Cybersecurity Architect II
American ExpressAbout the role
Description
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
Summary
American express is seeking Senior Network Security Engineer with deep expertise in cloud networking, zero trust security, and hybrid/multi-cloud architectures with proven ability to design, secure, and automate highly available cloud network environments while reducing risk and operational overhead. Recognized for strong analytical problem-solving, cross-functional collaboration, and delivering secure-by-design solutions at scale.
What You’ll Be Doing
- Design and evolve secure cloud network architectures across AWS, Azure, and GCP in alignment with security standards and business requirements.
- Implement, tune, and maintain Palo Alto, Security Group, and GCP firewall policies, balancing security controls with application performance and usability.
- Develop and maintain reusable Terraform modules to standardize cloud network security deployments.
- Embed network security controls into CI/CD pipelines using GitHub Actions, enabling consistent, automated, and auditable deployments.
- Partner with application, platform, and security teams to influence secure design decisions early in the development lifecycle.
- Perform regular security posture reviews of network configurations and firewall rules, identifying gaps and driving remediation efforts.
- Create and maintain clear documentation, reference architectures, and standards to support scalable and repeatable network security practices.
Required Qualifications
- Extensive hands-on experience designing and securing AWS VPCs, Azure Virtual Networks, and GCP VPCs, including subnet architecture, routing, NAT gateways, private endpoints, and security enforcement using cloud-native controls.
- Experience implementing and operating AWS Direct Connect, Azure ExpressRoute, and GCP Cloud Interconnect to support secure hybrid and multi-cloud connectivity.
- Specialized in deploying cloud firewalls, WAFs, DDoS protection, and Zero Trust access models to protect workloads, APIs, and users.
- Demonstrated proficiency in cloud-native networking and security controls across AWS, Azure, and GCP, including segmentation, identity-aware access, and traffic inspection.
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- VPC/VNet architecture, subnet design, routing, NAT gateways, private endpoints
- Hybrid and multi-cloud connectivity (site-to-site VPN, cloud interconnects)
- Palo Alto Networks, AWS Security Groups, GCP Firewall Rules
- Firewall policy design, threat prevention, IPS/IDS, SSL/TLS inspection
- Zero Trust networking, least-privilege access, network segmentation
- Terraform for multi-cloud infrastructure and security controls
- GitHub for source control and collaboration
- Core networking fundamentals: TCP/IP, BGP, routing, VPN technologies
Logging and monitoring fundamentals (firewall logs, flow logs, SIEM integration)
Preferred Qualifications
- GitHub Actions for CI/CD automation, security checks, and policy enforcement
- Load balancing (L4/L7), traffic segmentation, high availability design
- Identity and access integration with network security controls <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s