Cyber Security Engineer-CNAPP (AWS, GCP, OCI AND/ OR Azure)

American Express Company
Phoenix, AZ, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$89,250.0 - $150,250.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Agile Methodology Amazon Web Services ARM Architecture Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Network Security OpenShift
+12 more
Security Information and Event Management Private Cloud Environment Google Cloud Cloud Platform System Delivery Pipeline Multi-Cloud Kubernetes Infrastructure Automation Frameworks CIS Benchmarks Terraform Oracle Cloud Infrastructure Devsecops

Job description

The Engineer will be part of mainstream to establish comprehensive, end-to-end visibility across all cloud and SaaS environments by integrating with core systems of record into CNAPP, delivering a unified and consistent telemetry layer across platforms. Our focus is to provide accurate, prioritized, and actionable insights that reduce noise and enable effective decision-making. Democratize access to security intelligence, ensuring teams have the right context to act quickly and independently, while maintaining alignment with enterprise risk and governance standards. By embedding security leveraging Policy-as-a-Code capability seamlessly into cloud and SaaS adoption journeys, we enable speed without compromise driving scalable, secure, and efficient operations across the organization

Requirements

As part of this transformation, we are building a next-generation multi-cloud security platform and are seeking a CNAPP-focused engineer to drive visibility, risk reduction, and secure cloud adoption at scale. This role will play a critical part in shaping the enterprise security posture across AWS, Azure, GCP, and private cloud environments (e.g., OpenShift).

In this role, you will operate within a DevSecOps model, partnering closely with Technology Risk and Information Security (TRIS), Cloud Security Governance, Cloud Security Operations, and engineering teams across the organization. You will help identify, design, and deliver scalable security capabilities that are deeply integrated into cloud platforms and developer workflows.

You will drive a strong automation-first mindset, enabling zero-touch, idempotent, and scalable solutions through everything-as-code across infrastructure, security controls, and platform services. Success in this role requires the ability to operate across multiple initiatives, prioritize effectively, and translate evolving security and cloud technologies into practical, enterprise-ready solutions.

We are looking for a highly motivated, forward-thinking engineer who can balance technical depth with execution discipline, contribute to the maturation of end-to-end security capabilities, and ensure a seamless and secure experience for our engineering community.

  • 3+ years of experience in cloud security engineering across AWS, GCP, and/or Azure, with exposure to hybrid or private cloud environments (e.g., OpenShift).
  • Experience in leading the design, hands-on implementation, and scaling of CNAPP capabilities (e.g., Palo Cortex) across multi-cloud environments including AWS, Azure, GCP, and OpenShift-based private cloud.
  • Strong understanding and enabled end-to-end :
  • CSPM, CWPP, CIEM, container security, and runtime protection posture management
  • Cloud misconfiguration management and remediation automation
  • Experience securing Kubernetes/OpenShift environments, including container security, workload isolation, and OPA policy enforcement.
  • Define and developing policy-as-code frameworks (e.g., Cloud Native, Hashi Sentinel) and Infrastructure-as-Code tools (e.g., Terraform).
  • Analyzing and prioritize security findings across cloud environments, correlating misconfigurations, vulnerabilities, identity risks, and runtime threats by leveraging XQL and automation playbooks to drive remediation strategies.
  • Experience in integrating Palo Cortex with on-prem capabilities such as SIEM/SOAR and observability platforms for continuous monitoring and threat detection with CNAPP signals.
  • Experience in evaluating, onboard, and optimize CNAPP tools (Palo Alto Cortex, Wiz, or similar), ensuring full integration across cloud accounts, Kubernetes environments, andCI/CD pipelines., * Knowledge of cloud security frameworks and benchmarks such as CIS Benchmarks, NIST, and Cloud Control Matrix (CCM). Having an understanding of network security, identity, and data protection domain and technical implementation framework across cloud platforms.

  • Experience in developing and maintain cloud security reference architectures, detection patterns, and response playbooks aligned with enterprise governance and regulatory requirements.
  • Strong analytical and problem-solving skills, with the ability to prioritize risks based on impact and exploitability.Experience working in Agile environments, collaborating across engineering, platform, and security teams.

Benefits & conditions

18850 North 56th Street, Phoenix, AZ 85054 Hybrid work $89,250 - $150,250 a year - Full-time

About the company

Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.

The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.

At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage-empowering you to innovate, grow, and help shape the future of a Fortune 100 company., At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.

As part of Team Amex, you’ll experience our powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

You must create an Indeed account before continuing to the company website to apply

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

4:47 min

Exploring OpenShift and Red Hat Developer Sandbox resources

Markus Eisele Markus Eisele · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all