Manager-Technology Risk & Control

Phoenix, AZ · Charlotte, NCFull-timePosted Jul 21, 2026

The Global Risk & Compliance (GRC) organization serves as American Express’ independent risk management function. GRC maintains the enterprise risk framework, provides oversight and challenge, and monitors key risks. By embedding risk discipline into strategy and operations, GRC enables responsible growth, innovation, and long-term value creation while protecting customers and shareholders.

The Technical Risk Management (TRM) team safeguards the enterprise, globally, by identifying, assessing, monitoring & reporting risks across Information & Cyber Security Risk, Technology Risk, Data Risk, Resiliency Risk, and AI Risk. 

Technology Risk Management (ITRM) is a part of TRM, and is responsible for the independent risk management across technology applications and infrastructure at American Express.

ITRM is hiring for a Sr. Manager who will lead the governance, strategy and risk management for technology risks across American Express. This Sr. Manager will also assist with supporting senior technology committees and other forums. This Sr. Manager will report to the Technology Risk Management Director and be part of the team that will manage technology risk frameworks and support core IT domains, such as IT Asset Management, IT Change Management and IT Incident Management.

Job Responsibilities:

  • Lead risk management oversight of technology risk across core IT disciplines, including IT Asset Management, IT Change Management, IT Incident Management, and emerging IT risks associated with Artificial Intelligence (AI), by leveraging AI, automation, and analytics to enable IT risk management at scale
  • Support the development of the risk management program to identify, assess, measure and monitor IT risks associated with strategic business initiatives
  • Support and coordinate content development for areas such as: Technology Committees, internal/external audits, and broader enterprise initiatives
  • Monitor laws, rules, regulations and industry best practices related to technology risk and cybersecurity risk. Support enterprise-wide programs to ensure adherence

Minimum Qualifications:

  • Bachelor’s degree in business or technology or equivalent
  • Three years of risk management experience in cybersecurity or technology across one or more lines of defense
  • Three years of experience in the financial services industry
  • Experience within Technology disciplines, such as IT Asset Management, IT Change Management, IT Incident Management or Software Delivery Lifecycle (SDLC) practices, or experience with risk management policy development

     

Preferred Qualifications:

  • Degree in Cybersecurity, Information Systems, Information Technology, Computer Science, Data Science, or equivalent
  • A cybersecurity, technology, or risk management certification (CISSP, CCSP, CEH, CISM, etc.)
  • Experience with regulatory and industry technology or cybersecurity frameworks and guidance (CRI Sector Profile, NIST, FFIEC, COBIT)

 

We train and invest in our colleagues. So go ahead and apply!

Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions. 

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free