The Associate Technology Risk Manager orchestrates cross-team risk delivery, clarifies responsibilities, and ensures timely updates on risk artifacts, emphasizing clarity and accountability.
Global Infrastructure (GI) provides the foundational platforms and services that enable reliable, secure technology delivery across the enterprise, working across multiple teams and domains to keep the environment resilient and well controlled. Cross Platform Delivery (CPD) is Global Infrastructure’s thin, cross-GI orchestration layer connecting work that spans platforms and teams to enable consistency, transparency, and enterprise credibility without duplicating line ownership.
Role Overview
As an Associate Technology Risk Manager in CPD, you will orchestrate delivery of cross GI risk artifacts, such as MAPs, OREs, and PSRs, when inputs span multiple teams or responsibility is unclear. The role supports the Director by coordinating ownership, actions, and escalation paths with ETS Governance & Control partners so GI delivers a single, consistent narrative and on-time updates without taking on risk/control ownership or remediation execution.
How you will make an impact
- Drive a consistent GI technology risk posture by synthesizing inputs across teams into one clear view of risk, progress, and priorities.
- Clarify ownership, decision points, and escalation paths for cross-GI risk initiatives where accountability is potentially distributed or unclear.
- Improving the quality, completeness, and consistency of GI risk artifacts and updates leverage within GI and across the enterprise.
- Produce oversight-ready risk narratives that connect issues, events, controls, and remediation into an accurate, enterprise-aligned story.
- Enable timely decisions by highlighting trends, concentrations, and cross-cutting dependencies, and by escalating when delivery is at risk.
- Orchestrate cross GI delivery of risk artifacts (MAPs, OREs, PSRs) where inputs and actions span multiple teams, aligning stakeholders on scope, narrative, evidence needs, and timelines in partnership with ETS Governance & Control.
- Support the Director by running the cross GI operating rhythm with ETS Governance & Control, and second line partners, coordinating ownership, tracking actions, and driving escalation/decisioning when responsibility is unclear.
- Develop executive- and oversight-ready narratives that explain what happened, what is changing, residual risk, and the path to closure—grounded in facts and consistent across GI.
- Coordinate action plans across teams by surfacing dependencies, confirming owners and due dates, and escalating early when progress or accountability breaks down.
- Partner with ETS Governance & Control and risk/control stakeholders to align on evidence expectations and ensure remediation actions map back to the documented risk statements and control intent (while execution remains with accountable teams).
- Synthesize inputs into concise reporting and insights for GI leaders—highlighting trends, concentrations, hotspots, and recommended focus areas.
- Improve cross-GI ways of working by reducing friction in intake, tracking, and reporting, standardizing what “good” looks like while keeping ownership with the accountable teams.
- Bachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or equivalent practical experience.
- Experience in technology risk, operational risk, controls, or technology governance within a large, complex enterprise technology environment .
- Working knowledge of the first line/ second line/ third line (FLOD/SLOD/TLOD) model, including how to partner effectively across Technology, Control Management, Risk, Compliance, and Internal Audit while maintaining appropriate role clarity.
- Ability to synthesize complex inputs (issues, events, assessments, control gaps, remediation plans) into clear written narratives and executive-ready summaries.
- Experience coordinating deliverables across multiple stakeholders, including tracking actions, managing dependencies, and operating with urgency in time-bound situations.
- Familiarity with common technology risk and control domains (e.g., change/release management, resilience, access management, vulnerability management, incident/problem management, monitoring/observability, and third-party/affiliate considerations).
- Practical experience using risk and workflow platforms and reporting tools (e.g., Archer, ServiceNow GRC, or similar, data visualization and reporting capabilities), with a focus on outcomes and clarity over tool administration.
Preferred skills
- Cross-platform thinking: Comfortable operating across infrastructure, platforms, and enabling capabilities, identifying patterns and connecting related risks across multiple products and teams.
- Ambiguity management: Able to define the problem, propose a plan, and drive progress when information is incomplete or ownership is distributed.
- Executive communication: Strong writing and presentation skills; able to tailor messages by audience and turn complex detail into clear decisions and actions.
- Influence without authority: Proven ability to build alignment, negotiate tradeoffs, and move work forward through strong relationships and credibility.
- Continuous improvement mindset: Interest in simplifying processes, strengthening reporting, and improving evidence quality through better ways of working.
Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.
American Express New York, New York, USA Office
World Financial Center, New York, NY, United States, 10285
American Express New York, New York, USA Office
200 Vesey St, New York, NY, United States, 10281
Similar Jobs
eCommerce • Fintech • Real Estate • Software • PropTech
The Central Homes Project Manager oversees renovation projects remotely, managing contractors and ensuring quality and timelines without on-site presence.
Top Skills:
Google WorkspaceProject Management PlatformsSlack
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Senior Threat Hunting Intelligence Analyst will perform threat hunting and intelligence analysis, manage customer accounts, and present findings to stakeholders while improving security against adversaries.
Top Skills:
Application Programming Interfaces (Api)Crowdstrike Query Language (Cql)Cyber Threat IntelligenceLogscaleScripting Languages
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Conduct Cloud Red Team Blue Team engagements, support threat hunting and incident response, manage projects, and recommend enhancements to improve results for clients.
Top Skills:
AWSAzureAzure SentinelGCPLogscaleM365Microsoft Entra IdSIEMSplunk
What you need to know about the NYC Tech Scene
As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory


