Michael Czarnecki
Senior Director of Cyber Security Risk Oversight & Ai @American Express
Signup · Get unlimited contacts
WORK HISTORY
Senior Director of Cyber Security Risk Oversight & Ai @American Express
NY, US
Oversaw second-line cybersecurity risk governance, leading the development and enforcement of a unified control taxonomy and mapping framework aligned with NIST 800-53, ISO 27001, and internal enterprise policies. • Delivered quarterly board and committee risk memos supported by automated dashboards and thematic insights covering vulnerability aging, AI usage, and EUC governance, enhancing executive decision-making and regulatory defensibility. • Executed credible challenge reviews across cloud posture, encryption lifecycle, and LLM integration, ensuring adherence to policy and proactive mitigation of risk acceptance gaps. • Led data discovery initiatives to surface control misalignments across SaaS platforms, automating evidence collection and control effectiveness assessments via ServiceNow GRC and Power BI. • Built an AI governance playbook for LLM tools (e.g, Copilot,), embedding prompt injection safeguards, access controls, and classification rules into the policy stack. • Partnered with tech and risk teams to backtest the Risk Acceptance Framework, streamlining exception handling and improving audit readiness across SOX and OCC regulatory expectations. • Co-led the enterprise migration off Archer, ensuring continuity of policy mapping, exception workflows, and validation standards in the target GRC platform.
EDUCATION
University of Maryland Global Campus
Master's degree, Cyber Security
County College of Morris
A.S. Degree, Computer Science; Computer Science
University of Maryland University College
Bachelor’s Degree, Cyber Security
Harvard Business School Online
Credential of Digital Innovation and Strategy, Digital Transformation, AI Strategy, and Platform Business Models
SKILLS
ABOUT MICHAEL CZARNECKI
With over a decade in cybersecurity leadership, I’ve led threat assessments, risk management, and security operations for top financial institutions, including Capital One and American Express. I understand the high-stakes world of financial security—where a single breach can mean millions in loss.•Cybersecurity Strategy & Compliance – Aligning security with business goals to avoid regulatory pitfalls.•Threat & Risk Management – Assessing vulnerabilities and implementing solutions to protect high-value assets.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.