At a Glance
- Tasks: Support third-party risk management and ensure compliance with information security standards.
- Company: Join American Express, a leader in innovation and customer service.
- Benefits: Enjoy competitive salaries, bonuses, flexible working, and comprehensive health benefits.
- Why this job: Make a real impact on global risk management while developing your career.
- Qualifications: Experience in information security or risk management is a plus.
- Other info: Dynamic work environment with opportunities for growth and learning.
The predicted salary is between 50000 - 60000 £ per year.
As part of Team Amex, you will experience our powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
International Card Services (ICS) Governance & Control is responsible for supporting our international Issuing businesses across 28+ international markets excluding the USA. Colleagues operate across a variety of geographies and disciplines ensuring a robust ICS first line of defence, and in playing an active role in supporting the ICS Business and our International Legal Entities meet its growth objectives whilst demonstrating an effective control framework.
The organization partners closely with Third Party Lifecycle Management (TLM), Technology Risk and Information Security, Control Management, Risk Pillar owners, and Business stakeholders to ensure robust risk management across our third-party ecosystem.
How will you make an impact in this role? The Third Party Risk Analyst will report to the Third Party Information Security Manager and will play a key role in supporting effective third-party risk management across ICS. This role will primarily focus on Third-Party Information Security risk assessments, control evaluation, and advisory support to ICS business stakeholders. The Analyst will help ensure that third parties meet American Express Information Security standards, application lifecycle management requirements, and Third Party Lifecycle Management (TLM) expectations.
In addition, this role is designed to be flexible and may support broader Third Party Risk Management activities beyond Information Security, including due diligence reviews, reporting, issue follow-up, governance activities, and other third-party risk initiatives based on business priorities.
Key Responsibilities- Support Third-Party Information Security risk assessments, ensuring identified control gaps are clearly documented, risk-assessed, and tracked through remediation to closure.
- Partner with business stakeholders to collect required evidence and provide practical guidance on compensating controls and risk mitigation strategies where applicable.
- Partner with Technology teams, Third Party Relationship Managers, and business stakeholders to drive compliance of application lifecycle management across third-party supported applications.
- Provide clear, practical, and risk-based guidance to business stakeholders on information security, technology governance, and third-party risk requirements, translating technical risks into business-impact terms and identifying alternative or compensating controls where appropriate.
- Support preparation of third-party risk reporting, dashboards, and leadership updates, leveraging data analysis and visual storytelling to highlight key risk themes, trends, and emerging issues.
- Raise awareness and educate stakeholders on third-party information security expectations, and technology risk management practices.
- Identify opportunities to strengthen internal controls, enhance compliance posture, and improve the overall third-party risk management and governance framework.
- Support regional or market-specific third-party risk activities, including regulatory, outsourcing, or compliance-related requirements where applicable.
- Contribute to broader Third-Party Risk Management activities as needed, including due diligence reviews, ongoing monitoring, governance support, regulatory & audit response coordination, reporting, and ad-hoc risk initiatives in line with business priorities.
Demonstrated understanding of Third-Party Risk Management, Information Security fundamentals, and technology risk principles. Relevant experience in Information Security, Technology Risk, Third-Party Risk Management, Operational Risk, or related disciplines, including support of risk assessments, control reviews, or vendor due diligence activities. Strong analytical skills with the ability to assess control design and effectiveness, identify gaps, and interpret risk data from multiple sources. Ability to exercise sound judgment, constructively challenge where appropriate, and maintain effective stakeholder relationships. Excellent verbal and written communication skills, with the ability to translate technical security and lifecycle management concepts into clear, business-focused language. Experience preparing senior management reports, dashboards, and presentations using data-driven insights. Strong proficiency in Microsoft Excel (data analysis), PowerPoint (executive-ready presentations), and Word (structured documentation).
Foundational knowledge across multiple Information Security domains (e.g., network security, data protection, identity and access management, secure development, cloud security), with an understanding of Third-Party Security Risk Management principles. Familiarity with industry-recognized security frameworks and standards such as ISO 27001, PCI DSS, NIST, or comparable regulatory and control frameworks. Relevant professional certifications (or actively working toward certification), such as CISA, CISM, CRISC, Security+, or similar risk and security credentials are a plus. Experience supporting third-party due diligence, vendor risk assessments, or technology risk reviews, preferably within financial services or other regulated industries. Exposure to international markets and multi-jurisdictional regulatory environments, with the ability to interpret and apply security and outsourcing requirements in a practical business context.
Employment EligibilityEmployment eligibility to work with American Express in the UK is required as the company will not pursue visa sponsorship for these positions.
American Express CultureAt American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.
Benefits- Competitive base salaries
- Bonus incentives
- Support for financial well-being and retirement
- Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- Generous paid parental leave policies (depending on your location)
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities
Third Party Risk Analyst employer: TEAM Inc.
Contact Detail:
TEAM Inc. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Third Party Risk Analyst
✨Tip Number 1
Network like a pro! Reach out to current or former employees at American Express on LinkedIn. Ask them about their experiences and any tips they might have for landing the Third Party Risk Analyst role. Personal connections can give you insights that job descriptions just can't.
✨Tip Number 2
Prepare for the interview by brushing up on your knowledge of Third-Party Risk Management and Information Security. Be ready to discuss how you would handle specific scenarios related to risk assessments and compliance. We want to see your analytical skills in action!
✨Tip Number 3
Showcase your communication skills! During interviews, practice translating technical jargon into business-friendly language. This is crucial for the role, so demonstrate how you can make complex concepts easy to understand for stakeholders.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining Team Amex and contributing to our mission.
We think you need these skills to ace Third Party Risk Analyst
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Third Party Risk Analyst role. Highlight your relevant experience in Information Security and Third-Party Risk Management, and don’t forget to mention any specific skills that match the job description.
Showcase Your Analytical Skills: Since this role requires strong analytical abilities, be sure to include examples of how you've assessed control designs or interpreted risk data in your previous roles. Use clear, concise language to demonstrate your thought process.
Communicate Clearly: Your written communication skills are crucial for this position. When drafting your application, aim for clarity and simplicity. Avoid jargon where possible and focus on translating technical concepts into business-friendly language.
Apply Through Our Website: We encourage you to apply directly through our website. This not only streamlines the process but also ensures your application reaches the right people. Plus, it shows you're keen on joining Team Amex!
How to prepare for a job interview at TEAM Inc.
✨Know Your Stuff
Make sure you brush up on Third-Party Risk Management and Information Security fundamentals. Familiarise yourself with relevant frameworks like ISO 27001 or PCI DSS, as well as the specific requirements of American Express. This will help you speak confidently about how your skills align with their needs.
✨Showcase Your Analytical Skills
Prepare to discuss your experience with data analysis and risk assessments. Be ready to provide examples of how you've identified control gaps and proposed effective solutions in past roles. This will demonstrate your ability to translate technical risks into business terms, which is crucial for this position.
✨Communicate Clearly
Practice explaining complex concepts in simple language. Since you'll be working with various stakeholders, being able to convey technical information clearly is key. Consider preparing a few scenarios where you've successfully communicated risk management strategies to non-technical audiences.
✨Engage with Questions
Prepare thoughtful questions that show your interest in the role and the company. Ask about their current challenges in third-party risk management or how they measure success in this area. This not only shows your enthusiasm but also helps you gauge if the company is the right fit for you.