Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Cybersecurity Audit Director image - Rise Careers
Job details

Cybersecurity Audit Director - job 1 of 4

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

American Express’ Internal Audit Group (IAG) has reinvented our audit process and is leading the financial services industry with our Audit NextGen, Data-Driven Continuous Auditing, and Auditor of the Future initiatives. Each uniquely support our Winning Aspiration to be a world class internal audit function that:

  • Provides data-driven and technology-enabled assurance
  • Delivers timely risk insights that are business-aware and forward-looking
  • Supports our colleagues with experiences that prepare them to be enterprise leaders

Collectively, IAG’s strategic initiatives, combined with our greatest asset – our people – enable IAG to utilize advanced data analysis capabilities, provide greater and continuous assurance, and help ensure quality products and services are provided to American Express customers. 

IAG’s innovative Data-Driven Continuous Auditing approach has led to patent-pending technology assets over our uniquely developed audit methodology and technology enablers. 

We are looking for those who share our mission and aspirations and are passionate about the use of data and technology in a collaborative, people-focused environment.

About the Internal Audit Group at American Express

Our Internal Audit Group is a worldwide function with 300+ team members and offices across nine countries within American Express. Our mission is to protect and enhance organizational value by providing independent, objective, risk-based assurance, advisory services and to influence the way the company manages risk.

We are committed to growing our audit staff significantly as we continue to expand and enhance the Internal Audit Group. Our assurance and risk professionals have diverse backgrounds including internal controls, consumer compliance, technology, operational risk, financial accounting, data analytics, and banking operations. Our audit teams align to key risk areas and business units to ensure IAG can provide comprehensive and risk-based audit coverage. In addition, IAG has a Professional Practices group responsible for managing audit operations, quality, and standards; regulatory relations; reporting; training and professional development; and key internal capabilities and technologies.

About the Role:

Our Internal Audit group is seeking an eager Cybersecurity Audit Director to help advance and grow our audit coverage across our cybersecurity audit portfolio. In this role, the ideal candidate will be the team leader for auditors to provide assurance over areas such as application security, infrastructure security, cybersecurity incident readiness and response, encryption management, and cloud services. This is an exceptional opportunity for you to showcase and further expand your audit skills, and knowledge!

About the Team:

The cybersecurity audit portfolio spans the information technology through the enterprise. Audit coverage includes auditing first-line information security processes. The cybersecurity audit team is heavily focused on utilizing a data driven auditing approach across the audit portfolio.

The Key Responsibilities of the role include:

  • Lead a team of approximately five technology audit colleagues provide internal audit assurance over first-line information security processes, and deliver cybersecurity thought leadership to the team
  • Plan and lead execution of cybersecurity audits on the company annual audit plan
  • Ensure that audits delivery assurance and objectives by setting the audit scope, developing test plans, and leading colleagues to evaluate the design and operating effectiveness of cybersecurity controls, including testing control effectiveness with analytics-based testing
  • Analyze regulatory and industry cybersecurity requirements and frameworks over risk management, technology, and information security
  • Maintain the team's resources, training program, recruiting pipeline, and execute the screening and selection process
  • Monitor a portfolio of cybersecurity audit analytics, assess results, & use data to tell the business story, and work with audit and business colleagues to validate findings
  • Evaluate cybersecurity audit results, synthesize audit findings across the project, draft audit reports and ensure effective and efficient execution of audits in conformance with professional and department standards, budgets, and timelines
  • Present audit objectives, scope, and results to senior management and technology subject matter experts, clearly articulating the potential impact of control gaps in a highly professional and proficient manner
  • Assist other team leaders, senior auditors, and staff auditors in accomplishing team objectives and producing results
  • Execute multiple simultaneous global audit projects of all sizes and complexity across multiple business areas including integrated audits that consider financial, operational, compliance and technology risk
  • Effectively coach, teach, mentor and develop junior colleagues and co-sourced resources in geographically diverse locations across all aspects of their role, the audit and analytic lifecycle, audit methodology, and technology processes & controls
  • Monitor industry cybersecurity trends and emerging risks and propose potential changes to the IAG audit universe to ensure audit coverage evolves with the risk environment
  • Occasionally lead a team of approximately five technology audit colleagues provide internal audit assurance over first-line information technology general control processes
  • Assume full performance management responsibility for assigned staff

