> Markdown version of [/jobs/ext/1593318-cyber-security-engineer-cnapp-aws-gcp-oci-and-or-azure](https://www.wearedevelopers.com/jobs/ext/1593318-cyber-security-engineer-cnapp-aws-gcp-oci-and-or-azure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer-CNAPP (AWS, GCP, OCI AND/ OR Azure) - **Company:** American Express Company - **Location:** Phoenix, AZ, United States - **Experience:** Experienced - **Salary:** $89,250.0 - $150,250.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Agile Methodology, Amazon Web Services, ARM Architecture, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Network Security, OpenShift, Security Information and Event Management, Private Cloud Environment, Google Cloud, Cloud Platform System, Delivery Pipeline, Multi-Cloud, Kubernetes, Infrastructure Automation Frameworks, CIS Benchmarks, Terraform, Oracle Cloud Infrastructure, Devsecops - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8b412a3acc59417a ## About the Role As part of this transformation, we are building a next-generation multi-cloud security platform and are seeking a CNAPP-focused engineer to drive visibility, risk reduction, and secure cloud adoption at scale. This role will play a critical part in shaping the enterprise security posture across AWS, Azure, GCP, and private cloud environments (e.g., OpenShift). In this role, you will operate within a DevSecOps model, partnering closely with Technology Risk and Information Security (TRIS), Cloud Security Governance, Cloud Security Operations, and engineering teams across the organization. You will help identify, design, and deliver scalable security capabilities that are deeply integrated into cloud platforms and developer workflows. You will drive a strong automation-first mindset, enabling zero-touch, idempotent, and scalable solutions through everything-as-code across infrastructure, security controls, and platform services. Success in this role requires the ability to operate across multiple initiatives, prioritize effectively, and translate evolving security and cloud technologies into practical, enterprise-ready solutions. We are looking for a highly motivated, forward-thinking engineer who can balance technical depth with execution discipline, contribute to the maturation of end-to-end security capabilities, and ensure a seamless and secure experience for our engineering community. * 3+ years of experience in cloud security engineering across AWS, GCP, and/or Azure, with exposure to hybrid or private cloud environments (e.g., OpenShift). * Experience in leading the design, hands-on implementation, and scaling of CNAPP capabilities (e.g., Palo Cortex) across multi-cloud environments including AWS, Azure, GCP, and OpenShift-based private cloud. * Strong understanding and enabled end-to-end : + CSPM, CWPP, CIEM, container security, and runtime protection posture management + Cloud misconfiguration management and remediation automation * Experience securing Kubernetes/OpenShift environments, including container security, workload isolation, and OPA policy enforcement. * Define and developing policy-as-code frameworks (e.g., Cloud Native, Hashi Sentinel) and Infrastructure-as-Code tools (e.g., Terraform). * Analyzing and prioritize security findings across cloud environments, correlating misconfigurations, vulnerabilities, identity risks, and runtime threats by leveraging XQL and automation playbooks to drive remediation strategies. * Experience in integrating Palo Cortex with on-prem capabilities such as SIEM/SOAR and observability platforms for continuous monitoring and threat detection with CNAPP signals. * Experience in evaluating, onboard, and optimize CNAPP tools (Palo Alto Cortex, Wiz, or similar), ensuring full integration across cloud accounts, Kubernetes environments, andCI/CD pipelines., * Knowledge of cloud security frameworks and benchmarks such as CIS Benchmarks, NIST, and Cloud Control Matrix (CCM). Having an understanding of network security, identity, and data protection domain and technical implementation framework across cloud platforms. * Experience in developing and maintain cloud security reference architectures, detection patterns, and response playbooks aligned with enterprise governance and regulatory requirements. * Strong analytical and problem-solving skills, with the ability to prioritize risks based on impact and exploitability.Experience working in Agile environments, collaborating across engineering, platform, and security teams. ## Description The Engineer will be part of mainstream to establish comprehensive, end-to-end visibility across all cloud and SaaS environments by integrating with core systems of record into CNAPP, delivering a unified and consistent telemetry layer across platforms. Our focus is to provide accurate, prioritized, and actionable insights that reduce noise and enable effective decision-making. Democratize access to security intelligence, ensuring teams have the right context to act quickly and independently, while maintaining alignment with enterprise risk and governance standards. By embedding security leveraging Policy-as-a-Code capability seamlessly into cloud and SaaS adoption journeys, we enable speed without compromise driving scalable, secure, and efficient operations across the organization ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)