Join Team Amex and lets lead the way together.
International Risk and Controls sits within International Card Services (ICS), which comprises all the issuing functions across our 28 international markets. ICS is an integral part of the global growth strategy for American Express, and the Control Management teams objective is to foster a proactive and effective control environment that ensures adherence to regulatory standards and Amex policy.
ICS Control Management is looking for a detail-oriented and analytical Analyst to join our team. This role is focused on the independent testing and assurance of business process controls. You will be a key contributor to ensuring our control environment is robust, well-documented, and operating effectively as we transition to a new Risk & Control Self-Assessment (RCSA) framework. This position will involve extensive collaboration with partners across numerous business units and geographies.
How will you make an impact in this role
The Analyst, ICS Control Management Risk ID, Assessment, Testing & Reporting will :
- Execute independent control testing to assess both the design effectiveness and operating effectiveness of key controls within the business.
- Gather and document robust, high-quality evidence to support testing conclusions, and ensure timely and accurate updates in the system of record (e.g., Archer, ServiceNow or similar).
- Partner with control owners and business process experts to conduct control walkthroughs and gain a deep understanding of the processes under review.
- Identify, document, and report on control deficiencies, gaps, or weaknesses with clarity, providing actionable insights for remediation by the process owner.
- Prepare clear and concise reports on testing results for management, highlighting key themes and trends.
- Contribute to the continuous improvement of the control testing methodology, including sampling strategies and documentation standards.
- Support the business in the ongoing adoption and embedding of the new Risk and Control Self-Assessment (RCSA) framework.
Minimum Qualifications
- 2-3 years of experience in operational risk, internal controls, or a related testing/assurance function.
- Hands-on experience with control testing methodologies, including sampling, evidence gathering, and documentation.
- Strong analytical and problem-solving skills with a keen eye for detail and the ability to identify the root cause of control failures.
- Excellent communication and interpersonal skills, with the ability to articulate complex issues to stakeholders clearly and concisely.
- Proven ability to work independently, manage competing priorities, and meet deadlines in a fast-paced environment.
Preferred Qualifications
- Bachelor s degree in finance, Business, Risk Management, or a related field.
- Direct experience with a Governance, Risk, and Compliance (GRC) tool like Archer/ServiceNow for documenting test results.
- Familiarity with Risk and Control Self-Assessment (RCSA) frameworks.
- Proven ability to assess both control design (i.e., is the control designed properly to mitigate risk) and operating effectiveness (i.e., is the control working as intended).
- Experience working in a first line-of-defense risk or control management role within a global organization.
ORMCM