Manager-Technology Risk & Control

The Enterprise Technology Services organization partners with every part of the American Express business to power the company’s growth and innovation with trust and efficiency, and drive competitive differentiation with speed. We support the delivery and operations of technology, digital, and data capabilities, platforms, and services globally. Specifically, our team is responsible for the company’s technology engineering, architecture, and infrastructure, providing 24x7 support to ensure an uninterrupted, high-quality experience for customers and colleagues. We also provide product management for core enterprise platforms, and lead technology risk and information security, enterprise data governance and platforms, digital product and design, and enterprise AI platforms on behalf of the company.

Enterprise Digital (ED) within Enterprise Technology Services (ETS) creates unified digital experiences for prospects and Card Members across the customer lifecycle, powered by data and digital capabilities. Within ETS, the Control Management organization is responsible for identifying, assessing, monitoring, and mitigating operational and compliance risk, while strengthening the overall control environment.

The Risk Identification & Assessment team partners across business, enterprise risk management, compliance, technology, 2LOD and audit functions to drive effective risk governance, Risk and Control Self-Assessments (RCSA), control design and enhancement, and operational risk management activities.

Role Summary

The Manager, Control Management – Risk Identification & Assessment will lead risk assessment and control management activities across key Enterprise Digital processes, with a primary focus on the transition from legacy PRSA frameworks to the enterprise RCSA methodology. This role will partner closely with business process owners, Compliance, Operational Risk Management (ORM), Internal Audit Group (IAG), Enterprise Control Management (ECM) and Technology partners to ensure risks are appropriately identified, assessed, monitored, and mitigated.

The successful candidate will serve as a subject matter expert in RCSA execution, operational risk management, and control governance while providing leadership and oversight to analysts. This role requires strong stakeholder management, analytical thinking, and the ability to influence outcomes across a complex organizational environment.

Key Responsibilities

Risk Identification & Assessment (RCSA)

  • Lead execution and governance of Risk and Control Self-Assessments (RCSA) across assigned business processes, ensuring effective ownership of controls and sustainable control environment management.
  • Lead the transition of legacy Process Risk Self-Assessments (PRSAs) to the enterprise RCSA framework, including risk rationalization, control mapping, governance alignment, and decommissioning activities and Archer records following successful migration.
  • Maintain governance and oversight of legacy PRSAs pending future RCSA implementation.
  • Partner with Risk Identification teams across Enterprise to execute periodic RCSA refreshes, residual risk assessments, and control effectiveness evaluations.
  • Support development of future-state risk assessment strategies and implementation roadmaps.

Control Management & Operational Risk

  • Maintain ownership of control inventory, control design, control enhancements, and control governance activities.
  • Assess control effectiveness and identify opportunities to strengthen the control environment.
  • Monitor and manage residual risks across operational and compliance risk domains.
  • Support issue remediation, and closure activities resulting from risk assessments, testing, audits, and regulatory reviews.
  • Partner with process owners to implement sustainable corrective actions and preventive controls.
  • Support enterprise-wide initiatives focused on risk reduction and operational excellence.

Governance, Audit & Regulatory Support

  • Support Internal Audit Group (IAG) engagements, audit responses, remediation activities, and evidence management.
  • Facilitate regulatory examination support and management response activities.
  • Prepare and present risk assessment results, risk themes, and control environment insights to leadership and governance forums.
  • Ensure alignment with Operational Risk Management (ORM) standards, policies, and enterprise risk frameworks.

Digital, Technology & AI Risk Leadership

  • Lead risk identification and assessment activities across cloud-based platforms, digital products, data ecosystems, and emerging AI/ML solutions.
  • Partner with Engineering, Product Management, Architecture, and Data Science teams to proactively identify technology, operational, model, and data-related risks throughout the development lifecycle.
  • Assess risks associated with cloud infrastructure, distributed systems, APIs, third-party integrations, MLOps pipelines, model deployment practices, and automated decisioning solutions.
  • Support governance and oversight of AI/ML initiatives, including model explainability (XAI), model monitoring, model drift, bias management, and Responsible AI practices.
  • Develop risk indicators, monitoring capabilities, and reporting frameworks that provide actionable insights into technology and AI-related risk exposure.
  • Translate complex technical and algorithmic risks into business-relevant risk narratives, enabling effective decision-making by senior leadership.
  • Partner with Enterprise Digital leadership to align risk management priorities with strategic business objectives and digital transformation initiatives.
  • Contribute to the design and scaling of future-state risk architecture supporting cloud, data, digital product, and AI-enabled business capabilities.

People Leadership

  • Provide day-to-day leadership, coaching, and development for 1–2 analysts.
  • Establish priorities, monitor deliverables, and ensure high-quality execution of risk assessment activities.
  • Foster a culture of accountability, collaboration, continuous improvement, and strong risk management practices

Required Qualifications

  • 8+ years of experience in Operational Risk Management, Control Management, Risk Identification & Assessment, RCSA, Compliance, Internal Audit, or related risk disciplines.
  • Bachelor/Master’s degree in Business, Finance, Risk Management, Digital , or related discipline.
  • Strong hands-on experience executing and facilitating Risk and Control Self-Assessments (RCSA).
  • Demonstrated understanding of Operational Risk Management (ORM) frameworks, risk governance, and control management practices.
  • Experience assessing control design and operating effectiveness.
  • Strong stakeholder management skills with the ability to influence across multiple levels of the organization.
  • Experience managing cross-functional initiatives involving business, compliance, risk, technology, and audit partners.
  • Strong analytical, problem-solving, and communication skills.
  • Experience working with risk management platforms such as Archer , Service Now or equivalent governance, risk, and compliance (GRC) tools.
  • Ability to lead and develop team members.

Preferred Qualifications

  • Knowledge of regulatory expectations within the financial services industry.
  • Experience supporting Internal Audit, regulatory examinations
  • Professional certifications such as CRISC, CISA, CIA, CRCM or equivalent preferred.