Sr Cybersecurity Engineer I
Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.
At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.
Trust. Service. Security.
The Enterprise Technology Services organization partners with every part of the American Express business to power the company’s growth and innovation with trust and efficiency, and drive competitive differentiation with speed. We support the delivery and operations of technology, digital, and data capabilities, platforms, and services globally. Specifically, our team is responsible for the company’s technology engineering, architecture, and infrastructure, providing 24x7 support to ensure an uninterrupted, high-quality experience for customers and colleagues. We also provide product management for core enterprise platforms, and lead technology risk and information security, enterprise data governance and platforms, digital product and design, and enterprise AI platforms on behalf of the company.
- Drive AI-enabled security engineering and automation by partnering with application, engineering, and architecture teams to design and implement intelligent workflows, tools, and integrations that accelerate adoption of data security capabilities and secure-by-design practices.
- Design, develop, and enhance cryptographic libraries, APIs, and enterprise Key Management solutions, leveraging AI-assisted development and automation to improve engineering efficiency, security, scalability, and developer experience.
- Lead vulnerability management and remediation efforts for cloud-deployed applications, including vulnerability prioritization, remediation guidance, and validation, while driving consistent vulnerability management practices across the broader organization.
- Leverage AI and automation to improve vulnerability management, including accelerating vulnerability analysis, remediation recommendations, code-level fixes, prioritization, and identification of recurring security patterns and systemic risks.
- Perform security-focused code reviews to identify vulnerabilities, cryptographic weaknesses, insecure implementation patterns, and deviations from secure coding standards, while using AI-assisted tools where appropriate to improve review effectiveness and coverage.
- Develop reusable security tooling, automation, and guardrails that enable development teams to identify and remediate security issues earlier in the software development lifecycle and reduce manual security processes.
- Provide hands-on engineering and security consultation to internal development teams, helping teams integrate data protection, cryptography, key management and secure development practices into their applications.
- Collaborate across engineering, architecture, cloud, and cybersecurity teams to deliver scalable, resilient, developer-friendly data security capabilities that can be consistently adopted across diverse technology environments.
- Maintain high-quality internal and external technical documentation, ensuring implementation guidance, APIs, security standards, and product documentation remain accurate and aligned with evolving capabilities and security requirements.
- Identify opportunities to apply AI to cybersecurity engineering workflows, evaluating emerging AI-enabled technologies and developing practical solutions that improve security outcomes, developer productivity, vulnerability remediation, and operational efficiency.
- Mentor engineers and provide technical leadership across cybersecurity, secure software development, vulnerability management, cryptography, and AI-assisted engineering while contributing to the continuous improvement of team standards, processes, and technical capabilities.
- Bachelor’s degree in Computer Science, Computer Engineering, or equivalent.
- 6+ years of software engineering experience designing, developing, and delivering high-performance, scalable solutions using Java and modern Java frameworks within large-scale enterprise environments.
- Demonstrated experience leveraging AI-assisted development technologies, including GitHub Copilot, Large Language Models (LLMs), and other AI-enabled engineering tools to accelerate software development, code analysis, testing, documentation, and security engineering workflows.
- Experience designing and building high-performance libraries, SDKs, and REST APIs, with a strong focus on automation, scalability, security, resiliency, and developer experience.
- Hands-on experience developing Cryptography and Key Management solutions, with working knowledge of cryptographic standards, PKCS#11, Hardware Security Modules (HSMs), key lifecycle management, and secure integration patterns.
- Strong understanding of vulnerability management and secure software development practices, with demonstrated experience in driving remediation of application and cloud security vulnerabilities.
- Experience developing automated vulnerability remediation capabilities using CI/CD pipelines, GitHub Actions, security tooling, and AI-enabled technologies to accelerate vulnerability analysis, remediation, validation, and reporting.
- Experience with cloud platforms and cloud-native security practices, including securing applications, services, APIs, and workloads deployed in modern cloud environments.
- Strong analytical, engineering, and problem-solving skills, with the ability to evaluate complex security challenges, develop practical solutions, and use automation and AI to improve security outcomes at enterprise scale.
- Strong collaboration and technical leadership skills, with demonstrated ability to influence engineering teams, mentor developers, communicate security concepts effectively, and drive cross-functional initiatives across engineering, architecture, cloud, and cybersecurity organizations.
Depending on factors such as business unit requirements, the nature of the position, cost and applicable laws, American Express may provide visa sponsorship for some positions.