American Express logo
Hiring from
India
Work type
Hybrid
Posted
Sep 25, 2026
Is this job info correct?

The Enterprise Technology Services organization partners with every part of the American Express business to power the company’s growth and innovation with trust and efficiency, and drive competitive differentiation with speed. We support the delivery and operations of technology, digital, and data capabilities, platforms, and services globally. Specifically, our team is responsible for the company’s technology engineering, architecture, and infrastructure, providing 24x7 support to ensure an uninterrupted, high-quality experience for customers and colleagues. We also provide product management for core enterprise platforms, and lead technology risk and information security, enterprise data governance and platforms, digital product and design, and enterprise AI platforms on behalf of the company.

We are seeking an experienced Engineer (Cybersecurity Analytics & Automation) who combines strong software engineering skills with a hands-on analytical mindset. This role will focus on identifying and investigating automated and malicious activity targeting internet-facing applications and APIs, including bot attacks, account takeover attempts, fraud patterns, API abuse, and other anomalous behavior.

The ideal candidate will have a strong understanding of Layer 7 (HTTP/HTTPS) traffic and application security, along with the ability to analyze large-scale security and application datasets using Python, Elasticsearch, REST APIs, and related data-processing technologies.

This is a hands-on engineering and analytics role. The engineer will perform detailed manual investigations to understand emerging attack patterns and then translate repeatable analytical processes into scalable queries, detection logic, and Python-based automation.

The role also requires practical experience with Generative AI tools and AI-assisted engineering, including ChatGPT and GitHub Copilot, to accelerate investigation, data analysis, automation development, and operational efficiency.

Key Responsibilities:

· Investigate suspicious and malicious activity targeting internet-facing applications, websites, and APIs, with particular focus on automated bot activity and Layer 7 attacks.

· Perform hands-on analysis to identify malicious bots, credential stuffing, account takeover attempts, scraping, fraud patterns, API abuse, application-layer attacks, and anomalous network/application behavior.

· Analyze large-scale and diverse datasets, including:

  • Application logs
  • Web Application Firewall (WAF) events
  • Bot management and bot detection signals
  • API and network telemetry
  • Authentication and account activity
  • Fraud and security events
  • Threat intelligence feeds and external data sources

· Develop and optimize Elasticsearch queries to investigate security events, correlate signals, identify behavioral patterns, and support detection use cases.

· Use Python and REST APIs to collect, enrich, correlate, process, and analyze security data from multiple systems.

· Identify repetitive manual investigation and analysis activities and convert them into reusable, scalable automation.

· Correlate signals across WAF, bot management, application, authentication, fraud, and threat intelligence platforms to distinguish legitimate users and automation from malicious activity.

· Work with large-scale datasets and distributed data-processing environments to identify trends and attack patterns that may not be visible from individual events.

· Evaluate and apply Generative AI to security analytics and engineering workflows, including investigation assistance, query generation, data analysis, code development, and automation.

· Effectively use AI-assisted engineering tools such as GitHub Copilot and ChatGPT to accelerate development while applying appropriate validation and secure engineering practices.

· Document investigation methodologies, detection logic, automation workflows, and operational procedures.

· Collaborate with cybersecurity, application engineering, fraud, infrastructure, and data teams to improve detection capabilities and strengthen protection of internet-facing services.

Minimum Qualifications:

· Bachelor's degree in Computer Science, Cybersecurity, Engineering, Data Science, or a related technical field.

· 5+ years of software engineering, security engineering, security analytics, or related technical experience.

· Strong programming and automation skills using Python.

· Strong experience working with REST APIs and structured/semi-structured data.

· Hands-on experience with Elasticsearch, including querying and analyzing large datasets.

· Strong understanding of HTTP/HTTPS, REST APIs, Layer 7 protocols, web applications, and internet-facing application architectures.

· Ability to independently perform detailed investigations, formulate hypotheses, analyze data, and distinguish legitimate activity from suspicious or malicious behavior.

· Demonstrated ability to convert manual analytical processes into Python-based automation and repeatable engineering solutions.

· Practical experience using Generative AI and AI-assisted development tools, including ChatGPT, GitHub Copilot, or comparable technologies.

· Familiarity with modern software engineering practices, including Git, CI/CD, testing, code reviews, and secure development practices.

· Strong analytical, problem-solving, and communication skills.

Preferred Qualifications:

· Experience working on Docker, Kubernetes and Kafka.

· Experience analyzing large-scale application logs, security telemetry, network data, API traffic, or cybersecurity datasets.

· Working knowledge of cybersecurity concepts related to bots, application security, API security, fraud, account takeover, and automated attacks.

· Experience with cloud security platforms such as Cloudflare, Akamai WAF/Bot manager, or comparable technologies.

· Experience with SIEM, security analytics, observability, or threat detection platforms.

Similar jobs

Apply for this job