Director-Cyber Security- Network & Digital Edge Security
American ExpressAbout the role
Description
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.
As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
As Director - cybersecurity, you will define and lead the enterprise strategy for securing American Express’ digital edge and customer-facing applications across web, mobile, APIs, and cloud environments.
Key Responsibilities:
Strategy & Leadership:
- Define and execute the enterprise strategy for Application & Edge Security, including WAF, bot mitigation, API security, DDoS protection, and CDN/edge controls.
- Build and lead high-performing engineering and cyber defense teams.
- Partner closely with Product, Digital Engineering, Cloud, Infrastructure, Fraud Risk, and Architecture teams to embed security-by-design principles.
- Provide executive-level visibility into digital channel risks, resilience posture, and mitigation effectiveness.
Engineering & Architecture:
- Lead architecture and lifecycle management of:
- Web Application Firewalls (WAF)
- Bot management and automated threat mitigation platforms
- DDoS defense (L3/L4 and L7)
- Edge/CDN security controls
- Integrate behavioral analytics, telemetry, and ML-driven detection capabilities to reduce fraud and abuse.
- Ensure secure design patterns are embedded into customer-facing applications and APIs.
Operations & Resilience:
- Establish and manage KPIs/KRIs for:
- Credential stuffing and account takeover attempts
- Scraping and automation abuse
- Application-layer attacks (OWASP Top 10)
- Volumetric and protocol-based DDoS threats
- Lead incident response for high-severity edge or application-layer attacks.
- Continuously improve detection accuracy while minimizing customer friction.
Risk & Governance:
- Align controls with enterprise cybersecurity standards and regulatory expectations.
- Provide structured reporting to risk committees and senior leadership.
- Ensure third-party and vendor risk management across edge security providers.
- Support audits, regulatory exams, and control attestations as required.
Minimum Qualifications:
- 10+ years of experience in cybersecurity, with deep expertise in Application Security, Edge Security, or Digital Channel Protection.
- 5+ years of leadership experience managing cybersecurity engineering or operations teams.
- Strong knowledge of web arc
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s