Agentic AI Cybersecurity Engineer - Identity Access Lifecycle Managementgmt
American Express Phoenix, Arizona, United States · $104K–$175K/yr
Financial Services · 10,001+ employees
About the role
The role involves designing and maintaining AI-enabled agents and automation workflows to evaluate cybersecurity controls and identify gaps. You will partner with cross-functional teams to source data, build automated metrics, and ensure continuous control monitoring.
What they look for
Requirements
Candidates must have at least 2 years of experience in cybersecurity, technology risk, or automation engineering. A bachelor's degree in a relevant field is required, along with proficiency in Python, SQL, and AI security concepts.
Benefits
Full description
Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.
At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.
Trust. Service. Security.
We are seeking an experienced and results-oriented Cybersecurity Engineer to join the Identity Access and Lifecycle Management team. This role will help ensure first-line defense cybersecurity operational goals are met by partnering with cross-functional teams, engineering automation, and building AI-enabled agents that can support self-auditing of controls. The ideal candidate will bring a strong foundation in control management, data-driven control testing, automation engineering, stakeholder engagement, and AI-enabled solution design and delivery—sitting at the intersection of risk, controls, software engineering, and process automation in a fast-paced, matrixed environment.
Responsibilities
Engineering, Agent Development & Automated Metrics
- Design, build, and enhance automated metrics that strengthen control effectiveness and enable continuous control monitoring.
- Develop, configure, test, and maintain AI-enabled agents and automation workflows that can evaluate control evidence, identify exceptions, surface control gaps, recommend remediation actions, and support scalable self-auditing capabilities.
- Partner with data, engineering, and technology teams to source, validate, and transform data used in automated control testing and agent-driven analysis.
- Define and track KPIs/KRIs such as control performance trends, exception volumes, agent findings, remediation timeliness, and self-audit coverage.
Data Engineering, Insights & Reporting
- Analyze control testing outputs, cybersecurity telemetry, and agent-generated findings to identify trends, anomalies, emerging risks, and opportunities for control improvement.
- Engineer dashboards, reports, and data products that provide clear visibility into control health, self-audit results, exception patterns, and operational risk posture.
- Translate technical findings into concise, risk-informed insights and recommendations for control owners, engineering partners, and leadership stakeholders.
Continuous Improvement, Control Automation & Agentic AI
- Identify opportunities to enhance documentation quality, data integrity, and control standardization in accordance with the RCSA framework.
- Support the enhancement of metrics frameworks, automated testing logic, and reporting capabilities to increase repeatability and reduce manual effort.
- Partner with engineering and tooling teams to scale automated testing, monitoring, and agent-enabled self-audit solutions across controls.
- Contribute to automation and efficiency initiatives related to control documentation review, monitoring, metric design, evidence validation, and exception identification.
- Apply AI-enabled security tooling and automation capabilities to improve control observability, evidence review, investigation efficiency, and operational risk visibility.
- Create and implement secure, governed AI agents and workflows that align with enterprise security standards, risk requirements, control objectives, data protection expectations, and responsible AI practices.
- Design and refine prompts, rules, workflows, orchestration logic, validation criteria, and feedback loops that improve AI agent-enabled cybersecurity engineering activities, including control implementation, self-audit execution, exception triage, remediation tracking, control evidence analysis, and security research.
- Apply AI-enabled security tooling and automation capabilities to improve threat detection, investigation efficiency, and operational observability across cybersecurity environments.
- Support the implementation of security controls and monitoring practices for AI-enabled applications and workflows, ensuring alignment with enterprise security standards and risk requirements.
Qualifications
- 2+ years of experience in cybersecurity, control management, technology risk, audit response, automation engineering, or related disciplines.
- Experience designing or supporting automated control testing, continuous control monitoring, automated evidence review, or self-audit capabilities.
- Knowledge of AI security concepts, including risks associated with generative AI, model integrity, prompt security, data protection, and responsible use of AI-enabled workflows.
- Experience creating or configuring AI agents, automation frameworks, or agentic AI workflows used to enhance monitoring, detection, control validation, evidence analysis, and security engineering outcomes.
- Ability to design agent workflows that translate control objectives into executable tasks, including evidence collection, test execution, exception identification, result summarization, and escalation routing.
- Experience designing, building, testing, and governing AI agents or agentic workflows that connect to enterprise data sources, execute control validation tasks, evaluate evidence, identify exceptions, summarize results, and support human-reviewed self-auditing of cybersecurity controls.
- Strong engineering mindset with the ability to translate control requirements into automated logic, repeatable tests, data pipelines, dashboards, and agent-enabled workflows.
- Understanding of RCSA control processes, operational risk management concepts, control design, evidence expectations, and audit readiness requirements.
- Demonstrated ability to recognize opportunities and deliver automation of data metrics, control testing, and self-audit processes to support control effectiveness.
- Understanding of how AI/ML, NLP, and generative AI can be used to analyze control performance data, detect anomalies, summarize evidence, and identify potential control gaps.
- Experience using AI tools to assist in metric design, documentation review, evidence validation, exception analysis, workflow automation, and efficiency improvements.
- Ability to interpret AI-generated outputs, validate accuracy, identify limitations, and apply findings within a risk, control, and governance context.
- Experience leveraging Python, SQL, APIs, workflow automation, and analytics tools and Excel, PowerPoint to build scalable control monitoring and reporting solutions.
- Strong proficiency with Amex collaboration platforms such as Confluence, SharePoint, Slack, or Teams.
- Knowledge of AI security concepts, including risks associated with generative AI, model integrity, prompt security, and protection of sensitive enterprise data.
- Knowledge of AI-assisted cybersecurity operations and automation frameworks used to enhance detection, response, and security engineering workflows.
- Bachelor’s degree required in Computer Science, Information Systems, Cybersecurity, Engineering, Data Analytics, or comparable experience.
- Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.
Similar roles
-
Senior Lead Security Engineer - Google Cloud.
JPMorgan Chase & Co. Dublin, Leinster, Ireland
-
Consultant - Cybersecurity Policies and Strategies Department
Malomatia Doha, Qatar
-
Senior Information System Security Engineer
Leidos United States · $108K–$195K/yr
-
Senior Information Security Engineer
Synovus Columbus, Georgia, United States
-
Senior AI Security Engineer
Firmus Technologies Sydney, New South Wales, Australia
-
OT Cybersecurity Engineer
Advanced Petrochemical Company Al Jubayl, Eastern Province, Saudi Arabia