Sr. Manager-CyberSec Engineering-SaaS Security & Cloud Security
American ExpressAbout the role
Description
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
- Evaluate various SaaS technologies and tools for technical, functional and financial feasibility.
- Lead and provide technical guidance and expertise to a team of analysts.
- Provide security expertise to the Cloud Security and SaaS Security teams, as it pertains to the SaaS Security program
- Assess, measure and report against cloud controls, and drive risk reduction guidance for all cloud platforms.
- Provide security expertise to the Cloud Program, including Software as a Service (SaaS), and Cloud Application Architecture subprograms.
- Deliver and mature cloud tooling across public clouds collaborate with enterprise architects and SMEs to deliver comprehensive security solutions.
- Build security threat models, and create new components, threats and countermeasures that can be referenced for future cloud development.
- Lead the technical design and deployment of global projects including security solutions for SaaS services.
- Capture requirements; build functional specifications, timelines, adoption plans and other artifacts to support security implementation.
- Partner with and support various technology and business teams to drive and execute results in a timely manner.
Minimum Qualifications
- Demonstrated leadership skills
- Knowledge of data classification solutions
- Able to learn and follow documented processes and procedures while identifying and implementing improvements in such processes
- Recognize and handle confidential and sensitive information appropriately according to Amex standards
- Must be able to identify and rank risky data outflows whether they occur via TOR networks, anonymizers, unsanctioned cloud apps, or any other channels
- Strong work prioritization, planning, and organizational skills
- Be able to collaborate effectively, work closely within a coordinated team environment, and maintain professionalism under any circumstance
- Knowledge of common web technologies, cloud technologies, enterprise, and network architecture
- Strong communication skills (written and verbal)
- Understanding of financial industry standards and regulations such as FedRamp, NIST, CSA, PCI, and SOX
Preferred Qualifications
- Bachelor’s Degree in computer science, computer engineering, or related field; or equivalent experience.Experience with Cloud Control Matrix and CIS benchmarks for gap assessment and threat remediation.
- 5+ years of experience in Information Security roles
- Broad understanding of all IS disciplines including, Governance, Cyber Threat, Identity and Access, Infrastructure, Endpoint Protection, Vulnerability, Data Protection, Operations, Application, Incident Response.
- Understanding of Information Security technology and platform delivery with experience in planning and execution of security projects.
- Knowledge of configuration management, identity and access management, endpoint security and secrets management as they are applied to SaaS products
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s