Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cybersecurity Audit Director image - Rise Careers
Job details

Cybersecurity Audit Director - job 2 of 4

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

American Express’ Internal Audit Group (IAG) has reinvented our audit process and is leading the financial services industry with our Audit NextGen, Data-Driven Continuous Auditing, and Auditor of the Future initiatives. Each uniquely support our Winning Aspiration to be a world class internal audit function that:

  • Provides data-driven and technology-enabled assurance
  • Delivers timely risk insights that are business-aware and forward-looking
  • Supports our colleagues with experiences that prepare them to be enterprise leaders

Collectively, IAG’s strategic initiatives, combined with our greatest asset – our people – enable IAG to utilize advanced data analysis capabilities, provide greater and continuous assurance, and help ensure quality products and services are provided to American Express customers. 

IAG’s innovative Data-Driven Continuous Auditing approach has led to patent-pending technology assets over our uniquely developed audit methodology and technology enablers. 

We are looking for those who share our mission and aspirations and are passionate about the use of data and technology in a collaborative, people-focused environment.

About the Internal Audit Group at American Express

Our Internal Audit Group is a worldwide function with 300+ team members and offices across nine countries within American Express. Our mission is to protect and enhance organizational value by providing independent, objective, risk-based assurance, advisory services and to influence the way the company manages risk.

We are committed to growing our audit staff significantly as we continue to expand and enhance the Internal Audit Group. Our assurance and risk professionals have diverse backgrounds including internal controls, consumer compliance, technology, operational risk, financial accounting, data analytics, and banking operations. Our audit teams align to key risk areas and business units to ensure IAG can provide comprehensive and risk-based audit coverage. In addition, IAG has a Professional Practices group responsible for managing audit operations, quality, and standards; regulatory relations; reporting; training and professional development; and key internal capabilities and technologies.

About the Role:

Our Internal Audit group is seeking an eager Cybersecurity Audit Director to help advance and grow our audit coverage across our cybersecurity audit portfolio. In this role, the ideal candidate will be the team leader for auditors to provide assurance over areas such as application security, infrastructure security, cybersecurity incident readiness and response, encryption management, and cloud services. This is an exceptional opportunity for you to showcase and further expand your audit skills, and knowledge!

About the Team:

The cybersecurity audit portfolio spans the information technology through the enterprise. Audit coverage includes auditing first-line information security processes. The cybersecurity audit team is heavily focused on utilizing a data driven auditing approach across the audit portfolio.

The Key Responsibilities of the role include:

  • Lead a team of approximately five technology audit colleagues provide internal audit assurance over first-line information security processes, and deliver cybersecurity thought leadership to the team
  • Plan and lead execution of cybersecurity audits on the company annual audit plan
  • Ensure that audits delivery assurance and objectives by setting the audit scope, developing test plans, and leading colleagues to evaluate the design and operating effectiveness of cybersecurity controls, including testing control effectiveness with analytics-based testing
  • Analyze regulatory and industry cybersecurity requirements and frameworks over risk management, technology, and information security
  • Maintain the team's resources, training program, recruiting pipeline, and execute the screening and selection process
  • Monitor a portfolio of cybersecurity audit analytics, assess results, & use data to tell the business story, and work with audit and business colleagues to validate findings
  • Evaluate cybersecurity audit results, synthesize audit findings across the project, draft audit reports and ensure effective and efficient execution of audits in conformance with professional and department standards, budgets, and timelines
  • Present audit objectives, scope, and results to senior management and technology subject matter experts, clearly articulating the potential impact of control gaps in a highly professional and proficient manner
  • Assist other team leaders, senior auditors, and staff auditors in accomplishing team objectives and producing results
  • Execute multiple simultaneous global audit projects of all sizes and complexity across multiple business areas including integrated audits that consider financial, operational, compliance and technology risk
  • Effectively coach, teach, mentor and develop junior colleagues and co-sourced resources in geographically diverse locations across all aspects of their role, the audit and analytic lifecycle, audit methodology, and technology processes & controls
  • Monitor industry cybersecurity trends and emerging risks and propose potential changes to the IAG audit universe to ensure audit coverage evolves with the risk environment
  • Occasionally lead a team of approximately five technology audit colleagues provide internal audit assurance over first-line information technology general control processes
  • Assume full performance management responsibility for assigned staff

