empty

Information Security Analyst

American Express

Job Description

Posted on: 
September 17, 2024

Summary and company overview

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities, and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

As part of our diverse tech team, you can architect, code and ship software that makes us an essential part of our customers’ digital lives. Here, you can work alongside talented engineers in an open, supportive, inclusive environment where your voice is valued, and you make your own decisions on what tech to use to solve challenging problems. American Express offers a range of opportunities to work with the latest technologies and encourages you to back the broader engineering community through open source. And because we understand the importance of keeping your skills fresh and relevant, we give you dedicated time to invest in your professional development. Find your place in technology on #TeamAmex.

American Express is on an exciting Cloud transformation journey led by a high-energy, delivery-focused team delivering security as code and integration to enable on-premise equivalent security models for cloud workloads. The Cloud Security Engineering group builds and delivers technology which enables shift left security integration through partnership and collaboration across Technology Risk and Information Security, as well as multiple Technology teams. Information Security Analysts working in the Kubernetes Security domain will design and develop Cloud infrastructure security requirements across Cloud platform, container, network, and storage tiers to deliver security capabilities for the enterprise Hybrid Multi Cloud Journey. The Analyst will be accountable for securely enabling the cloud journey through a delivery-based program based on automation and a guardrails-based approach.

To be successful, you and your team will work very closely with other Technology Risk and Information Security functions, as well as Cloud Security Governance, Cloud Security Operations, and many other Technology and non-Technology teams to identify, solution, and deliver security code elements. You will drive automation, zero touch, and idempotency through “everything-as-code” across cloud platform and infrastructure components. This position demands a well-organized; action-oriented team player with the ability to prioritize daily work; work on multiple initiatives simultaneously; establish and maintain an outward looking view on new and evolving network edge technologies; and an ability to mature and operate business critical, end-to-end processes and solutions – while ensuring a great colleague user experience.

Responsibilities

  • Deliver Cloud Security Engineering functions intended to establish security code elements across private and public multi-cloud
  • Provide security and engineering expertise and guidance to the Cloud Programs, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Policy as Code (PaC).
  • Collaborate with enterprise architects and SMEs to deliver complete security architecture solutions.
  • Design and deliver Container security requirements and guardrails across VMs, Containers, CNI, CSI, and Mesh
  • Identify exciting opportunities for adopting new technologies to solve existing needs and predicting future challenges.
  • Present key security ideas to various audiences (technical and non-technical), in an effective manner.

Job Requirements

Required Skills/Experience:

  • 3 years of experience in Information Security roles.
  • 2 years of experience with OpenShift or Kubernetes cluster administration or Kubernetes security solution implementation.
  • Experience with Docker, Open Container Initiative (OCI), or similar containerization platforms.
  • Experience in defining Rego policies for enforcement through Open Policy Agent (OPA) Gatekeeper.
  • Experience using Infrastructure as Code to deploy and maintain OPA Gatekeeper in production environments.
  • Proven ability to read and critique source code, including Terraform and either Python or Go.
  • Experience in applying Security Principles to Kubernetes or OpenShift clusters and container workloads.
  • 2+ years of experience utilizing Git, GitOps and various Git workflows.
  • Experience with pull-based GitOps via ArgoCD to manage cluster deployments and workloads as code.
  • Experience working with GitHub Actions or Jenkins Pipelines.
  • Understanding of Cloud Fundamentals, including securing public cloud with data protection controls.
  • Experience performing validation and verification of configurations in a cloud environment.
  • Knowledge of security configuration management, container security, endpoint security and secrets management as they are applied to cloud applications.
  • Knowledge of network architecture, proxy infrastructure, and programs to support network access and enablement.
  • Understanding of multiple Information Security domains, such as Identity & Access Management, Infrastructure Vulnerability Management, Network Security, Data Loss Prevention, End User Security, etc.
  • Experience in defining resources configurations using Terraform or Helm.
  • Understanding of DevOps and DevSecOps principles

Educational Requirements:

  • Bachelor’s Degree in Computer Science, Software Engineering, Electric Computer Engineering (ECE) or equivalent information security degree.
  • Certified Kubernetes Administrator (CKA) or equivalent work experience.
  • Certified Kubernetes Security Specialist (CKS) preferred.
  • Other Information Security or Cloud Certifications preferred, such as CISSP, CISM, CCSP.

Additional commentary

  • Salary Range: $85,000.00 to $150,000.00 annually + bonus + benefits
  • The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.
  • We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:
  • Competitive base salaries
  • Bonus incentives
  • 6% Company Match on retirement savings plan
  • Free financial coaching and financial well-being support
  • Comprehensive medical, dental, vision, life insurance, and disability benefits
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities
  • For a full list of Team Amex benefits, visit our Colleague Benefits Site.
  • American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.
  • We back our colleagues with the support they need to thrive, professionally and personally. That's why we have Amex Flex, our enterprise working model that provides greater flexibility to colleagues while ensuring we preserve the important aspects of our unique in-person culture. Depending on role and business needs, colleagues will either work onsite, in a hybrid model (combination of in-office and virtual days) or fully virtually.
  • US Job Seekers/Employees - Click here to view the “Know Your Rights” poster and the Pay Transparency Policy Statement.
  • If the links do not work, please copy and paste the following URLs in a new browser window: https://www.dol.gov/agencies/ofccp/posters to access the three posters.
  • Employment eligibility to work with American Express in the U.S. is required as the company will not pursue visa sponsorship for these positions.

Summary and company overview

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities, and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

As part of our diverse tech team, you can architect, code and ship software that makes us an essential part of our customers’ digital lives. Here, you can work alongside talented engineers in an open, supportive, inclusive environment where your voice is valued, and you make your own decisions on what tech to use to solve challenging problems. American Express offers a range of opportunities to work with the latest technologies and encourages you to back the broader engineering community through open source. And because we understand the importance of keeping your skills fresh and relevant, we give you dedicated time to invest in your professional development. Find your place in technology on #TeamAmex.

American Express is on an exciting Cloud transformation journey led by a high-energy, delivery-focused team delivering security as code and integration to enable on-premise equivalent security models for cloud workloads. The Cloud Security Engineering group builds and delivers technology which enables shift left security integration through partnership and collaboration across Technology Risk and Information Security, as well as multiple Technology teams. Information Security Analysts working in the Kubernetes Security domain will design and develop Cloud infrastructure security requirements across Cloud platform, container, network, and storage tiers to deliver security capabilities for the enterprise Hybrid Multi Cloud Journey. The Analyst will be accountable for securely enabling the cloud journey through a delivery-based program based on automation and a guardrails-based approach.

To be successful, you and your team will work very closely with other Technology Risk and Information Security functions, as well as Cloud Security Governance, Cloud Security Operations, and many other Technology and non-Technology teams to identify, solution, and deliver security code elements. You will drive automation, zero touch, and idempotency through “everything-as-code” across cloud platform and infrastructure components. This position demands a well-organized; action-oriented team player with the ability to prioritize daily work; work on multiple initiatives simultaneously; establish and maintain an outward looking view on new and evolving network edge technologies; and an ability to mature and operate business critical, end-to-end processes and solutions – while ensuring a great colleague user experience.

Apply now