About the role
What will you do at American Express?
Joining Amex Tech means discovering and shaping your contribution to something
big. Here, you can work alongside talented tech teams and build a unique career
with the Powerful Backing of American Express. With a range of opportunities to
work with the latest technologies, and a commitment to back the broader
engineering community through open source, our mission is to power your success.
Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Technology organization enables and accelerates the company’s growth
strategies, delivering global capabilities and services in support of Amex’s
customers and colleagues, while maintaining 24/7 servicing and availability to
ensure an uninterrupted, high-quality customer experience. Technology provides
the foundation for everything we do in the company while driving differentiation
through building and leveraging innovative technology and data insights.
At American Express, our mission is to deliver the world’s best customer
experience every day. At the heart of this mission is our Information Security
organization, enabling exceptional experiences built on a foundation of trust,
service, and security. We leverage advanced technologies and data-driven
insights to stay ahead of an evolving threat landscape. We foster a culture of
passion, curiosity, and courage—empowering you to innovate, grow, and help shape
the future of a Fortune 100 company.
Trust. Service. Security.
A Senior Cyber Security Engineer for Agentic AI IAM, and Secrets Management is
responsible for securing enterprise identities, AI agents, machine identities,
and secrets across hybrid environments including on-premises infrastructure and
public cloud platforms.
This role leads the design, implementation, governance, and operational
management of identity security capabilities that support Zero Trust principles,
secure automation, and enterprise-wide access governance.
The role is accountable for translating enterprise security objectives into
measurable security outcomes, operational KPIs, delivery milestones, and
progressive risk reduction strategies. This includes defining security maturity
targets, driving execution roadmaps, establishing measurable controls
effectiveness, and continuously improving identity and secrets management
posture across the organization.
The individual partners closely with infrastructure, cloud, DevOps, application,
and risk teams to establish scalable identity controls, secure secrets
management practices, resilient authentication and authorization architectures,
and sustainable governance models that balance security, operational efficiency,
and business enablement.
Vision
* Build a modern, scalable, and resilient Agentic AI IAM and secrets management
ecosystem across hybrid cloud environments.
* Enable secure adoption of AI agents, automation platforms, and machine
identities through policy-driven governance.
* Drive Enterprise-Wide Risk Reduction Initiatives for Application Secrets
Management
* Elimination of Hardcoded Secrets
* Centralized Enterprise Secrets Vault Adoption
* Automated Secrets Rotation
* Machine Identity and Workload Identity Modernization
* CI/CD and DevSecOps Secrets Security
* Cloud-Native Secrets Governance
* Enterprise Secrets Discovery and Inventory
* Secrets Access Monitoring and Behavioral Analytics
* Zero Trust Application Authentication
* Third-Party and Vendor Secrets Governance
* AI Agent and Autonomous Workflow Secrets Security
* Deliver centralized visibility, compliance, and operational excellence for
identities and access management including sustained controls and metrics
delivery
Functional Requirements/ Core Technical Capabilities
* Strong experience in Agentic AI IAM architecture, identity governance,
secrets management, security engineering, and enterprise IAM program
delivery.
* Strong expertise in requirement gathering, current-state assessments, gap
analyses, control evaluations, and target-state Agentic AI IAM security
architecture design.
* Experience securing cloud-native and hybrid environments.
* Knowledge of Zero Trust architecture and machine identity security.
* Experience implementing AI/Agentic security controls and secure automation
frameworks.
Platform Experience
* Microsoft Entra ID / Okta
* HashiCorp Vault, AWS Secrets Manager, Google cloud secrets manager
* AWS, Azure, Google Cloud Platform
* Kubernetes and container security platforms
* Terraform, CI/CD, DevSecOps tooling
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Cloud Security Engineer
Morgan & Morgan, P.A. · Tampa, Florida, United States
IT Senior Security Engineer
August Schell · Bethesda, Maryland, United States
Lead Engineer, Information Security (Application Security)
RXO, Inc. · United States
Senior Security Engineer
Credit Sesame · Mountain View, California, United States
Security Engineer
Brightspot · Reston, Virginia, United States
Workday Senior Security Engineer
UW Medicine · Seattle, Washington, United States
Role information can change. Confirm current details on the original application page.