Minimum Qualifications

  • 7+ years of relevant technology audit experience
  • 4+ years of leadership experience managing audit teams and stakeholders
  • Big 4 public accounting firm audit experience
  • Experience testing all IT General Control technology control domains
  • BA, BS, or equivalent degree in accounting or technology related field
  • Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP)
  • An industry recognized cloud certification, e.g., ICS2 CCSP, or complete within 12 months of hire date.
  • Knowledge and experience in the application of control theory and professional auditing practices including the audit lifecycle
  • Strong knowledge of information security and infrastructure related terminology and concepts (e.g., zero trust, defense in depth, hybrid cloud, infrastructure as code, virtualization, public key infrastructure (PKI), etc.)
  • Prior experience in applying cybersecurity concepts and controls/countermeasures in public cloud environments (Amazon Web Services, Google Cloud, etc.).
  • Prior experience in analyzing regulatory and industry cybersecurity frameworks (NIST, FFIEC, CRI, MITRE ATT&CK) and applying guidance to audits of cybersecurity controls
  • Demonstrated ability to serve as a cybersecurity mentor or coach to junior team members, including prior experience in creating training materials and delivering cybersecurity training to audit teams and departments
  • Ability to break-down a complex problem into components, solve them using data analysis, process knowledge and risk/control knowledge, and communicate results and control recommendations with transparency and integrity
  • Strong written and verbal communication skills that deliver quality, actionable and beneficial feedback to management on potential control issues and solutions to close gaps.
  • Effectively leads a team in a fast-paced environment to drive business results, utilizing related project management skills, employing creative thinking, and the ability to work on competing priorities

Preferred Qualifications

  • Financial services industry strongly preferred
  • 10+ years of relevant technology audit experience
  • BA or BS in Cybersecurity, Information Systems, Computer Science, or related field
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Experience leading teams in technology, cybersecurity, or information security risk management
  • Experience with using data analytic tools, data visualization, key risk indicators (KRIs), key performance indicators (KPIs), and scorecards / dashboards
  • Background in information systems, data analytics or information technology 

Non-considerations for sponsorship: Employment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions.

Salary Range: $130,000.00 to $205,000.00 annually + bonus + equity (if applicable) + benefits

The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

  • Competitive base salaries 
  • Bonus incentives 
  • 6% Company Match on retirement savings plan 
  • Free financial coaching and financial well-being support 
  • Comprehensive medical, dental, vision, life insurance, and disability benefits 
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need 
  • 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy 
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location) 
  • Free and confidential counseling support through our Healthy Minds program 
  • Career development and training opportunities

For a full list of Team Amex benefits, visit our Colleague Benefits Site.

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law. American Express will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable state and local laws, including, but not limited to, the California Fair Chance Act, the Los Angeles County Fair Chance Ordinance for Employers, and the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance. For positions covered by federal and/or state banking regulations, American Express will comply with such regulations as it relates to the consideration of applicants with criminal convictions.

We back our colleagues with the support they need to thrive, professionally and personally. That's why we have Amex Flex, our enterprise working model that provides greater flexibility to colleagues while ensuring we preserve the important aspects of our unique in-person culture. Depending on role and business needs, colleagues will either work onsite, in a hybrid model (combination of in-office and virtual days) or fully virtually.

US Job Seekers/Employees - Click here to view the “Know Your Rights” poster and the Pay Transparency Policy Statement.

If the links do not work, please copy and paste the following URLs in a new browser window: https://www.dol.gov/agencies/ofccp/posters to access the three posters.

American Express Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
American Express DE&I Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of American Express
American Express CEO photo
Stephen J Squeri
Approve of CEO

Average salary estimate

$167500 / YEARLY (est.)
min
max
$130000K
$205000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cybersecurity Audit Director, American Express

As the Cybersecurity Audit Director at American Express in Phoenix, Arizona, you'll be at the forefront of protecting and enhancing our organizational value. This role isn't just about leading audits—it's about guiding a passionate team through the intricate world of cybersecurity. You'll play a crucial part in the Internal Audit Group, where your data-driven approach will help us ensure that our cybersecurity audit portfolio remains robust. Imagine leading a dedicated team of auditors through audits on application and infrastructure security, cybersecurity incident response, and more. You'll have the unique chance to impact how we understand and manage risks while fostering a collaborative environment that encourages professional development. We value personal growth and believe in providing our colleagues with the tools and support they need to thrive in their careers. You’ll lead audits, develop test plans, and clearly communicate findings to senior management, all while mentoring junior colleagues and integrating emerging cybersecurity trends into our audit universe. At American Express, we're more than just a team—we're a community committed to maintaining the highest standards of integrity and security. If you’re driven by the challenge of translating data into actionable insights, this is your opportunity to shine. Join us, and let’s lead the way together in delivering exceptional customer experience and maintaining an industry-leading cybersecurity function.

Frequently Asked Questions (FAQs) for Cybersecurity Audit Director Role at American Express
What are the main responsibilities of the Cybersecurity Audit Director at American Express?

The Cybersecurity Audit Director at American Express leads a team of auditors to provide internal audit assurance over cybersecurity processes. Key responsibilities include planning and executing cybersecurity audits, developing test plans, evaluating the design and effectiveness of cybersecurity controls, and analyzing regulatory requirements. This role also involves presenting findings to senior management and mentoring junior staff to ensure knowledge sharing and development within the team.

Join Rise to see the full answer
What qualifications are required for the Cybersecurity Audit Director position at American Express?

To be considered for the Cybersecurity Audit Director role at American Express, candidates need at least 7 years of relevant technology audit experience, with a minimum of 4 years in leadership roles. A BA or BS in a related field and certifications like CISA or CISSP are essential. Additionally, knowledge of cybersecurity frameworks and experience in public cloud environments will strengthen your application.

Join Rise to see the full answer
How does the Cybersecurity Audit Director contribute to the Internal Audit Group at American Express?

The Cybersecurity Audit Director plays a pivotal role in advancing the Internal Audit Group's capabilities by leading a skilled team of auditors. This role not only enhances the cybersecurity audits portfolio but also contributes to the development of data-driven audit methodologies and technologies that align with American Express’s commitment to excellence in risk management and organizational value.

Join Rise to see the full answer
What skills are necessary for success as a Cybersecurity Audit Director at American Express?

Success as a Cybersecurity Audit Director at American Express requires strong leadership skills, in-depth knowledge of cybersecurity concepts, and proficiency in data analysis. Exceptional verbal and written communication skills are also crucial for articulating complex findings to management. Additionally, a commitment to mentoring team members and an understanding of emerging cybersecurity risks are essential for thriving in this role.

Join Rise to see the full answer
What benefits can the Cybersecurity Audit Director expect while working at American Express?

The Cybersecurity Audit Director at American Express enjoys a competitive salary, bonus incentives, a robust retirement plan, and comprehensive medical benefits. The company also prioritizes employee well-being with flexible work arrangements, extensive parental leave, and professional development opportunities, making it easier to maintain a work-life balance while advancing your career.

Join Rise to see the full answer
Common Interview Questions for Cybersecurity Audit Director
Can you explain your experience with cybersecurity audit methodologies?

When answering this question, focus on specific methodologies you've utilized and how they've positively impacted audit outcomes. Share examples of your approach to auditing cybersecurity processes, such as using data analytics or risk assessments, and emphasize your adaptability in applying different methodologies to meet organizational needs.

Join Rise to see the full answer
What strategies do you use to lead and mentor your audit team?

Highlight your leadership style, particularly how you empower team members through mentorship. Talk about fostering a collaborative environment and how you provide training and resources that enable junior colleagues to develop their skills. Mention the importance of regular feedback and coaching sessions to ensure continuous growth.

Join Rise to see the full answer
How do you approach communicating audit findings to senior management?

Discuss your strategy for clearly articulating audit findings in a manner that’s easily digestible for stakeholders. Describe how you emphasize the significance of control gaps while also offering actionable recommendations. Stress the relevance of data visualization tools to enhance your presentations.

Join Rise to see the full answer
Can you describe a complex cybersecurity issue you faced during an audit and how you resolved it?

Provide a detailed example of a challenging situation you've encountered, explaining the issue’s complexity and its potential impact. Discuss the steps you took to investigate, how you collaborated with your team, and the solution you implemented, demonstrating your problem-solving and critical-thinking skills.

Join Rise to see the full answer
What experience do you have with regulatory frameworks related to cybersecurity?

Share your familiarity with frameworks like NIST or FFIEC and how you’ve applied them in previous audits. Emphasize your ability to analyze these regulations and integrate their requirements into your audit practices, ensuring compliance and enhancing security measures for the organization.

Join Rise to see the full answer
How do you keep up with the latest cybersecurity trends and threats?

Discuss the resources you leverage to stay informed about the evolving cybersecurity landscape. This could include attending professional conferences, subscribing to industry publications, or participating in relevant online courses. Highlight your proactive approach to integrating new insights into your auditing processes.

Join Rise to see the full answer
Can you provide an example of how you improved an audit process?

Talk about a specific initiative you led to enhance the efficiency or effectiveness of an audit process. Include details about the challenges you faced, the strategies you implemented, and the positive outcomes that resulted from your efforts, illustrating your forward-thinking and innovative approach.