Minimum Qualifications

  • 7+ years of relevant technology audit experience
  • 4+ years of leadership experience managing audit teams and stakeholders
  • Big 4 public accounting firm audit experience
  • Experience testing all IT General Control technology control domains
  • BA, BS, or equivalent degree in accounting or technology related field
  • Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP)
  • An industry recognized cloud certification, e.g., ICS2 CCSP, or complete within 12 months of hire date.
  • Knowledge and experience in the application of control theory and professional auditing practices including the audit lifecycle
  • Strong knowledge of information security and infrastructure related terminology and concepts (e.g., zero trust, defense in depth, hybrid cloud, infrastructure as code, virtualization, public key infrastructure (PKI), etc.)
  • Prior experience in applying cybersecurity concepts and controls/countermeasures in public cloud environments (Amazon Web Services, Google Cloud, etc.).
  • Prior experience in analyzing regulatory and industry cybersecurity frameworks (NIST, FFIEC, CRI, MITRE ATT&CK) and applying guidance to audits of cybersecurity controls
  • Demonstrated ability to serve as a cybersecurity mentor or coach to junior team members, including prior experience in creating training materials and delivering cybersecurity training to audit teams and departments
  • Ability to break-down a complex problem into components, solve them using data analysis, process knowledge and risk/control knowledge, and communicate results and control recommendations with transparency and integrity
  • Strong written and verbal communication skills that deliver quality, actionable and beneficial feedback to management on potential control issues and solutions to close gaps.
  • Effectively leads a team in a fast-paced environment to drive business results, utilizing related project management skills, employing creative thinking, and the ability to work on competing priorities

Preferred Qualifications

  • Financial services industry strongly preferred
  • 10+ years of relevant technology audit experience
  • BA or BS in Cybersecurity, Information Systems, Computer Science, or related field
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Experience leading teams in technology, cybersecurity, or information security risk management
  • Experience with using data analytic tools, data visualization, key risk indicators (KRIs), key performance indicators (KPIs), and scorecards / dashboards
  • Background in information systems, data analytics or information technology 

Non-considerations for sponsorship: Employment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions.

Salary Range: $130,000.00 to $205,000.00 annually + bonus + equity (if applicable) + benefits

The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

  • Competitive base salaries 
  • Bonus incentives 
  • 6% Company Match on retirement savings plan 
  • Free financial coaching and financial well-being support 
  • Comprehensive medical, dental, vision, life insurance, and disability benefits 
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need 
  • 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy 
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location) 
  • Free and confidential counseling support through our Healthy Minds program 
  • Career development and training opportunities

For a full list of Team Amex benefits, visit our Colleague Benefits Site.

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law. American Express will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable state and local laws, including, but not limited to, the California Fair Chance Act, the Los Angeles County Fair Chance Ordinance for Employers, and the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance. For positions covered by federal and/or state banking regulations, American Express will comply with such regulations as it relates to the consideration of applicants with criminal convictions.

We back our colleagues with the support they need to thrive, professionally and personally. That's why we have Amex Flex, our enterprise working model that provides greater flexibility to colleagues while ensuring we preserve the important aspects of our unique in-person culture. Depending on role and business needs, colleagues will either work onsite, in a hybrid model (combination of in-office and virtual days) or fully virtually.

US Job Seekers/Employees - Click here to view the “Know Your Rights” poster and the Pay Transparency Policy Statement.

If the links do not work, please copy and paste the following URLs in a new browser window: https://www.dol.gov/agencies/ofccp/posters to access the three posters.

American Express Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
American Express DE&I Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of American Express
American Express CEO photo
Stephen J Squeri
Approve of CEO

Average salary estimate

$167500 / YEARLY (est.)
min
max
$130000K
$205000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cybersecurity Audit Director, American Express

Join American Express as a Cybersecurity Audit Director in Phoenix, Arizona, where you'll play a pivotal role in enhancing our internal audit function while backing our mission to provide the world's best customer experience. This position offers an exciting opportunity to lead a talented team of cybersecurity auditors, guiding them to assess and improve various security frameworks across the business. Your responsibilities will include planning and executing comprehensive audits, developing test plans, and ensuring that our stringent cybersecurity controls are effective. At American Express, we believe in the power of data-driven decision-making, equipping you with innovative tools that reflect our commitment to continuous improvement. You'll have the chance to synthesize findings, draft impactful audit reports, and present to senior management, all while mentoring junior colleagues in a collaborative environment. As a leader, you will influence our strategy on cybersecurity risk management, ensuring that we remain at the forefront of industry trends and developments. With 7+ years of technology audit experience and proven leadership skills, you will drive excellence in audit practices that not only protect but also enhance the value of our organization. American Express is a place where your contributions matter, and your career can flourish. We offer competitive salaries, a flexible working model, and extensive benefits to support your overall well-being. If you're ready to take on this exciting challenge, we would love to hear from you and welcome you to our Team Amex family!

