Upload Button Icon Add office photos
filter salaries All Filters

200 Resy Jobs

Information Security Manager

8-13 years

Kolkata, Mumbai, New Delhi + 4 more

1 vacancy

Information Security Manager

Resy

posted 5d ago

Job Description

The Information Security Manager role is part of the third-party security team within Technology R isk & Information Security (TRIS) , and is responsible for security control enforcement, awareness , and enablement of American Express standard controls at 3 rd party environment .
This position, reporting to the Director of Information Security , is responsible for assessing the information security risk associated with Third Parties and facilitating and/or performing information security assessments of those Third Parties . The person in this position will be responsible for managing third party security risk specifically focused on aspects of assessing, monitoring, providing risk expertise on security control domains, process uplift recommendations, and providing professional guidance to key stakeholders of the program on information security aspects .
The ideal candidate for this role has an extensive background in risk management / Audit / Information Security. They are dynamic, with the ability to manage a fluctuating workload with competing deadlines. The candidate is highly inquisitive with a healthy dose of cautiousness , has a broad-based perspective and thrives on building a network of internal and external alliances. S/he has highly developed communication skills, excellent time management and an acute attention to detail

Responsibilities:
  • Partner with the BU to complete third party risk assessments and ensure adherence to program requirements .
  • Assist with risk analysis and security posture evaluations of Third Parties to support security assessment activitie s , including vulnerability threat assessments
  • Execute or f acilitate execution of information security assessments for in-scope third parties , assess the quality of assessments conducted by External A ssessors, define risk ratings as appropriate to the control failures, etc.
  • Review and evaluate the security controls of third-party vendors to ensure they align with the AXP s security standards and explains control requirements to the business colleagues and third parties, as appropriate
  • Partner with other colleagues in third party security team in sharing inputs towards third party assessment questionnaires and Guidance documents
  • Conduct training and awareness sessions for internal stakeholders on third-party security risks and best practices . Be an Information Security Risk Expert for team and other stakeholders
  • Foster strong relationships with Business colleagues and TLM team to promote security best practices and collaboration
  • S upport with security and compliance initiatives as led by third party security team
Requirements / Qualification :
  • Thorough knowledge of information security components, principles, practices, and procedures
  • Information security specialist with 8 + years of experience
  • A broad understanding of the IT controls and best practices across key risk domains, including risk assessment methodology , application security, network and infrastructure security, Data loss prevention, and incident management is recommended
  • Prior experience managing risk assessments; including background in audit, information security , Third Party Risk/Oversight, or other risk control functions
  • Strong knowledge of information security frameworks (e.g., NIST, ISO 27001) and regulatory requirements
  • Proficiency in risk assessment methodologies and third-party risk management tools
  • Attention to Detail: Careful evaluation of vendor security practices and documentation
  • Excellent communication, negotiation, and stakeholder management skills , able to effectively communicate at all levels within the organization
  • Being flexible and able to adjust to new needs and new technologies , and be comfortable with ambiguity
  • Strategic Thinking: Ability to align third-party security with broader organizational objectives
  • Relevant certifications such as CISSP, CISM, CISA, CRISC , ISO 27001 are preferred
Compliance Language
Benefits include:
  • Competitive base salaries
  • Bonus incentives
  • Support for financial-well-being and retirement
  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • Generous paid parental leave policies (depending on your location)
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities
Benefits include:
  • Competitive base salaries
  • Bonus incentives
  • Support for financial-well-being and retirement
  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • Generous paid parental leave policies (depending on your location)
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities

Employment Type: Full Time, Permanent

Read full job description

Compare Resy with

TCS

3.7
Compare

Accenture

3.9
Compare

Wipro

3.7
Compare

Cognizant

3.8
Compare

Capgemini

3.8
Compare

HDFC Bank

3.9
Compare

ICICI Bank

4.0
Compare

Infosys

3.7
Compare

HCLTech

3.5
Compare

Tech Mahindra

3.6
Compare

Genpact

3.9
Compare

Teleperformance

3.9
Compare

Concentrix Corporation

3.8
Compare

Axis Bank

3.8
Compare

Amazon

4.1
Compare

Jio

3.9
Compare

Reliance Retail

3.9
Compare

IBM

4.1
Compare

iEnergizer

4.7
Compare

LTIMindtree

3.9
Compare

Similar Jobs for you

Information Security Manager at Bajaj Finserv Ltd.

Pune

4-8 Yrs

₹ 6-10 LPA

Information Security Specialist at Amdocs Development Center India Pvt. Ltd.

Pune

6-7 Yrs

₹ 8-9 LPA

Information Security Manager at National Commodity Clearing Limited (NCCL)

Mumbai

5-10 Yrs

₹ 10-18 LPA

Information Security Program Manager at Maruti Suzuki India Limited

Gurgaon / Gurugram

5-10 Yrs

₹ 12-16 LPA

Director Information Security at Medline Healthcare Industries

Pune

9-12 Yrs

₹ 11-14 LPA

Chief Information Security Officer at tcpwave

Hyderabad / Secunderabad

9-14 Yrs

₹ 11-16 LPA

Information Security Specialist at Amdocs Development Center India Pvt. Ltd.

Pune

6-7 Yrs

₹ 8-9 LPA

Information Security Manager at Gnani Innovations

Bangalore / Bengaluru

6-8 Yrs

₹ 7-11 LPA

Information Security Manager at Prakhar Software Solutions

New Delhi

3-8 Yrs

₹ 5-10 LPA

Information Security Analyst at Eurofins It Solutions India Pvt Ltd

Bangalore / Bengaluru

3-9 Yrs

₹ 8-12 LPA

Information Security Manager

8-13 Yrs

Kolkata, Mumbai, New Delhi +4 more

5d ago·via naukri.com

Lead Analyst

2-3 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

Engineering Director - UI

15-20 Yrs

Chennai

2d ago·via naukri.com

VP Technology IV, Customer Domain Engineering

10-15 Yrs

Gurgaon / Gurugram

2d ago·via naukri.com

Engineering Director

19-20 Yrs

Chennai

2d ago·via naukri.com

Engineer II

3-6 Yrs

Bangalore / Bengaluru

2d ago·via naukri.com

Director-Control Management

13-18 Yrs

Gurgaon / Gurugram

5d ago·via naukri.com

Engineering Director

19-20 Yrs

Bangalore / Bengaluru

5d ago·via naukri.com

Director Compliance

14-19 Yrs

Gurgaon / Gurugram

5d ago·via naukri.com

Director-Digital Product Management

10-15 Yrs

Gurgaon / Gurugram

5d ago·via naukri.com
write
Share an Interview