Role Summary
Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.
The Director, Control Risk Advisory - GCST & USCDT, is a strategic advisory leader dedicated to supporting two Senior Leadership Team (SLT) members and their Technology organizations: Global Commercial Services Technology (GCST) and U.S. Consumer Services and Digital Technology (USCDT). The role provides an independent, forward-looking view of technology, information security, operational, and control risk; delivers clear and decision-oriented risk reporting; identifies emerging trends and leading indicators; and helps the two organizations prioritize pragmatic risk-reduction actions in alignment with business strategy, delivery commitments, and risk appetite. For GCST, the Director connects risk advisory to the GCS vision of backing businesses so they can do more business and to its mission of being the undisputed leader in financial and membership services for businesses while responsibly driving double-digit revenue growth, with particular attention to modernizing foundational capabilities and improving governance and controls. For USCDT, the Director supports the technology capabilities that power U.S. consumer products, Membership experiences, digital acquisition, banking, payments, marketing, travel, dining, Ads & Offers, and other mobile- and web-enabled experiences. The Director leads and develops a high-performing advisory team and champions responsible use of AI and GenAI to improve advisory effectiveness, operational efficiency, and decision quality.
Portfolio Focus
- GCST: Serve as the dedicated Control Risk Advisory partner to GCST leadership, connecting technology risk reporting, risk reduction, and prioritization to GCS business priorities, growth objectives, client needs, foundational modernization, and stronger governance and controls.
- USCDT: Serve as the dedicated Control Risk Advisory partner to USCDT leadership across the technology portfolio that enables U.S. consumer products and experiences, including digital acquisition, banking, payments, marketing, travel, dining, Ads & Offers, and mobile- and web-enabled capabilities that strengthen the value of Membership.
- Across both Technology organizations: Establish a consistent, comparative view of risk posture; surface cross-portfolio themes and dependencies; support transparent trade-off decisions; and focus leadership attention and resources on the highest-priority, highest-impact risk-reduction opportunities.
Responsibilities
- Lead, mentor, and coach a high-performing Risk Advisory team aligned to the GCST and USCDT portfolios, setting a clear strategic vision, creating an inclusive culture of continuous learning, and using feedback and metrics to strengthen individual and team performance.
- Establish credibility and trusted-advisor relationships with the GCST and USCDT SLT leaders and their senior Technology teams, balancing effective risk management with GCS and U.S. Consumer business priorities, delivery commitments, growth objectives, and strategic outcomes; provide clear, candid, evidence-based challenge while maintaining strong partnerships and influencing decisions without direct authority.
- Provide strategic risk advice across GCST and USCDT product, platform, and service areas, helping leaders make informed decisions by translating complex architectures, engineering practices, control environments, and technical issues into concise business-risk implications tied to customer, colleague, growth, and operational outcomes.
- Assess and report risk posture using data, metrics, leading indicators, and trend analysis to identify emerging risks before they become material events; deliver portfolio-specific and cross-portfolio insights that move leadership conversations from historical reporting toward predictive, comparative, and decision-oriented action.
- Drive pragmatic risk reduction across GCST and USCDT by converting risk insights into actionable remediation plans, measurable outcomes, clear ownership, and sustainable control improvements; help leaders prioritize investments and capacity toward the most consequential risks and accelerate delivery through strong execution discipline.
- Oversee and integrate complex, large-scale risk management and mitigation initiatives across the two portfolios, ensuring appropriate resource allocation, timely execution, escalation, and alignment.
- Independently develop lightweight, data-driven risk solutions for GCST and USCDT, including querying and integrating structured data, consuming APIs, automating recurring analysis, and developing dashboards or visualizations that provide timely portfolio and cross-portfolio risk insights while reducing dependency on manually produced Excel and PowerPoint reporting.
- Coordinate with product development and service delivery teams to embed Operational Risk Management and control considerations throughout product lifecycles, technology change, and ongoing service operations.
- Compile and apply lessons learned and best practices from product launches, technology changes, risk events, and control outcomes to improve proactive risk identification and decision-making.
- Support mergers, acquisitions, and significant business or technology change from a control-environment and risk-posture perspective, as applicable.
- Assess the needs of business and functional leaders to strengthen understanding of Operational Risk Management, technology risk, information security risk, governance, and controls; facilitate targeted risk awareness and education.
- Accountable for building strong relationships with senior stakeholders who manage highly complex and diverse portfolios.
- Demonstrate advanced executive communication to drive clarity and translate complex technical and risk information into concise, actionable narratives and compelling storytelling.
- Champion the responsible adoption of AI, GenAI, automation, and data-driven capabilities to enhance advisory effectiveness, risk sensing, analysis, and decision quality while maintaining appropriate governance, security, and risk controls.
