Prepin
Log in
American Express

engineering opportunity

Senior Cybersecurity Engineer-IAM And/ OR Cloud Security (AI Agent security)

Lead the design and implementation of identity security and secrets management for AI agents and machine identities across hybrid cloud environments. Establish scalable identity controls and governance models to reduce enterprise risk and support Zero Trust principles.

Phoenix, Arizona, United StateshybridFULL_TIME

Posted

About the role

What will you do at American Express?

Joining Amex Tech means discovering and shaping your contribution to something

big. Here, you can work alongside talented tech teams and build a unique career

with the Powerful Backing of American Express. With a range of opportunities to

work with the latest technologies, and a commitment to back the broader

engineering community through open source, our mission is to power your success.

Because Amex Tech is powered by our technology, our culture, and our colleagues.

The Technology organization enables and accelerates the company’s growth

strategies, delivering global capabilities and services in support of Amex’s

customers and colleagues, while maintaining 24/7 servicing and availability to

ensure an uninterrupted, high-quality customer experience. Technology provides

the foundation for everything we do in the company while driving differentiation

through building and leveraging innovative technology and data insights.

At American Express, our mission is to deliver the world’s best customer

experience every day. At the heart of this mission is our Information Security

organization, enabling exceptional experiences built on a foundation of trust,

service, and security. We leverage advanced technologies and data-driven

insights to stay ahead of an evolving threat landscape. We foster a culture of

passion, curiosity, and courage—empowering you to innovate, grow, and help shape

the future of a Fortune 100 company.

Trust. Service. Security.

A Senior Cyber Security Engineer for Agentic AI IAM, and Secrets Management is

responsible for securing enterprise identities, AI agents, machine identities,

and secrets across hybrid environments including on-premises infrastructure and

public cloud platforms.

This role leads the design, implementation, governance, and operational

management of identity security capabilities that support Zero Trust principles,

secure automation, and enterprise-wide access governance.

The role is accountable for translating enterprise security objectives into

measurable security outcomes, operational KPIs, delivery milestones, and

progressive risk reduction strategies. This includes defining security maturity

targets, driving execution roadmaps, establishing measurable controls

effectiveness, and continuously improving identity and secrets management

posture across the organization.

The individual partners closely with infrastructure, cloud, DevOps, application,

and risk teams to establish scalable identity controls, secure secrets

management practices, resilient authentication and authorization architectures,

and sustainable governance models that balance security, operational efficiency,

and business enablement.

Vision

* Build a modern, scalable, and resilient Agentic AI IAM and secrets management

ecosystem across hybrid cloud environments.

* Enable secure adoption of AI agents, automation platforms, and machine

identities through policy-driven governance.

* Drive Enterprise-Wide Risk Reduction Initiatives for Application Secrets

Management

* Elimination of Hardcoded Secrets

* Centralized Enterprise Secrets Vault Adoption

* Automated Secrets Rotation

* Machine Identity and Workload Identity Modernization

* CI/CD and DevSecOps Secrets Security

* Cloud-Native Secrets Governance

* Enterprise Secrets Discovery and Inventory

* Secrets Access Monitoring and Behavioral Analytics

* Zero Trust Application Authentication

* Third-Party and Vendor Secrets Governance

* AI Agent and Autonomous Workflow Secrets Security

* Deliver centralized visibility, compliance, and operational excellence for

identities and access management including sustained controls and metrics

delivery

Functional Requirements/ Core Technical Capabilities

* Strong experience in Agentic AI IAM architecture, identity governance,

secrets management, security engineering, and enterprise IAM program

delivery.

* Strong expertise in requirement gathering, current-state assessments, gap

analyses, control evaluations, and target-state Agentic AI IAM security

architecture design.

* Experience securing cloud-native and hybrid environments.

* Knowledge of Zero Trust architecture and machine identity security.

* Experience implementing AI/Agentic security controls and secure automation

frameworks.

Platform Experience

* Microsoft Entra ID / Okta

* HashiCorp Vault, AWS Secrets Manager, Google cloud secrets manager

* AWS, Azure, Google Cloud Platform

* Kubernetes and container security platforms

* Terraform, CI/CD, DevSecOps tooling

Which skills does this role require?

Agentic AI IAMSecrets ManagementCloud SecurityZero Trust ArchitectureIdentity GovernanceMachine Identity SecuritySecurity EngineeringHybrid Cloud SecurityDevSecOpsCI/CD SecurityRequirement GatheringGap AnalysisAgentic AIIAMZero TrustMicrosoft Entra IDOktaHashiCorp VaultAWS Secrets ManagerGoogle Cloud Secrets ManagerAWSAzureGCPKubernetesTerraformCISSPCISMCCSPMachine IdentityCloud-Native SecurityHybrid CloudProduct Strategy

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.