Hiring.Camp

Information Security Compliance Analyst

Click Here to Learn More

·

Jun 5, 2026

Location
Mexico
Type
Full-time
Department
Legal
Experience
3+ years
Education
Bachelor
Source
Workday

Description

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

 

Join our Governance, Risk & Compliance (GRC) team as an Information Security Compliance Analyst. You will lead critical security programs that protect the organization and empower the workforce. This role sits at the intersection of security awareness, phishing prevention, and policy governance—reporting to the IT Risk and Information Security Manager.

What You’ll Do

  • Design and implement phishing simulation campaigns; analyze emerging threat trends; develop targeted intervention strategies; and build automated reporting and response mechanisms
  • Develop and manage a policy exception framework with standardized review, documentation, and tracking processes aligned to organizational risk tolerance.
  • Build and deliver a tiered security awareness curriculum addressing cyber threats through engaging, multi-format materials and function-specific learning paths.
  • Maintain detailed audit trails across all programs to ensure compliance with information security protocols and industry frameworks including NIST, ISO 27001, and PCI DSS
  • Manage exception currency and access removal to ensure policy exceptions remain current and aligned with evolving risk posture

What We’re Looking For

  • 3–5 years of experience in Information Security, specifically within GRC or Security Awareness.
  • Experience designing and executing organizational phishing simulations, from technical setup through reporting and trend analysis.
  • Experience developing engaging, multi-format security awareness curricula and role-based training content.
  • Solid background in managing security policy exceptions, including risk alignment, documentation, and audit trail maintenance.
  • Skilled in creating reporting mechanisms to track phishing resilience, training completion rates, and overall program effectiveness.
  • Able to translate complex security concepts into clear, digestible training for all organizational levels, including executive audiences.
  • Familiarity with NIST CSF, ISO 27001, PCI DSS, or SOC2 as they relate to policy management and training compliance.
  • Experience with phishing simulation and LMS platforms such as KnowBe4, Proofpoint, or Adaptive Security, and GRC workflow tools such as Jira, ServiceNow, or Onspring.
  • Bachelor's degree in Information Security, Information Systems, or a related field (or equivalent experience).
  • Current CISSP or CISA certification preferred.

     

Location

Mexico

     

Click here to learn more about the benefits we offer in Mexico.

     

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Click Here for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;" please apply anyway. You may be exactly the person we’re looking for!

Skills

JiraServiceNowComplianceISO 27001CISSP

Similar Jobs

30

Head of Governance, Risk and Compliance (Information Security)

Leonardocompany · GB - Basildon - Home Based, United Kingdom +9 · Hybrid, Remote

5 days ago

Manager - Information Security Compliance

Verisign · Reston,Virginia,United States

6 days ago

Manager:in Information Security & Compliance (m/w/d)

Steeleurope · Hamborn, Germany · Remote

1 week ago

Sr. Information Security Compliance Analyst

Warnerbros · GA Atlanta 1050 Techwood Drive NW, United States of America · Hybrid

2 weeks ago

Information Security Compliance Analyst

Holmesmurphy · West Des Moines, United States of America

1 month ago

Information Security & Compliance Associate

Jobs at · Cordoba · Onsite

1 month ago

Information Security Compliance Analyst

"Eagle Creek Renewable Energy, LLC" · Badin, NC

1 month ago

Information Security & Compliance Manager

Blue Matter · London

1 month ago

Information Security Compliance Associate

Case IQ

1 month ago

Information Security Compliance Analyst

Fluke · India · Onsite

2 months ago

Information Security Compliance Analyst

Fortive · IN

2 months ago

Sr. Manager Information Security & Compliance

Ritzcarltonyachtcollection · Ft. Lauderdale, United States of America · Hybrid

2 months ago

Information Security Compliance Manager (India)

Tide · India, Delhi NCR

2 months ago

IT Compliance & Information Security Manager (m/f/d)

Onventis · Stuttgart, Baden-Württemberg

2 months ago

Senior Information Security Compliance Engineer

Crestron · Crestron Electronics Inc. - Plano, TX, 7250 Dallas Parkway, Plano, Texas, United States of America +1

2 months ago

Information Security & Compliance Leader

RFS Group · New York, San Francisco, California, New York · Hybrid, Onsite

3 months ago

Information Security Compliance Coordinator

Cgsfederal · Washington, DC · Remote

4 months ago

Information Security Compliance Specialist

Securiport · Reston, Virginia

6 months ago

Information Security Compliance Analyst - CISSP/CISA

Harborconsulting · Philadelphia, Pennsylvania, US

1+ year ago

Information Security Compliance Specialist

Tactibit Technologies LLC · Suitland, MD, US

1+ year ago

VP, Information Security and Compliance

JOIN THE TEAM · United States of America - Remote · Remote

1 week ago

Senior Information Security, Risk & Compliance Specialist

Geotab · z. Canada Job Post Template +1

2 weeks ago

Information Security and Compliance Analyst Intern

Interac Corp. · Interac Corp. Head Office, Canada

1 month ago

Associate Information Security and Compliance

Datavail Infotech Pvt. Ltd. · Mumbai, Maharashtra, India · Onsite

2 months ago

Director of Information Security Governance & Compliance

Sobi · Stockholm, Stockholm County, Sweden · Hybrid

2 months ago

Manager — Information Security and Compliance

Apexanalytix · Noida, India

2 months ago

Compliance Manager (Information Security)

Sterling Computers · North Sioux City, SD

3 months ago

Manager Information Security Architecture & Compliance - Full Time

Connecticut Children\'s · Hartford, CT, United States, US · Hybrid

4 months ago

Information Security and Compliance Lead

Hitachi Solutions · Sofia, Sofia City Province, Bulgaria · Hybrid

4 months ago

Sr Manager, Information Security and Compliance

Tarro · Dumaguete +1 · Onsite

1+ year ago