Information Security Technology Manage

Information Security Technology Manage

Full-Time 36000 - 60000 £ / year (est.) No working from home possible
American Express Global Business Travel

At a Glance

  • Tasks: Manage and enhance information security systems while ensuring compliance with industry standards.
  • Company: Join Amex GBT, a leader in travel and technology with a collaborative culture.
  • Benefits: Enjoy flexible benefits, travel perks, and access to over 20,000 learning courses.
  • Other info: Inclusive environment with opportunities for personal and professional growth.
  • Why this job: Make a real impact in the cybersecurity field while working with a diverse team.
  • Qualifications: Experience in ISO 27001 and PCI DSS, strong leadership, and analytical skills required.

The predicted salary is between 36000 - 60000 £ per year.

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We are here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

American Express Global Business Travel (Amex GBT) is seeking a motivated and driven individual to maintain and enhance an existing information security management system and associated frameworks. By joining our Global Cyber Governance, Risk and Compliance team, you will be a core member responsible for security oversight and compliance management for a dedicated product/service in the Company's portfolio. You will be responsible for promoting best practices, company's policies and controls in protecting the confidentiality, integrity and availability of GBT's assets.

The information security manager will be responsible for managing an existing ISO 27001 ISMS and maintaining associated ISO 27001 certification as well as PCI DSS certification for a product line. This role will include responsibility for managing policies, controls reviews, management reporting, exception and issue remediation tracking, metrics and support of customer facing security requests.

What You'll Do:

  • Serves as a single point of contact for information security related audit and assessments requests which will include Internal Audit, Key Controls Testing, PCI and ISO 27001 audit engagements.
  • Responsible for ISO 27001 and PCI DSS certification execution.
  • Supports departments by collecting and coordinating internal compliance data with auditors and various departments.
  • Maintains audit schedule and request trackers, collects evidence and supports audit fieldwork/certification engagements.
  • Prepares management reports for technical, management and leadership level stakeholders including Management Reviews and metrics.
  • Drives completion of management responses and compiles mitigation plans, tracks progress of mitigation activities, when applicable.
  • Enhances compliance department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to job accomplishments which may include policy creation and management, exception evaluations and tracking, metrics, etc.
  • Identifies areas of improvement and enhances awareness of security requirements.
  • Drives information security policy and standard enhancements.
  • Provide support in various security risk reviews, conducts risk assessments, control testing and supports execution of assigned security controls.
  • Conducts internal and external audits.
  • Completes customer security questionnaires and assessments and participates in the customer RFP engagement process.

What We're Looking For:

  • Must have Fluent English and French, preference is for Bilingual background.
  • Strong leadership skills and ability to work effectively with a multi-disciplinary set of stakeholders across different levels, time zones and with minimal supervision.
  • Formal experience with ISO 27001 certification and ISMS management as well as PCI DSS.
  • Experience complying with industry security standards such as COBIT, ISO 27001/2, NIST CSF or similar.
  • Experience working with 3rd party security auditors.
  • Strong understanding of the business impact of security tools, processes, and policies as well as high proficiency in how to assess risk and business impact.
  • Team player; able to work collaboratively and effectively with and through others at all levels in an organization; proven ability to influence others and move toward a common vision or goal.
  • Technical knowledge of IT processes to include configuration management, networking, database management, application coding, availability, data center operations, etc.
  • Excellent understanding of technical security safeguards.
  • Solid business acumen, flexibility, and judgment to evaluate issues/problems of high complexity and make sound decisions.
  • Strong project management and people management skills.
  • Solid analytical skills and understanding of processes, technology and operational concepts.
  • 5+ years of relevant security technology experience.
  • 3+ years in similar role, such as Information Security Officer/Manager, IT Administrator, or Data Governance Officer/Manager.

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process.

If you're passionate about our mission and believe you'd be a phenomenal addition to our team, don't worry about 'checking every box;' please apply anyway. You may be exactly the person we're looking for.

Information Security Technology Manage employer: American Express Global Business Travel

At Amex GBT, we foster an inclusive and collaborative culture where your contributions are valued, making it an exceptional place to work. With flexible benefits tailored to your needs, extensive learning opportunities, and a commitment to employee growth, you can thrive in your career while enjoying travel perks and a supportive environment. Join us in making a meaningful impact in the travel industry as part of our dedicated team in the United Kingdom.

American Express Global Business Travel

Contact Details:

American Express Global Business Travel Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Technology Manage

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including American Express Global Business Travel, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through American Express Global Business Travel

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at American Express Global Business Travel. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Technology Manage

ISO 27001 Management
PCI DSS Certification
Information Security Audits
Risk Assessment
Compliance Management
Stakeholder Engagement
Technical Security Safeguards

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at American Express Global Business Travel insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to American Express Global Business Travel that you’re committed to staying ahead in the game.

How to prepare for a job interview at American Express Global Business Travel

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at American Express Global Business Travel to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at American Express Global Business Travel.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.