Associate - CyberOps & Assurance
Generate a McCoy IQ challenge in 30 seconds.
See how candidates think and approach the work this role demands, before the phone screen. We'll build a video challenge from this posting, and you can edit or share it before it goes live.
Key details
Job Description
Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.
The External Attack Surface Management team protects American Express by identifying, investigating, and reducing risk across our Internet-facing environment. This role combines technical investigation, threat analysis, infrastructure research, customer engagement, and incident response to better understand how external technologies can be identified, targeted, and exploited.
The ideal candidate is naturally curious, enjoys solving unfamiliar technical problems, and is energized by understanding how complex systems work. They are comfortable researching emerging threats, investigating ambiguous technical issues, and partnering across engineering organizations to drive meaningful risk reduction. Success in this role comes from asking questions, following technical breadcrumbs, and the curiosity to investigate problems that do not have established playbooks.
Threat Investigation & Research
• Investigate externally facing infrastructure, applications, cloud services, DNS, certificates, APIs, and Internet technologies to identify exposure and recommend remediation.
• Research emerging attack vectors, adversary techniques, Internet technologies, and threat trends to improve organizational awareness and defensive capabilities.
• Perform technical investigations using multiple security tools and data sources to validate findings, determine root cause, and distinguish meaningful risk from false positives.
• Analyze network traffic, packet captures (PCAPs), DNS records, routing behavior, TLS configurations, proxy logs, WAF telemetry, and other infrastructure artifacts to support investigations and inventory reconciliation.
External Attack Surface Management
• Monitor the external attack surface for newly identified assets, vulnerabilities, configuration issues, and emerging risks.
• Partner with application teams to explain findings, prioritize remediation activities, and validate successful resolution.
• Conduct rescans, validate mitigation efforts, and continuously improve the accuracy and quality of attack surface intelligence.
• Evaluate new security tools, Internet intelligence sources, and detection capabilities to improve operational effectiveness.
• Investigate externally discovered artifacts to determine appropriate ownership and responsibility
Incident Support
• Support investigations involving Internet-facing technologies during security incidents.
• Rapidly assess technical findings while maintaining composure during high-pressure situations.
• Partner with Security Operations, Engineering, Infrastructure, and Application teams to coordinate investigation and remediation activities.
• Translate complex technical findings into actionable recommendations appropriate for both engineering and business stakeholders.
Program Development
• Identify opportunities to improve scalability, automation, visibility, and operational maturity across the program.
• Participate in proof-of-concepts, tool evaluations, and strategic initiatives supporting the evolution of External Attack Surface Management capabilities.
• Contribute to documentation, operating procedures, technical standards, and knowledge sharing across the organization.
How You Think
- The strongest candidates typically demonstrate many of the following characteristics:
- Naturally curious with a genuine desire to understand how technology works.
- Enjoy solving difficult technical problems that do not have obvious answers.
- Comfortable researching unfamiliar technologies and independently developing expertise.
- Strong analytical mindset capable of recognizing patterns across multiple technical data sources.
- Able to distinguish symptoms from root cause while balancing technical findings with business impact.
- Thrive in ambiguous environments where investigation, experimentation, and continuous learning are encouraged.
- Demonstrate persistence, ownership, and follow-through when solving difficult technical problems.
- Remain calm, organized, and methodical during security incidents or other high-pressure situations.
Technical Experience
- Experience with more than one of the following domains:
- Enterprise networking fundamentals (DNS, HTTP/S, TLS, routing, VPNs, proxies, reverse proxies, CDNs, load balancing, WAFs, firewalls).
- Packet analysis (Wireshark, tcpdump, PCAP interpretation).
- Cloud infrastructure and Internet-facing services.
- Vulnerability Management and External Attack Surface Management
- Security Operations and Threat Intelligence.
- OSINT research techniques
- APIs and data integration concepts.
- Bash, Python, PowerShell, or other scripting knowledge recommended (secondary to investigative ability and technical reasoning).
Collaboration
- Strong written and verbal communication skills.
- Ability to explain complex technical findings to both engineering and non-technical audiences.
- Comfortable building trusted partnerships across multiple technical organizations.
- Customer-focused with the ability to balance security requirements against operational realities.
- Able to receive constructive feedback, adapt quickly, and continuously improve.
- Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.
As part of Team Amex, you’ll experience our powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:
- Competitive base salaries
- Bonus incentives
- 6% Company Match on retirement savings plan
- Free financial coaching and financial well-being support
- Comprehensive medical, dental, vision, life insurance, and disability benefits
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities
For a full list of Team Amex benefits, visit our Colleague Benefits Site.
Audit details(provenance, verification trail, raw fields)
Core fields
amex:26013220Provenance
egug.fa.us2.oraclecloud.com|CX_1Verification trail
This posting hasn't been probed by our closure verifier yet. Stream C runs on a rolling schedule against postings approaching the close-decision threshold.
LLM enrichment
See how we measure for definitions, or our corrections log for known issues. Found something wrong? Flag a correction.