Frequently Asked Questions (FAQs) for Cybersecurity Audit Director Role at American Express
What are the responsibilities of the Cybersecurity Audit Director at American Express?

The Cybersecurity Audit Director at American Express is responsible for leading a team of auditors in assessing and providing assurance over various cybersecurity processes, including application security, infrastructure security, and incident readiness. This role involves planning and executing audits, ensuring compliance with industry cybersecurity frameworks, analyzing audit results, and presenting findings to senior management.

Join Rise to see the full answer
What qualifications are needed for the Cybersecurity Audit Director role at American Express?

To qualify for the Cybersecurity Audit Director role at American Express, candidates should have at least 7 years of relevant technology audit experience, including 4 years of leadership experience. Necessary certifications include CISA or CISSP, along with industry-recognized cloud certifications and a strong understanding of cybersecurity frameworks.

Join Rise to see the full answer
How does American Express support professional growth for Cybersecurity Audit Directors?

American Express is committed to the professional growth of its Cybersecurity Audit Directors by offering extensive training programs, mentorship opportunities, and a collaborative team environment. Employees are encouraged to keep up with industry trends and develop their skills in data analytics and auditing methodologies to advance their careers.

Join Rise to see the full answer
What work-life balance options does American Express provide for its Cybersecurity Audit Director?

American Express offers a flexible working model for its Cybersecurity Audit Directors, allowing for hybrid, onsite, or fully virtual work arrangements. This flexibility helps employees maintain a healthy work-life balance while meeting the demands of their roles within the company.

Join Rise to see the full answer
What kind of impact can a Cybersecurity Audit Director have at American Express?

A Cybersecurity Audit Director at American Express has the opportunity to significantly impact the company's security posture by leading audits, identifying control gaps, and influencing cybersecurity risk management strategies. Their work ensures the integrity and security of the company’s operations while supporting its overarching mission to deliver excellent customer experiences.

Join Rise to see the full answer
Common Interview Questions for Cybersecurity Audit Director
Can you describe your experience in managing cybersecurity audits?

When answering this question, you should highlight your past roles where you've led cybersecurity audits, including specific audit projects and outcomes. Mention any frameworks and methodologies you used, along with how you managed your team to achieve successful results.

Join Rise to see the full answer
How do you stay current with industry cybersecurity trends?

A good response would include mentioning relevant publications, webinars, forums, or certifications you're involved with. Share examples of how you've applied recent trends to enhance audit practices or improve your team's performance in prior roles.

Join Rise to see the full answer
What strategies have you used to evaluate the effectiveness of cybersecurity controls?

Discuss the quantitative and qualitative methods you've employed to assess cybersecurity controls, such as conducting risk assessments, utilizing analytics-based testing, and how you developed your evaluation criteria. Be sure to mention the results of these strategies in previous positions.

Join Rise to see the full answer
How do you handle conflicting priorities in audit projects?

To effectively answer this question, describe a situation where you faced competing priorities. Explain the steps you took to assess the situation, prioritize critical tasks, communicate with your team, and ensure all projects were delivered on time while maintaining quality.

Join Rise to see the full answer
What are the key elements you include in audit reports?

In your response, emphasize the importance of clarity, data integrity, actionable findings, and comprehensive recommendations in audit reports. Discuss how you ensure reports are tailored to different stakeholders' needs, including senior management.

Join Rise to see the full answer
Describe your experience in mentoring and developing junior auditors.

Highlight your approaches to mentorship, such as providing hands-on training, sharing knowledge through workshops, and creating a supportive environment. Include examples of how you've helped junior auditors improve their skills and their career growth.

Join Rise to see the full answer
What is your approach to analyzing regulatory cybersecurity frameworks?

Share your methodology for reviewing regulatory frameworks, such as NIST or FFIEC, and how you've applied their guidelines to your audit processes. Emphasize your ability to translate complex regulations into actionable audit practices.

Join Rise to see the full answer
How do you communicate findings to senior management?

