Live opening · Posted 8 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
International Card Services (ICS) brings together our International Consumer and Small & Medium Size Enterprises (SME) issuing activities, as well as our Commercial Large Market sales and account development teams. ICS issues Cards in 27 countries, and is responsible for two Joint Ventures covering around a dozen countries. The leaders in these countries are empowered to make decisions at a local level, in partnership with other local business leaders. Local teams are supported by two cross-market teams – the Centre of Excellence, and Risk & Control Management.
The ICS Control Management Risk ID, Assessment, Testing & Reporting team is responsible for identifying, assessing, mitigating, and reporting Operational Risk across ICS business processes, supporting adherence to regulatory requirements and Amex policies while strengthening the control environment and business resilience.
Required Qualifications
• 3+ years of experience in Operational Risk, Controls Creation/Management, Compliance, Process Improvement, Business Transformation, Internal Audit, or related risk and control disciplines.
• Hands-on experience with RCSA or similar Risk & Control Self-Assessment frameworks, including risk identification, assessment, control evaluation, and remediation.
• Hands-on experience in creating, documenting, and enhancing controls and conducting control testing.
• Good understanding of control design and operating effectiveness, including walkthroughs, evidence review, testing, and identification of control deficiencies.
• Experience identifying inherent and residual risks, control gaps, root causes, and mitigation actions.
• Familiarity with Change Management processes and assessing risk and control implications arising from business or technology changes.
• Experience working with business/process owners and Risk, Compliance, Audit, Technology, and other control functions.
Preferred Qualifications
• Regulatory Obligation Management experience is highly regarded, including experience mapping regulatory or policy requirements to processes and controls.
• Experience developing or maintaining RCMs, process flowcharts, process narratives, and risk/control documentation.
• Experience supporting Audit, regulatory examinations, Second Line reviews, issue management, and remediation activities.
• Experience with GRC platforms such as Archer and ServiceNow, or equivalent.
The role will be responsible for strengthening the First Line Risk & Control framework through Process Confirmation, RCSA & Control Development, Access Governance, Change Management, and Audit/Regulatory Support.
The individual will partner with business teams, process owners, Legal Entity Governance, Technology, Operational Risk Management, Compliance, and other control functions to ensure risks are appropriately identified, controls remain current and effective, access risks are appropriately managed, and regulatory obligations are met.
Key Responsibilities
• Manage and support the transition of the existing PRSA program to RCSA, ensuring adherence to RCSA and Internal Control Framework requirements.
• Participate in RCSA activities to identify and assess inherent and residual risks, evaluate controls, identify control gaps, and develop appropriate mitigation plans.
• Partner with process owners to identify key operational and compliance risks, provide risk-based consultation, and strengthen the overall control environment.
• Support development and maintenance of Risk & Control Matrices (RCMs), process flowcharts, risk and control inventories, and controls documentation.
• Design and create new controls and enhance existing controls arising from RCSA findings, NPAs, OREs, Audit MAPs, regulatory requirements, and business/process changes.
• Support Change Management activities by assessing risk and control impacts arising from changes to products, processes, systems, and technology.
• Support Regulatory Obligation Management, including mapping applicable requirements to business processes and controls and identifying potential gaps.
• Review and action Second Line requests, including those relating to Privacy, Records Management, Operational Risk, and Compliance.
• Provide analytical risk insights by analyzing RCSA, controls, testing, and issue data to identify trends, emerging risks, control gaps, and root causes.
• Identify opportunities for process improvement, control simplification, automation, and business transformation.
Work arrangement
Hybrid
More openings worth a look
Recently tracked roles with full details and direct application links.