Senior Associate -CyberOps & Assurance
The Enterprise Technology Services organization partners with every part of the American Express business to power the company’s growth and innovation with trust and efficiency, and drive competitive differentiation with speed. We support the delivery and operations of technology, digital, and data capabilities, platforms, and services globally. Specifically, our team is responsible for the company’s technology engineering, architecture, and infrastructure, providing 24x7 support to ensure an uninterrupted, high-quality experience for customers and colleagues. We also provide product management for core enterprise platforms, and lead technology risk and information security, enterprise data governance and platforms, digital product and design, and enterprise AI platforms on behalf of the company.
The Third Party Security Executive Escalations and Reporting team is responsible for delivering meaningful insights, risk communications, and data-driven reporting to enable effective management of third-party cyber risk across the enterprise.
This role supports the ongoing evolution of Third Party Security Overwatch (TPSO) reporting and intelligence capabilities through cyber risk reporting, analytics, data management, quality control, and AI-enabled operational enhancements. This individual will assist in maintaining reporting frameworks that provide visibility into third-party cyber risk across business portfolios while helping ensure the accuracy, integrity, and quality of TPSO data and reporting processes. This role will also support the Third Party Security Overwatch product through data validation, reporting support, and technical activities that enable critical reporting and analytics capabilities. Working closely with team members and stakeholders, this individual will contribute to process improvements, automation initiatives, data visualization efforts, and AI-enabled solutions that enhance operational efficiency and strengthen TPSO reporting and intelligence functions.
- Support an evolving enterprise reporting framework that delivers meaningful third-party cyber risk metrics, dashboards, and analyses to leadership, business units, market areas, risk management committees, and other internal stakeholders.
- Generate, analyze, and communicate key risk metrics designed to measure the cyber health of third-party portfolios and support informed risk-based decision-making.
- Support delivery of clear and impactful risk communications, executive presentations, and reporting deliverables tailored for various stakeholder audiences.
- Support the Third Party Security Overwatch product through data management, validation, quality assurance, enhancement activities, and operational support.
- Perform data analysis and validation activities to ensure the integrity, completeness, and accuracy of TPSO reporting data.
- Identify and resolve data quality issues while driving continuous improvement opportunities across reporting processes.
Execute scripts, automation routines, and technical activities required to support TPSO data ingestion, validation, and reporting processes.
- Utilize AI-assisted reporting, documentation, and analytical capabilities to improve operational reporting processes and stakeholder insights.
- Apply effective prompt design practices to optimize reporting accuracy, efficiency, relevance, and consistency while validating AI-generated outputs against cybersecurity, risk, and compliance requirements.
- Support AI enablement initiatives that enhance reporting capabilities, workflow efficiency, stakeholder engagement, and operational intelligence.
- Contribute to the design and delivery of data visualization solutions that improve understanding of third-party cyber risk trends and exposures.
- Collaborate on strategic initiatives that advance the maturity of TPSO reporting, intelligence, automation, and governance capabilities.
- Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, Data Analytics, Business Analytics, Information Management, or a related field, or equivalent work experience.
- Knowledge of cybersecurity principles, third-party risk management, regulatory compliance requirements, and security standards.
- Understanding of regulatory and industry frameworks including PCI-DSS, ISO 27001, NIST, and related cybersecurity standards.
- Strong analytical and problem-solving skills with the ability to translate complex data into meaningful business insights.
- Strong written and verbal communication skills with the ability to present technical and risk-related information to diverse audiences.
- Experience with reporting and data visualization tools such as Power BI, Tableau, Excel, or similar platforms.
Experience with scripting and automation technologies such as Python, PowerShell, SQL, or comparable tools used for data management and operational processes.
- Experience leveraging AI-assisted reporting, documentation, analytics, or workflow automation capabilities.
- Experience applying prompt engineering or prompt design techniques to improve the effectiveness of AI-enabled reporting and operational processes.
- Understanding of Generative AI security risks, responsible AI practices, and governance considerations associated with AI-enabled technologies and data protection.