At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
This Staff Cybersecurity leader will be accountable for the Network Security Data Protection technical strategy and architecture. They will lead a team of one to two architects and engineers to transform our current network security strategy, improving our cost, speed to value for our customers, while improving our security posture. This leader will author the strategy for data center network security, public cloud network security and edge network security. This will require close collaboration with network and cloud architecture and engineering teams. The leader must be a catalyst for change and offer innovative network security solutions.
Responsibilities :
- Designs and maintains comprehensive network security architecture, ensuring scalability and resilience against evolving threats
- Oversees the integration of advanced security technologies and methodologies into enterprise-wide systems, driving continuous improvement in security posture
- Adheres to enterprise governance models for network security architecture, ensuring robust risk management and compliance with global regulatory requirements
- Authors Policies and Standards that govern network security
- Assesses highly complex security incidents and breaches, coordinating cross-functional teams and external partners to identify architectural changes to mitigate impact and prevent recurrence
- Reviews and approves exceptions, assesses risk, coaches teams on best practices to comply with Network Security Policies and Standards.
- Anticipates, researches and evaluates the impacts of emerging technology, threats, trends and geopolitical developments on the organization's security architecture, recommending and implementing strategic improvements
- Leads cross-functional engineering teams to align implementations with technical specifications and blueprints, facilitating efficient project execution
- Leads development of proof of concepts to evaluate the latest trending software / tools in the industry to recommend the right tool for unique business scenarios
- Architects and designs complex secure network solutions, including advanced firewalls, VPNs, intrusion detection / prevention systems, or other security systems to protect the organization's data
- Ensure networks security strategy and its control implementations protect sensitive data in transit and at rest, ensuring the confidentiality and integrity of the organization's data
- Leads, mentors, and coaches teams, fostering a culture of excellence, continuous professional growth, and knowledge sharing within the cyber & network security community
- Oversees the development of detailed technical documentation and reports on security assessments and findings and creates remediation efforts to provide inputs to senior management and stakeholders
- Collaborates and co-creates effectively with teams in product and the business to align technology initiatives with business objectives
Qualifications :
Bachelor's degree in Computer Science, Information Systems, Information Technology, Cybersecurity, and / or comparable experience; advanced degree preferredKnowledge of cybersecurity technology portfolios, security principles, and frameworksKnowledge of Network Security and Application SecurityKnowledge of Threat ModelingKnowledge of Identity & Access Management (IAM)Knowledge of Data Privacy & Protection (DPP, GDPR)Knowledge of Cloud Security ManagementKnowledge of global regulatory requirements and industry standards for cybersecurityKnowledge of Data Security ManagementKnowledge of Application Development & SecurityKnowledge of Data EngineeringKnowledge of scripting languages such as Python, Bash, or PowerShell for automating security tasksKnowledge of network protocols (e.g., TCP / IP, DNS, HTTP) and security fundamentalsPreferred Qualifications :
Experience architecting and engineering network and network security on premises and in the public cloudDeep understanding of network security principles and technologies including physical, host-based and virtual firewalls, network micro-segmentationExperience with SIEM (Security Information and Event Management) tools such as Splunk, ArcSight, QRadar, or ElasticExperience with IDS / IPS (Intrusion Detection Systems / Intrusion Prevention Systems)Experience with network security tools such as firewalls (e.g., Palo Alto, Cisco ASA, Illumio, Istio), intrusion detection systems (e.g., Snort, Suricata), WAF and Bot protection (Akamai, CloudFlare, Cequence)Experience in Technical Writing and Documentation DevelopmentExperience in leading network incident response efforts, including forensic analysisExperience with threat intelligence platforms (e.g., ThreatConnect, Recorded Future) and their integration into network security operationsExperience with securing cloud environments (e.g., AWS, Azure, Google Cloud) and implementing cloud security best practicesExperience responding to and adhering with regulatory requirements and standards (e.g., PCI-DSS, ISO 27001, NIST)Guardian