Amex GBT is a place where colleagues find inspiration in travel as a force for good and - through their work - can make an impact on our industry. We're here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.
At American Express Global Business Travel (Amex GBT), we help our customers power progress through travel. We are committed to delivering secure, innovative, and customer-centric travel solutions through the combined strength of our people, technology, and industry expertise. Within the Global Information Security (GIS) organization, our mission is to protect Amex GBT's information assets, customers, colleagues, and business operations through effective security governance, risk management, compliance oversight, and security assurance activities. We foster a culture of security, collaboration, continuous improvement, and operational excellence.
We are seeking motivated and talented professionals who are passionate about cybersecurity, risk management, and compliance to join our growing team.
What You'll Do
- Participate in internal security assessments and security reviews; conduct security risk analysis of business processes and technology solutions to evaluate whether they comply with internal security policies and standards as well as regulatory / industry requirements and security best practices.
- Support annual security compliance audits (e.g., PCI DSS, SOC 1/SOC 2, ISO 27001:2013).
- Support the third-party/vendor security risk assessment process; monitor and report on progress of third-party/vendor security risk treatment activities by business owners.
- Support the Sales process by participating in customer-initiated security due diligence and/or vendor qualification audits, reviewing security terms in customer contracts, and helping to respond to security questionnaires and documentation requests from customers.
- Assist with maintenance of information security program documentation consisting of information security policies, standards, and guidelines, and coordinating management ratification of policies and standards at regular intervals.
- Participate in improving the overall Security culture across CWT; contribute to employee security awareness campaigns and educational activities to address areas of potential risk and/or gaps in compliance.
- Technical skills on MS-Excel, scripting and automation would be an add-on and preferred.
- Lead and support technical data encryption remediation efforts in coordination with Cybersecurity Operations and Enterprise IT
What We're Looking For
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field.
- Experience in information security, risk management, compliance, audit, or third-party risk management.
- Working knowledge of security frameworks and regulations including PCI DSS, ISO 27001, SOC 1/SOC 2, GDPR, NIST CSF, and CIS Controls.
- Experience supporting client security assessments, audits, or security questionnaire responses.
- Strong analytical, documentation, and stakeholder management skills.
- Proficiency in Microsoft Excel, PowerPoint, and reporting tools.
- Experience with automation, scripting, data analytics, Power Automate, Python, or similar technologies is highly desirable.
- Professional certifications such as CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, Security+, or equivalent are preferred.