Job Description
Intro
Are you ready to explore a world of possibilities, both at work and during your time off? Join our American Airlines family, and you’ll travel the world, grow your expertise, and become the best version of you. As you embark on a new journey, you’ll tackle challenges with flexibility and grace, learning new skills and advancing your career while having the time of your life. Feel free to enrich both your personal and work life and hop onboard!
Why you'll love this job
- As one diverse, high-performing team dedicated to technical excellence, you will focus relentlessly on delivering unrivaled digital products that drive a more reliable and profitable airline.
- Cybersecurity Governance, Risk and Compliance (GRC) establishes the frameworks, oversight, and accountability that help the airline protect its operations, customers, data, and critical aviation systems. By aligning strategy, investment, risk management, and regulatory obligations, the function enables informed decision-making, operational resilience, and sustained compliance readiness.
- As a Cybersecurity Senior Manager, you will play a key leadership role in shaping how Cybersecurity operates, prioritizes work, and delivers capabilities across the enterprise. This role brings together governance, strategy execution, product and capability oversight, chief of staff operations, and cyber work management and finance to help strengthen risk reduction, improve transparency, and enable more effective decision-making across Cybersecurity.
What you'll do
This list is intended to reflect the current job but there may be additional essential functions (and certainly non-essential job functions) that are not referenced. Management will modify the job or require other tasks be performed whenever it is deemed appropriate to do so, observing, of course, any legal obligations including any collective bargaining obligations.
- Lead Cybersecurity Governance Capabilities: Set direction for cybersecurity governance capabilities, ensuring policies, standards, control expectations, and risk management practices are practical, scalable, clearly owned, and aligned to enterprise priorities.
- Oversee Cyber Products and Capabilities: Provide leadership over cybersecurity products, services, and enterprise capabilities by shaping roadmaps, prioritizing investments, tracking outcomes, and ensuring delivery supports risk reduction, regulatory readiness, and operational effectiveness.
- Drive Cyber Strategy, Planning, and Execution: Translate cybersecurity strategy into actionable priorities, roadmaps, operating rhythms, and measurable outcomes; partner with cyber leaders to ensure work is prioritized, resourced, governed, and delivered against commitments.
- Oversee the Chief of Staff Function: Provide leadership and direction for the Cybersecurity Chief of Staff role, ensuring the function supports effective leadership cadence, executive communications, decision support, cross-functional coordination, and follow-through on key actions and commitments.
- Lead Cyber Work Management and Financial Planning: Oversee Cybersecurity work intake, prioritization, resource planning, budget tracking, financial forecasting, and portfolio reporting to improve transparency, accountability, and investment decisions across the organization.
- Strengthen Risk, Compliance, and Executive Reporting: Partner across Cybersecurity, Technology, Legal, Finance, Audit, Privacy, and business teams to align risk and compliance activities, support regulatory obligations, and provide clear, outcome-focused reporting to senior leadership.
- Build and Develop High-Performing Teams: Lead, coach, and develop team members and managers; foster strong collaboration, ownership, sound judgment, accountability, and consistent delivery across complex cybersecurity initiatives.
All you'll need for success
Minimum Qualifications – Education & Prior Job Experience
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management, Compliance, Audit, or a related discipline, or equivalent experience/training.
- 7+ years of experience in cybersecurity, information technology, risk management, compliance, audit, governance, or a closely related field
- 5+ years of leadership experience
- Experience delivering and leading cybersecurity, information technology, risk management, compliance, audit, governance, or related activities.
Preferred Qualifications – Education & Prior Job Experience
- Bachelor's degree in Information Security, Computer Science, or a related field; advanced degree preferred
- 8+ years of experience in cybersecurity, information technology, risk management, compliance, audit, governance, or a closely related field preferred, and 6+ years of leadership experience
- Experience leading cybersecurity governance, risk management, compliance, control management, or related enterprise programs, including setting priorities, defining outcomes, and improving program maturity.
- Experience overseeing security audits, assessments, control assurance activities, remediation governance, and executive reporting to ensure clear ownership, accountability, and timely risk reduction.
- Experience applying regulatory, risk, compliance, and control frameworks such as NIST, ISO 27001, PCI DSS, SOX, SOC 2, CMMC, GDPR, or similar standards to guide strategy, prioritization, governance, and leadership decision-making.
All you'll need for success (continued....)
Skills, Licenses, and Certifications
- Strong leadership experience overseeing cybersecurity governance, risk management, compliance, portfolio management, or related enterprise capabilities.
- Ability to set strategic direction, define capability roadmaps, prioritize work, and align cyber products and services to enterprise risk, regulatory, and business objectives.
- Experience leading cyber work management, operating rhythms, resource planning, budget oversight, financial tracking, and portfolio reporting across complex organizations.
- Strong understanding of cybersecurity, risk, compliance, and control frameworks such as NIST, ISO 27001, PCI DSS, SOX, SOC 2, CMMC, GDPR, or similar standards.
- Proven ability to translate complex cybersecurity risks, priorities, and investments into clear executive-level communications, decision materials, metrics, and reporting.
- Demonstrated ability to lead cross-functional teams and influence senior stakeholders across cybersecurity, technology, finance, legal, audit, privacy, compliance, and business teams.
- Strong judgment, ownership, and executive presence, with the ability to drive alignment, resolve ambiguity, escalate decisions appropriately, and ensure follow-through on critical commitments.
- Experience building, coaching, and developing high-performing teams, including setting expectations, strengthening accountability, and improving delivery across multiple workstreams.
- Relevant cybersecurity, risk, audit, privacy, compliance, leadership, or project/program management certifications preferred, such as CISM, CISSP, CRISC, CISA, CDPSE, ISO 27001, PMP, or comparable certifications.
What you'll get
From the team members we hire to the customers we serve, inclusion and diversity are the foundation of the dynamic workforce at American Airlines. Our 20+ Employee Business Resource Groups are focused on connecting our team members to our customers, suppliers, communities, and shareholders, helping team members reach their full potential and creating an inclusive work environment to meet and exceed the needs of our diverse world.
Are you ready to feel a tremendous sense of pride and satisfaction as you do your part to keep the largest airline in the world running smoothly as we care for people on life’s journey? Feel free to be yourself at American.
Feel free to be yourself at American
From the team members we hire to the customers we serve, inclusion and diversity are the foundation of the dynamic workforce at American Airlines. Our 20+ Team Member Resource Groups are focused on connecting our team members to our customers, suppliers, communities and shareholders, helping team members reach their full potential and creating an inclusive work environment to meet and exceed the needs of our diverse world.
Are you ready to feel a tremendous sense of pride and satisfaction as you do your part to keep the largest airline in the world running smoothly as we care for people on life’s journey? Feel free to be yourself at American.