects of regulatory changes and projects
- Identify, scope, and investigate new information security risks, including assisting with assessment of key American Express third-party providers in the region
- Deliver leadership reporting and risk metrics that demonstrate the effectiveness of the cyber security program to American Express Asia-pacific legal entities.
- Consult on market-specific Business & Technologies projects to ensure appropriate security protection
- Craft responses to Information Security audit and examination requirements for the market
- Operate as part of the extended Information Security team in support of all security and compliance initiatives
- Collaborate with global teams to publish market specific Information Security KPIs/KRIsParticipate in represent regional information security office in APAC risk committees

**Required Skills**:

- 5-10 years of Information Security and/or Data Privacy
- Experience working with regulators, such as METI, in complex regulated businesses
- Strong in risk management. Ability to link threats to risk tolerance and control effectiveness measurements.Understanding of cyber regulatory landscape

**Required Work Experience, Education, Certification / Training**:

- Bachelor’s degree in computer science, information systems, network security or other related field. Master’s degree preferred
- Professional certifications (CISSP, CRISC, CISA, PCI, CISM or equivalent)
- At least 5 years’ work experience in information security or technology risk management
- Technical background with hands-on experience across a variety of technologiesProficiency in information security, risk management and audit (risk/security policies, procedures and controls)

**Required Knowledge, Skills and Abilities**:

- Exceptional verbal and written communication skills
- Ability to lead and drive discussions on technical matter with senior business stakeholders along with partners and regulators
- Fluency English language
- Requires knowledge of a minimum of several business and technical functional capabilities in some of the following areas: security architecture; security engineering; threat management; vulnerability management; electronic discovery; computer and data breach incident management; data protection; forensics; 3rd party/vendor management; security monitoring; cryptography; cloud security; security operations and administration; access management; security policies and standards; security awareness; business continuity; disaster recovery; IT risk management and controls; web security; data security; network security; system security, technology operations and compliance
- Strong knowledge and experience in risk assessment and relevant methodologies including quantitative risk management techniques
- Knowledge of applicable information security standards and regulatory requirements
- Highly self-motivated and directed
- Keen attention to detail

We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:

- Competiti



  • Sydney, Australia x15ventures Full time

    Risk and Controls Manager (Tech and Cyber) x15ventures **Risk and Controls Manager (Tech and Cyber) x15ventures** - You are a problem solver with a strong technology background - You are eager to learn and upskill fast and passionate about driving great risk outcomes. - Access a workplace that lets you drive and deliver ideas and innovation. **Let's...


  • Sydney, New South Wales, Australia American Express Full time $120,000 - $180,000 per year

    At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new...


  • Sydney, New South Wales, Australia American Express Full time $150,000 - $200,000 per year

    At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new...

  • Risk Manager

    1 week ago


    Sydney, Australia Insignia Financial Full time

    Risk Manager - Tech and Cyber - Play a key role in the risk transformation of Insignia Financial - Permanent Full-Time role - Location Agnostic **The Role** To assist the Risk Management team in creating and overseeing robust governance risk and compliance frameworks. Support business units in embedding and operating the frameworks, with a particular focus...


  • Sydney, New South Wales, Australia Tech Aalto Full time $150,000 - $200,000 per year

    Security Risk AssuranceRole-The Senior Cyber Security Risk Assurance Lead is hands-on and multi disciplined, assessing complex technical issues and performing cyber security risk assessments across a wide range of initiatives in a fast-paced, complex environment.• Performing cyber security risk assessments across multiple projects.• Collaborating with...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time $120,000 - $180,000 per year

    Senior Manager, CCO Engineering, SRE and Tech RiskDo work that mattersThe Technology Chief Controls Office (TCCO) is a Line 1 risk team responsible for ensuring new and changing initiatives are assessed and that appropriate risk mitigations are in place.This role sits within the Chief Technology Office (CTO) Centre of Excellence of TCCO and partners closely...

  • Credit Controller

    1 week ago


    Sydney, Australia Tetra Tech Full time

    Key business performance role supporting our Australia and New Zealand business - Member of ANZ Financial team - Part-time 6-month contract (3 days per week) **About the role** Tetra Tech is a premier worldwide consulting and engineering firm that leads with science to create positive, impactful change as we address the world’s most complex...


  • Sydney, Australia ING Full time

    The Technology Risk Manager - Regulatory is directly engaged to support management with regard to Regulatory reviews, issues registration and controls environment. In this position, the Technology Risk Manager - Regulatory will have a deep understanding of the ING business model, risk & control governance and Technology Regulatory compliance landscape. They...


  • Sydney, Australia Control Risks Full time

    Control Risks' Embedded Consulting Practice is growing in Sydney, and we have a great opportunity for someone with a few years of experience in the areas of crisis management, risk management, or corporate security to join our team. As part of a regional team, this role will be embedded within a multinational tech client and will provide structured and...

  • Manager, Risk

    2 days ago


    Sydney, Australia AMP Limited Full time

    **The opportunity** The purpose of this role is to support the Super & Retirement business in effectively identifying, managing and reporting on its risks and controls to enable the Director, Super & Retirement to have confidence that risks are managed effectively within risk appetite and in support of the Superannuation Trustee’s strategy and business...