Job Description
Work Location Options :
Hybrid
You Lead the Way. Weve Got Your Back.
With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, youll learn and grow as we help you create a career journey thats unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.
At American Express, youll be recognized for your contributions, leadership, and impactevery colleague has the opportunity to share in the companys success. Together, well win as a team, striving to uphold our and powerful backing promise to provide the worlds best customer experience every day. And well do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.
Join Team Amex and let's lead the way together.
Information Security Manager (Regional Information Security Office)
The Information Security Manager function resides within the Regional Information Security Office and is responsible for control enforcement, cybersecurity awareness, reporting and enablement for American Express in Japan. The incumbent will be responsible for helping design and execute a regionalized information security risk management strategy closely informed by the APAC regulatory landscape and AXP business interests, including third party service providers, affiliates, and legal entities.
Key responsibilities include :
- Assist with the interconnection between core enterprise information security functions and American Express Asia-pacific legal entities
- Contribute to the first line information security risk management and reporting
- Assess the design and operating effectiveness of information security controls upon which the American Express Asia-pacific legal entities rely to protect Confidentiality, Availability, and Integrity of Information and Systems
- Collaborate with General Counsel, Market Compliance, and the American Express Privacy Office to support market regulatory requirements
- Lead the information security related aspects of regulatory changes and projects
- Identify, scope, and investigate new information security risks, including assisting with assessment of key American Express third-party providers in the region
- Deliver leadership reporting and risk metrics that demonstrate the effectiveness of the cyber security program to American Express Asia-pacific legal entities.
- Consult on market-specific Business & Technologies projects to ensure appropriate security protection
- Craft responses to Information Security audit and examination requirements for the market
- Operate as part of the extended Information Security team in support of all security and compliance initiatives
- Collaborate with global teams to publish market specific Information Security KPIs / KRIs
- Participate in represent regional information security office in APAC risk committees
- Participate in meetings with regulatory bodies in Japan and present Information security posture of American Express
Required Skills :
5-10 years of Information Security experienceExperience working with regulators, such as METI, in complex regulated businessesBroad understanding of information security disciplines with emphasis on vulnerability management, data protection, infrastructure security, application security, identity and access, incident management and data analyticsStrong in risk management. Ability to link threats to risk tolerance and control effectiveness measurements.Understanding of cyber regulatory landscape in JapanRequired Work Experience, Education, Certification / Training :
Bachelors degree in computer science, information systems, network security or other related field. Masters degree preferredProfessional certifications (CISSP, CRISC, CISA, PCI, CISM or equivalent)At least 5 years work experience in information security or technology risk managementTechnical background with hands-on experience across a variety of technologiesProficiency in information security, risk management and audit (risk / security policies, procedures and controls)Required Knowledge, Skills and Abilities :
Exceptional verbal and written communication skillsAbility to lead and drive discussions on technical matter with senior business stakeholders along with partners and regulatorsFluency in Japanese and English languageRequires knowledge of a minimum of several business and technical functional capabilities in some of the following areas : security architecture; security engineering; threat management; vulnerability management; electronic discovery; computer and data breach incident management; data protection; forensics; 3rd party / vendor management; security monitoring; cryptography; cloud security; security operations and administration; access management; security policies and standards; security awareness; business continuity; disaster recovery; IT risk management and controls; web security; data security; network security; system security, technology operations and complianceStrong knowledge and experience in risk assessment and relevant methodologies including quantitative risk management techniquesKnowledge of applicable information security standards and regulatory requirementsHighly self-motivated and directedKeen attention to detailWe back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include :
Competitive base salariesBonus incentivesSupport for financial-well-being and retirementComprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)Flexible working model with hybrid, onsite or virtual arrangements depending on role and business needGenerous paid parental leave policies (depending on your location)Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)Free and confidential counseling support through our Healthy Minds programCareer development and training opportunitiesOffer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.
Other Jobs You May Be Interested In
Information Security Manager - Technology Exam and Findings Management
Sandy, Utah, United States and 1 more
Director - Technology Regulatory, Audit, and Review Engagement
Phoenix, Arizona, United States and 1 more
Coordinator-Security Operations
Minato-ku, Tokyo, Japan
Information Security Analysts
New York, New York, United States
AML Specialist, Compliance
Minato-ku, Tokyo, Japan
Analyst - Marketing (Regular Consumer Card)
Minato-ku, Tokyo, Japan
Director & Counsel
Minato-ku, Tokyo, Japan
Manager Credit Risk Management
Minato-ku, Tokyo, Japan
Manager, Enterprise Risk Management, Japan
Minato-ku, Tokyo, Japan
Slide 1 of 3When you become part of our Talent Community, well keep you posted about future job opportunities that you may be a match for, as well as career-related events.