American Express

CNAPP/ Cybersecurity Engineer

American Express$100K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in cloud security engineering across AWS, GCP, and Azure, including hybrid environments like OpenShift.
  • Hands-on experience designing and scaling CNAPP capabilities (e.g., Palo Cortex) in multi-cloud settings.
  • Proficient in CSPM, CWPP, CIEM, and container security management.
  • Experience securing Kubernetes environments, focusing on container security and policy enforcement.
  • Skilled in defining and developing Policy-as-Code frameworks (e.g., Terraform).
  • Ability to analyze and prioritize security findings across cloud platforms using automation playbooks.
  • Experience integrating CNAPP tools with on-premise capabilities for continuous monitoring.

Responsibilities

  • Manage daily CNAPP platform configurations and triage identity risk challenges.
  • Investigate security signals across multi-cloud environments to prioritize high-risk exposures.
  • Collaborate with policy-as-code teams to enforce secure configurations based on CNAPP findings.
  • Evaluate new cloud security tools and recommend scalable adoption strategies.
  • Document solutions and patterns to enable team knowledge sharing and adoption.
  • Act as a technical resource for application teams on secure cloud-native architecture design.
  • Embed security controls within CI/CD pipelines to ensure continuous compliance.

Benefits

  • Access to advanced training and certifications in cloud security technologies.
  • Collaborative working environment with cross-functional teams.
  • Opportunity to shape enterprise security posture and policies.
  • Flexible working arrangements to support work-life balance.
  • Involvement in cutting-edge security platform development and technologies.
Full Job Description
Job Description

The Engineer will be part of mainstream to establish comprehensive, end-to-end visibility across all cloud and SaaS environments by integrating with core systems of record into CNAPP, delivering a unified and consistent telemetry layer across platforms. Our focus is to provide accurate, prioritized, and actionable insights that reduce noise and enable effective decision-making. Democratize access to security intelligence, ensuring teams have the right context to act quickly and independently, while maintaining alignment with enterprise risk and governance standards. By embedding security leveraging Policy-as-a-Code capability seamlessly into cloud and SaaS adoption journeys, we enable speed without compromise driving scalable, secure, and efficient operations across the organization

How will you make an impact in this role?

As part of this transformation, we are building a next-generation multi-cloud security platform and are seeking a CNAPP-focused engineer to drive visibility, risk reduction, and secure cloud adoption at scale. This role will play a critical part in shaping the enterprise security posture across AWS, Azure, GCP, and private cloud environments (e.g., OpenShift).

In this role, you will operate within a DevSecOps model, partnering closely with Technology Risk and Information Security (TRIS), Cloud Security Governance, Cloud Security Operations, and engineering teams across the organization. You will help identify, design, and deliver scalable security capabilities that are deeply integrated into cloud platforms and developer workflows.

You will drive a strong automation-first mindset, enabling zero-touch, idempotent, and scalable solutions through everything-as-code across infrastructure, security controls, and platform services. Success in this role requires the ability to operate across multiple initiatives, prioritize effectively, and translate evolving security and cloud technologies into practical, enterprise-ready solutions.

We are looking for a highly motivated, forward-thinking engineer who can balance technical depth with execution discipline, contribute to the maturation of end-to-end security capabilities, and ensure a seamless and secure experience for our engineering community.

Responsibilities

  • Manage CNAPP (Cortex/Prisma/Wiz) Platform configurations, and challenges on a daily basis, triaging challenge's identity risks, and alerts, and driving remediation with engineering teams.
  • Investigate and correlate security signals across multi-cloud environments (AWS, GCP, Azure, OpenShift) to identify high-risk exposures and prioritize actions based on business impact and exploitability.
  • Work closely with PaC (policy-as-code) and guardrails (OPA, Sentinel, native cloud policies) teams to enforce secure-by-default configurations across cloud platforms for the CNAPP findings.
  • Contribute to proof-of-concept efforts by evaluating new CNAPP features, cloud security tools, and container security capabilities, and recommending scalable adoption strategies.
  • Document solutions, patterns, and learnings through runbooks, architecture decision records (ADRs), and knowledge-sharing sessions to enable broader team adoption.
  • Act as a go-to technical resource, supporting application teams in designing secure cloud-native architectures and troubleshooting security-related issues.
  • Work closely with Cloud Engineering and DevOps teams to embed security controls into CI/CD pipelines, ensuring shift-left security and continuous compliance.
  • Support onboarding of new cloud accounts, Kubernetes clusters, and services into CNAPP by configuring data ingestion, identity mapping, and policy enforcement.
  • Analyze cloud usage patterns and integrate with DSPM capabilities to identify sensitive data, validate access controls, and reduce data exposure risks.
  • Collaborate with SIEM/SOAR and observability teams to integrate CNAPP signals into detection and response workflows, improving visibility and incident response time.
  • Participate in incident triage and root cause analysis, contributing to remediation strategies and continuous improvement of detection and response playbooks.


