CyberSecurity Engineer 1
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
The Cybersecurity Analyst, Threat Intelligence & Red Team is a hybrid role supporting our Counter Adversary Operations function. This position splits its time between working as a Threat Intelligence Analyst ingesting, enriching, and actioning threat intel from multiple sources and fulfilling intel requests from partner teams and supporting our Red Team as a contributor to hands-on offensive security testing.
This role is well suited to an analyst early in their offensive security career who wants to build technical red team skills while developing strong threat intelligence fundamentals. The candidate will work closely with senior red teamers, threat hunters, detection engineers, and IR to help mature our security posture across a global, highly distributed travel and hospitality technology enterprise.
What You’ll Do
Threat Intelligence
- Monitor, triage, and ingest threat intel from OSINT, ISACs, and vendor feeds into the TIP
- Enrich IOCs/TTPs and correlate with internal telemetry
- Respond to RFIs from IR, DSI, and leadership
- Produce threat briefs, IOC packages, and actor profiles for travel/hospitality
- Map threat actor TTPs to MITRE ATT&CK
- Translate intel into hunt leads and detection opportunities
Red Team Support
- Assist with scoped engagements (recon, scanning, exploitation, lateral movement) under supervision
- Perform atomic/scenario testing aligned to ATT&CK
- Support Purple Team exercises and validate closed detection gaps
- Build familiarity with offensive tools (Kali, Burp Suite, BloodHound, C2) via mentorship
- Contribute to documentation, evidence capture, and reporting
Collaboration
- Partner with Detection Engineering, Threat Hunting, IR, and Red Team to close gaps
- Communicate findings clearly to technical and non-technical audiences, * Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.
- Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.
- Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.
- We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.
- And much more!
All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.
Click Here (https://explorer.amexglobalbusinesstravel.com/rs/346-POJ-129/images/Additional%20Disclosures%20in%20Accordance%20with%20the%20LA%20County%20Fair%20Chance%20Ordinance.pdf?version=2) for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.
Requirements
- 1-3 years in cybersecurity with exposure to threat intel and/or offensive security
- Foundational knowledge of MITRE ATT&CK
- Familiarity with IOCs, TTPs, Diamond Model, kill chain analysis
- Basic scripting (Python, PowerShell, or Bash)
- Ability to learn and support SOAR/CAO workflows
- Strong written communication for reports and documentation
- Interest in offensive security and willingness to learn
- Understanding of APIs and workflow integration
Preferred Qualifications
- Experience with a TIP (e.g., Cyber6Gill/Bitsight, ISACs, CrowdStrike CAO Elite)
- Exposure to AD attacks (BloodHound, Kerberoasting) or cloud security (AWS/Azure)
- CTF, home lab, or self-directed offensive security practice
- Certifications/coursework (Security+, GCTI, eJPT, OSCP progress)
- Experience with Atomic Red Team or similar frameworks
Benefits & conditions
$84,700.00 - $157,300.00
The national range provided includes the base salary that Amex GBT expects to pay for the role. Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.
About the company
Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement (https://www.amexglobalbusinesstravel.com/gbt-recruitment-privacy-statement/) .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.