Join Rise to see the full answer
What are your views on the importance of data analytics in auditing?

Emphasize how data analytics enhances the audit process by offering deeper insights and enabling a more comprehensive assessment of controls. Discuss your experience using data-driven approaches to identify anomalies and improve risk management strategies, underscoring its importance in modern auditing.

Join Rise to see the full answer
How do you prioritize and manage multiple audit projects?

Share your project management techniques, like establishing clear timelines and goals for each audit. Discuss how you allocate resources efficiently and ensure open communication with your team, which helps maintain productivity while balancing competing priorities effectively.

Join Rise to see the full answer
Why do you believe integrity is crucial in the audit profession?

Reflect on the significance of integrity in building trust within the organization and ensuring accurate assessments of risk and controls. Discuss how your commitment to ethical standards shapes your decision-making process and impacts your work as an audit leader.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
American Express Remote New York, New York, United States
Posted 10 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as a Director & Counsel to lead and provide expert legal counsel on employment matters within a global context.

Photo of the Rise User
Posted 10 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

As an Analyst-Compliance at American Express, you'll leverage your expertise in data analysis and reporting to drive compliance initiatives within a leading financial institution.

Posted 8 days ago

Join Toyota as a Senior Analyst specializing in SAP Vertex to drive innovative solutions within our Business Technology Platforms.

Join a pivotal role at Microsoft Security as a Senior Insider Threat Analyst, where you will be instrumental in safeguarding against insider risks.

Photo of the Rise User
Kyndryl Hybrid Nicosia, Lefkosia (Lefkoşa), Cyprus
Posted 2 days ago

Join Kyndryl as a Network Services Lead and be integral in shaping IT infrastructure management with cutting-edge technology.

Photo of the Rise User
CCMR3 Remote United States
Posted yesterday

Join CCMR3 as a Business Analyst to deliver top-notch IT solutions while working in a collaborative, dynamic environment.

The University of British Columbia seeks an experienced Associate Director in Cybersecurity Architecture and Development to enhance its strategic cybersecurity initiatives.

Photo of the Rise User
Posted 14 days ago

The role of Vice President, Chief Architect focuses on leading architectural initiatives and aligning technology with business objectives.

Photo of the Rise User
Thomson Reuters Remote BRA-São Paulo-Av Cardoso de Me
Posted 7 days ago

Join Thomson Reuters as an Oracle Integrations Analyst and impact the industry through innovative financial solutions.

Posted 14 days ago

Join Fairway Lawns as a Business Systems Analyst to enhance the customer experience through effective technical solutions and support for NICE CXOne.

Photo of the Rise User
Posted 9 months ago
Photo of the Rise User
Posted last month

As a key member of CVS Health, you'll be connecting with Medicare and Medicaid members to enhance their healthcare experience through appointment scheduling.

Photo of the Rise User
Posted 8 months ago
Mission Driven
Collaboration over Competition
Inclusive & Diverse
Growth & Learning
Maternity Leave
Paternity Leave
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Paid Time-Off

American Express is a multinational financial services corporation and global leader in providing personal, small business, and corporate credit cards.

4083 jobs
MATCH
Calculating your matching score...
BADGES
Badge Family FriendlyBadge Office VibesBadge Work&Life BalanceBadge Rapid Growth
CULTURE VALUES
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
BENEFITS & PERKS
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 4, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Remote Customer Service Representative at Conduent
Photo of the Rise User
Someone from OH, Cleveland just viewed Customer Support Team Lead (6-month Contract) at Jane App
o
Someone from OH, Cincinnati just viewed Marketing and Communications Consultant at osu
Photo of the Rise User
Someone from OH, Toledo just viewed Registered Nurse (Part-time) at Calibrate
Photo of the Rise User
Someone from OH, Toledo just viewed Clinical Research Associate II at Alimentiv
Photo of the Rise User
Someone from OH, Cleveland just viewed IT Support Engineer at Level AI
Photo of the Rise User
Someone from OH, Dayton just viewed Customer Content Specialist at Cision
Photo of the Rise User
Someone from OH, Cuyahoga Falls just viewed Senior Corporate Communications Manager at Bumble Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at Workday
Photo of the Rise User
Someone from OH, Cincinnati just viewed Financial Planning and Analysis Lead at JLL
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Operations at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Strategic Finance Analyst, Corporate at Benchling
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Project Finance at Apex Clean Energy
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior FP&A Analyst, Sales at GitLab
Photo of the Rise User
Someone from OH, Cincinnati just viewed FP&A Analyst at Lithic
Photo of the Rise User
15 people applied to Junior Security Engineer at Epic