Qualifications

  • 3+ years of experience in cloud security engineering across AWS, GCP, and/or Azure, with exposure to hybrid or private cloud environments (e.g., OpenShift).
  • Experience in leading the design, hands-on implementation, and scaling of CNAPP capabilities (e.g., Palo Cortex) across multi-cloud environments including AWS, Azure, GCP, and OpenShift-based private cloud.
  • Strong understanding and enabled end-to-end :
    • CSPM, CWPP, CIEM, container security, and runtime protection posture management
    • Cloud misconfiguration management and remediation automation
  • Experience securing Kubernetes/OpenShift environments, including container security, workload isolation, and OPA policy enforcement.
  • Define and developing policy-as-code frameworks (e.g., Cloud Native, Hashi Sentinel) and Infrastructure-as-Code tools (e.g., Terraform).
  • Analyzing and prioritize security findings across cloud environments, correlating misconfigurations, vulnerabilities, identity risks, and runtime threats by leveraging XQL and automation playbooks to drive remediation strategies.
  • Experience in integrating Palo Cortex with on-prem capabilities such as SIEM/SOAR and observability platforms for continuous monitoring and threat detection with CNAPP signals.
  • Experience in evaluating, onboard, and optimize CNAPP tools (Palo Alto Cortex, Wiz, or similar), ensuring full integration across cloud accounts, Kubernetes environments, andCI/CD pipelines.

Preferred Qualifications:
  • Knowledge of cloud security frameworks and benchmarks such as CIS Benchmarks, NIST, and Cloud Control Matrix (CCM).
    Having an understanding of network security, identity, and data protection domain and technical implementation framework across cloud platforms.
  • Experience in developing and maintain cloud security reference architectures, detection patterns, and response playbooks aligned with enterprise governance and regulatory requirements.
  • Strong analytical and problem-solving skills, with the ability to prioritize risks based on impact and exploitability.
  • Experience working in Agile environments, collaborating across engineering, platform, and security teams.


About American Express

Amex provides industrial services to the coatings and linings sector, providing support for commercial, industrial, and maritime projects such as petrochemical, power, and water treatment industries. They offer painting services for steel structures, storage tank linings and coatings, pipelines, floors, and marine vessels such as ships, tugboats, and barges.

American Express Careers

Join the vibrant team at American Express, a global leader in financial services, and be part of a company that values innovation, leadership, and diversity. At American Express, we offer more than just job opportunities; we provide a platform for professional growth and a chance to be part of a culture that is committed to excellence and inclusive growth. Work You’ll Do At American Express, we are dedicated to helping our employees reach their full potential. With a variety of career paths available in areas such as technology, marketing, finance, and customer service, American Express is the perfect place to advance your career. Our team is composed of highly skilled professionals who thrive on innovation and collaboration. Join our team and contribute to a company known for its prestigious history of leadership in the credit card industry. Engage in meaningful work that makes a real impact on our global scale business operations. American Express Leadership and Development Programs We believe in nurturing the leadership skills of our employees with extensive training programs and leadership development opportunities. Our commitment to professional growth is evident in our comprehensive benefits package that supports both personal and professional development. Internship Opportunities Start your career with an internship at American Express and gain valuable industry experience. Our internships offer a chance to develop skills, work on challenging projects, and learn from leaders in the industry. Interns at American Express are considered integral members of the team and are given responsibilities that provide a real insight into their future career paths. Diversity and Inclusion At American Express, diversity and inclusion are at the core of our company culture. We are committed to building a diverse workforce and inclusive environment where every employee feels valued and inspired. We offer diversity training programs that empower our employees to thrive and lead in a global marketplace. Networking and Innovation Our employees enjoy unparalleled opportunities for networking and personal growth through our global connections and innovative projects. American Express encourages a culture of innovation that helps propel our company and your career forward. Career Benefits and Growth American Express is dedicated to the growth of its employees. We offer competitive benefits, including health, retirement plans, and family leave, ensuring that our team members have the support they need to succeed both at work and in their personal lives. Join Our Team Explore the job opportunities and open positions at American Express. We are continuously hiring talented individuals who are passionate about their careers and interested in working for a company that offers a dynamic and supportive environment. Stay Connected Keep up to date with the latest from American Express Careers by following our career blog and signing up for job alert emails. Tailor your subscription to receive updates that match your skills and interests. Discover the exciting and rewarding career opportunities that await at American Express. SEARCH AMERICAN EXPRESS JOBS Whether you are looking for a full-time position, an internship, or a leadership opportunity, American Express offers a path to a rewarding career. Join us and make a difference with your passion, creativity, and drive.
Learn more about American Express
Size
64,000 employees
Market Cap
$108.1 billion
Industry
Net Income
$3.1 billion
Founded
1850
5 Year Trend
+3.5%
Revenue
$37 billion
NASDAQ

Similar Jobs

More Jobs at American Express

More Information Technology Jobs

Find similar CNAPP/ Cybersecurity Engineer jobs: