At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.
As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
Joining ETS Governance & Control means helping protect American Express customers and company through integrated, intelligence-driven technology risk and control management. Operating at the intersection of technology, governance, and risk, the team partners across the enterprise to modernize the foundation, advance risk intelligence, demonstrate trust at scale, and reduce material risk—enabling innovation with the right controls in place.
By building simplified, consistent frameworks and embedding continuous assurance, ETS Governance & Control enhances transparency, accountability, and sustainable risk reduction. The work is about empowering confident decisions, accelerating responsible delivery, and ensuring controls evolve with the business to strengthen trust and reduce enterprise risk at scale.
Role Overview
The Director, Technology Risk and Control (Software Development & Enterprise Architecture) is a senior leader within the Technology Governance & Control organization, accountable for risk advisory, governance, and control oversight across secure software development, engineering practices, enterprise architecture, and emerging technology domains.
This role partners with leaders across Technology, Engineering, Enterprise Architecture, Cybersecurity, Product, and Operational Risk to ensure technology risks are identified, assessed, governed, and mitigated through a robust Risk and Control Self-Assessment (RCSA) framework.
The successful candidate will bring deep expertise in technology risk management, software engineering and enterprise architecture practices, and governance of AI/ML and other emerging technology solutions within large, complex, and highly regulated environments.