Senior Java/ AI Engineer- Cybersecurity Engineer
Job Description
American Express is hiring a Senior Cybersecurity Engineer within its Data Security organization in Phoenix, AZ (onsite). In this role, you will design, develop, and modernize secure cryptographic services while applying generative AI and AI-based automation to improve developer productivity and support incident-free operations.
What you’ll do
- Design, develop, and modernize secure, scalable, and resilient cryptographic services, accelerating AI-enabled engineering and intelligent automation.
- Apply Generative AI and AI-based automation across engineering and operational workflows to improve developer productivity.
- Automate vulnerability remediation to reduce time-to-fix and reliance on manual work.
- Proactively identify and remediate issues while reducing manual intervention.
- Advance the organization’s journey toward incident-free operations through improved automation and operational workflows.
What you bring
- Bachelor’s degree in Computer Science, Computer Engineering, Software Engineering, or equivalent practical experience.
- 7+ years of professional software development experience.
- 2+ years leading software developers, including technical mentoring and design guidance.
- 5+ years of experience within Financial Services or another highly regulated industry.
- 5+ years building APIs, microservices, or backend applications using Java, Python, Go, JavaScript/TypeScript, or similar languages.
- 5+ years developing or consuming REST and/or SOAP services.
- 2+ years hands-on experience with GCP, AWS, Azure, or private/hybrid cloud platforms.
- 2+ years experience with Kubernetes, Docker, containerization, service mesh, or related cloud-native technologies.
- 2+ years developing solutions involving PKI, symmetric/asymmetric cryptography, encryption, tokenization, digital certificates, or cryptographic key management.
- 2+ years experience with HashiCorp Vault, KMS, HSM, or comparable secrets/key management technologies.
- Hands-on experience integrating LLMs or Generative AI into applications, software engineering workflows, or operational automation.
- Hands-on experience with AI agents, Retrieval-Augmented Generation (RAG), LLM APIs, prompt engineering, agentic workflows, or similar Generative AI patterns.
- Experience applying AI to engineering and operational use cases such as incident detection, root-cause analysis, vulnerability remediation, observability, automated remediation, or recovery.
- Deep understanding of PKI architecture, certificate lifecycle management, cryptographic key lifecycle management, TLS/mTLS, encryption, digital signatures, and secure communication protocols.
- Experience designing highly available enterprise PKI or cryptographic services.
- Experience integrating applications with HSMs, enterprise PKI, HashiCorp Vault, cloud KMS, and certificate management platforms.
- Strong understanding of API security, OAuth/OIDC, authentication, and authorization.
- Experience with DevSecOps, CI/CD, automated security testing, observability, and infrastructure automation.
- Understanding of security, privacy, access control, and responsible AI considerations for enterprise AI solutions.
Tools and technologies
- Java, Python, Go, JavaScript/TypeScript, REST, SOAP
- GCP, AWS, Azure, Kubernetes, Docker, service mesh
- PKI, symmetric/asymmetric cryptography, encryption, tokenization, digital certificates, cryptographic key management
- HashiCorp Vault, KMS, HSM
- LLMs, Generative AI, AI agents, Retrieval-Augmented Generation (RAG), LLM APIs, prompt engineering, agentic workflows
- OAuth/OIDC, TLS/mTLS, DevSecOps, CI/CD, automated security testing, observability, infrastructure automation
Compensation: USD 123,000 - 215,250 per year.