Outline your approach to effective communication with senior management, including how you establish context, prioritize key points, and suggest actionable solutions. Providing examples of such communications can strengthen your answer.

Join Rise to see the full answer
Can you give an example of a complex cybersecurity problem you solved?

In your answer, provide details about a specific complex issue, the approach you took to analyze and address it, and the outcomes of your efforts. This will showcase your problem-solving skills and technical expertise.

Join Rise to see the full answer
Why do you want to work as a Cybersecurity Audit Director at American Express?

This is your chance to express your passion for American Express's mission and your alignment with their values. Share specific elements of the role and company that resonate with you, such as their innovative approach to auditing or commitment to employee development.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

American Express seeks a Director of Digital Product Management to enhance privacy risk processes and guide a dedicated team.

Photo of the Rise User
American Express Remote New York, New York, United States
Posted 8 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

American Express is looking for a Senior Manager to join their Privacy Center of Excellence to enhance privacy risk assessment processes.

Photo of the Rise User
Posted 4 days ago

Join a dynamic team as a Senior Consultant, shaping the future of global Client Services through innovative strategy and market insights.

Photo of the Rise User
Posted 14 days ago

Equip is on a mission to provide evidence-based care for eating disorders and seeks a dedicated Psychiatric Nurse Practitioner to join their virtual treatment team.

Photo of the Rise User
Posted 10 days ago

Become a key player in Visa's hybrid Service Experience team, specializing in innovative payment solutions and enhancing customer experiences.

Photo of the Rise User

Visa Consulting and Analytics is on the hunt for a Senior Manager to spearhead impactful consulting projects in the digital payments sector for their North America clients.

Posted 13 days ago

Join a leading consulting firm as an Informatica PowerCenter Consultant, where you'll work on transformative ETL and data warehousing solutions.

Photo of the Rise User
NECSWS Remote Home Based / Hybrid, United Kingdom
Posted 10 days ago

Join NEC Software Solutions as a Presales Consultant, leveraging your Public Safety expertise to significantly impact safety solutions.

Photo of the Rise User
Posted 6 days ago

We're looking for a Sr. Consultant in Client Success at Visa to lead client relationships and drive operational effectiveness in a hybrid work environment.

Photo of the Rise User
Posted 12 days ago

Join Step Forward Therapy to make a difference in the lives of children as a Pediatric Occupational Therapist.

American Express is a multinational financial services corporation and global leader in providing personal, small business, and corporate credit cards.

2285 jobs
MATCH
VIEW MATCH
BADGES
Badge Family FriendlyBadge Office VibesBadge Work&Life BalanceBadge Rapid Growth
CULTURE VALUES
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
BENEFITS & PERKS
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 3, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cincinnati just viewed AI training and enablement at Writer
Photo of the Rise User
Someone from OH, Cincinnati just viewed Data Analyst (Contact Center-Hybrid) at Dow Jones
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health
Photo of the Rise User
Someone from OH, Youngstown just viewed Event Services Human Resources Coordinator at Allied Universal
Photo of the Rise User
Someone from OH, Columbus just viewed IP Network Engineering Intern - Summer 2025 at Bandwidth
Photo of the Rise User
Someone from OH, Cleveland just viewed Director, Education Programs & Partnerships at Encoura
Photo of the Rise User
Someone from OH, Cleveland just viewed Operations Associate (Part-Time) - Pinecrest at Alo Yoga
Photo of the Rise User
Someone from OH, Dayton just viewed Medical Receptionist at LifeStance Health
Photo of the Rise User
Someone from OH, Coldwater just viewed Engineering Design Checker Jobs at Lockheed Martin
Photo of the Rise User
Someone from OH, Loveland just viewed SEO Admin & Business Support at Outliant
Photo of the Rise User
Someone from OH, Columbus just viewed Casting: Cedar Lake - Pilot Episode at Backstage
Photo of the Rise User
Someone from OH, Mount Orab just viewed Software Development Manager at Assured Guaranty
H
Someone from OH, Mansfield just viewed Medical Appointment Setter (Remote LatAm) at HireHawk
Photo of the Rise User
Someone from OH, Lewis Center just viewed Third Party Risk Analyst at Experian
Photo of the Rise User
Someone from OH, Columbus just viewed Lead Preschool Teacher at Guidepost Montessori
A
Someone from OH, Cincinnati just viewed Global Supply Manager - Taiwan at Also
Photo of the Rise User
193 people applied to Mindset/Life Coach at Upwork