Business Unit / Role Specific Info
The Enterprise Technology Services organization partners with every part of the American Express business to power the company’s growth and innovation with trust and efficiency, and drive competitive differentiation with speed. We support the delivery and operations of technology, digital, and data capabilities, platforms, and services globally. Specifically, our team is responsible for the company’s technology engineering, architecture, and infrastructure, providing 24x7 support to ensure an uninterrupted, high-quality experience for customers and colleagues. We also provide product management for core enterprise platforms, and lead technology risk and information security, enterprise data governance and platforms, digital product and design, and enterprise AI platforms on behalf of the company.
At American Express, we empower technologists to learn, innovate, and make an impact from day one. As a Cybersecurity Analyst in Enterprise Technology Services, you’ll join a full-time graduate program and contribute to work that helps protect American Express information systems, customer data, colleague experiences, and digital assets.
Cybersecurity teams help identify, reduce, monitor, and respond to technology and information security risks. In this role, you may support cybersecurity operations, security architecture, identity and access management, endpoint protection, application security, security monitoring, cloud security, documentation, and AI-enabled cybersecurity workflows while collaborating with cybersecurity teams, product partners, software development teams, operations teams, and business stakeholders.
Key Responsibilities
- Supports in monitoring security systems and events using a variety of tools, alerts, and logs to identify potential threats and vulnerabilities, ensuring timely detection and prevention of security or operational issues
- Triages and investigates security or operational issues to determine root causes, impacts, and potential mitigation strategies, helping to prevent future incidents and minimize damage
- Support secure network, endpoint, identity, access management, application security, and cloud security activities under guidance from experienced engineers.
- Assist with security documentation, assessment findings, remediation tracking, reporting, and control implementation activities that support compliance and security posture improvements.
- Collaborate with software development and product teams to help integrate security into the software development lifecycle and support secure coding practices.
- Research emerging cyber threats, security technologies, AI-enabled security risks, and control approaches to support team knowledge and decision-making.
- Use AI-enabled cybersecurity tools to support threat detection, alert triage, analysis, documentation, and investigation activities while validating outputs before escalation or implementation.
- Support security control implementation and monitoring approaches for cloud-based, AI-enabled, or enterprise technology services.
- Apply structured prompt design techniques when using AI agent-enabled security tools, including clear context, objectives, constraints, and security requirements.
- Collaborate across cybersecurity, engineering, product, risk, operations, and business teams to strengthen secure technology delivery and enterprise risk reduction.
Minimum Qualifications
- Must have earned a Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Computer Engineering, Engineering, or another technical field before the full-time start date.
- Foundational understanding of cybersecurity, information security, application security, network security, cloud security, or technology risk concepts.
- Foundational knowledge of network protocols, security fundamentals, identity and access management, data privacy, data protection, or secure software development concepts.
- Interest in scripting or automation using languages such as Python, Bash, PowerShell, or similar technologies.
- Strong communication, collaboration, analytical thinking, discretion, attention to detail, and learning agility with the ability to work effectively in a team environment.
Preferred Qualifications
- Students must have a graduation date between December 2026 and June 2027.
- Coursework, projects, internships, labs, competitions, research, or extracurricular experience in cybersecurity, information security, artificial intelligence, machine learning, software development, cloud, data, networking, or technology risk.
- Awareness of security standards, regulatory compliance, data privacy, data protection, security governance, and risk management concepts.
- Familiarity with security monitoring, threat detection, vulnerability management, incident response, endpoint protection, network security, or identity and access management concepts.
- Exposure to security tools, platforms, or operational processes used to investigate alerts, analyze threats, document findings, or support remediation activities.
- Interest in application security, secure coding, DevSecOps, cloud security, IAM, data security, network security, or AI security.
- Awareness of AI-enabled cybersecurity capabilities and emerging risks such as prompt injection, model misuse, data exposure, AI-assisted security operations, and automation-enabled analysis.
- Interest in cybersecurity certifications or continued learning; certifications are not required for early-career consideration.
- Strong problem solving, curiosity, ownership, professionalism, ethical judgment, and comfort learning new technologies in a fast-paced environment.
Our team reviews applications on a rolling basis. We appreciate your patience while we consider your application and will contact qualified candidates regarding next steps.
Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.