- Apply approved Generative AI capabilities to accelerate research, analysis, synthesis, workflow automation, and risk reporting for the GCST and USCDT portfolios; identify and implement appropriate AI-enabled solutions while understanding associated security, data, accuracy, and governance considerations.
- Establish governance expectations for responsible use of AI in risk assessments, control monitoring, analysis, and documentation, including appropriate oversight, escalation, and accountability.
- Adapt leadership and advisory approaches to evolving technology, regulatory expectations, business priorities, and emerging risks while maintaining strategic focus and delivery.
- Collaborate effectively across GCST, USCDT, Technology, Information Security, Product, Risk, Compliance, Audit, and Control Management to create consistent and efficient risk practices, share insights and cross-portfolio themes, and align risk decisions to GCS, U.S. Consumer, and enterprise objectives.
- Demonstrate strong leadership agility to navigate a rapidly evolving technology and regulatory landscape, adapt leadership style to changing business priorities, embrace continuous learning, and lead teams and stakeholders through ambiguity while maintaining strategic focus and delivery.
Qualifications
- 6+ years of experience in operational risk management, technology risk, information security risk, control management, Internal Audit, or a related risk discipline, with demonstrated understanding of critical risk-management lifecycle activities.
- Experience leading technology risk and control teams and setting strategic direction while operating autonomously and driving measurable outcomes.
- Demonstrated credibility with senior technology and security leaders, including experience supporting broad product, platform, or business-aligned technology portfolios as a trusted advisor who can challenge constructively and escalate appropriately.
- Proven ability to translate complex technical and risk issues into executive-level business insights, portfolio reporting, prioritization decisions, and measurable risk-reduction outcomes.
- Strong track record of using risk data, metrics, and analytical techniques to identify trends, detect leading indicators, evaluate scenarios, and influence decisions.
- Experience leading complex mitigation, remediation, transformation, or control-improvement initiatives through influence, execution discipline, and cross-functional accountability.
- Experience embedding risk and control considerations into product development, technology change, service delivery, or operational processes.
- Experience establishing governance routines, decision forums, escalation paths, and executive risk-reporting mechanisms that enable transparent, comparative, and timely portfolio decision-making.
- Experience facilitating risk awareness, education, or capability building for business, technology, or product leaders and teams.
- Experience applying or enabling AI/GenAI, automation, or advanced analytics to improve risk advisory, monitoring, analysis, or operational efficiency, with appropriate governance and human oversight.
- Experience working across geographically distributed and diverse teams and stakeholders in a complex matrixed environment.
- Financial-services experience preferred.
B40 Leadership & Leveling Expectations
- Independently handles complex work assignments that affect multiple teams, products, services, or risk domains and exercises sound judgment with limited direction.
- Executes strategies with significant organizational impact and converts strategic objectives into measurable team and risk outcomes.
- Makes independent decisions across products, services, risk priorities, and stakeholder needs, balancing technical depth, business context, regulatory expectations, and risk appetite.
- Leads larger teams or departments, develops talent, establishes accountability, and makes key decisions that shape the advisory function and broader risk posture.
- Demonstrates leadership agility in ambiguity, adapts to rapidly evolving technology and regulatory landscapes, and maintains strategic focus while accelerating delivery.
Core Capability Profile
- High Technical Acumen: Deep technology, information security, cyber-risk, and modern engineering knowledge; translates technical complexity into business risk.
- Autonomous Leadership & Strategic Execution: Sets vision, leads with minimal direction, and drives accountable, measurable outcomes.
- Advanced Analytical Capability: Uses risk data, trends, metrics, and leading indicators to surface emerging issues and enable predictive risk management.
- Executive Presence, Communication & Storytelling: Influences senior stakeholders through concise, clear, decision-oriented risk narratives.
- Deep Risk Expertise: Applies strong technology, information security, governance, control, regulatory, and operational-resilience judgment.
- Leadership Agility: Leads through ambiguity and changing priorities while sustaining learning, focus, and delivery.
- AI & GenAI Adoption Mindset: Uses AI and GenAI responsibly to improve advisory effectiveness and decision quality while ensuring governance, security, and controls.
- Pragmatic Risk Reduction & Delivery: Turns risk insight into practical mitigation, accountability, accelerated execution, and sustainable proactive risk reduction.
- Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.
As part of Team Amex, you’ll experience our powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:
- Competitive base salaries
- Bonus incentives
- 6% Company Match on retirement savings plan
- Free financial coaching and financial well-being support
- Comprehensive medical, dental, vision, life insurance, and disability benefits
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities
For a full list of Team Amex benefits, visit our Colleague Benefits Site.
Learn more about this Employer on their Career Site
