Back to jobs
American Express10K+ employees

Software Engineer II

INSalary not listedPosted yesterday

Immigration summary

Visa sponsorship

Highly likelyHigh confidence

This employer sponsors this kind of work repeatedly, and is still filing this year.

658 recent H-1B filings · 115 similar-role filings

View visa evidence

Green card sponsorship

Strong historyHigh confidence

This employer has recently sponsored green cards at scale.

101 recent certified PERM filings · 4 similar-role filings

View green card evidence

Job description

The Enterprise Technology Services organization partners with every part of the American Express business to power the company’s growth and innovation with trust and efficiency, and drive competitive differentiation with speed. We support the delivery and operations of technology, digital, and data capabilities, platforms, and services globally. Specifically, our team is responsible for the company’s technology engineering, architecture, and infrastructure, providing 24x7 support to ensure an uninterrupted, high-quality experience for customers and colleagues. We also provide product management for core enterprise platforms, and lead technology risk and information security, enterprise data governance and platforms, digital product and design, and enterprise AI platforms on behalf of the company.

Responsibilities

We are seeking an experienced Engineer (Cybersecurity Analytics & Automation) who combines strong software engineering skills with a hands-on analytical mindset. This role will focus on identifying and investigating automated and malicious activity targeting internet-facing applications and APIs, including bot attacks, account takeover attempts, fraud patterns, API abuse, and other anomalous behavior.

The ideal candidate will have a strong understanding of Layer 7 (HTTP/HTTPS) traffic and application security, along with the ability to analyze large-scale security and application datasets using Python, Elasticsearch, REST APIs, and related data-processing technologies.

This is a hands-on engineering and analytics role. The engineer will perform detailed manual investigations to understand emerging attack patterns and then translate repeatable analytical processes into scalable queries, detection logic, and Python-based automation.

The role also requires practical experience with Generative AI tools and AI-assisted engineering, including ChatGPT and GitHub Copilot, to accelerate investigation, data analysis, automation development, and operational efficiency.

Key Responsibilities:

·  Investigate suspicious and malicious activity targeting internet-facing applications, websites, and APIs, with particular focus on automated bot activity and Layer 7 attacks.

·  Perform hands-on analysis to identify malicious bots, credential stuffing, account takeover attempts, scraping, fraud patterns, API abuse, application-layer attacks, and anomalous network/application behavior.

·  Analyze large-scale and diverse datasets, including:

  • Application logs
  • Web Application Firewall (WAF) events
  • Bot management and bot detection signals
  • API and network telemetry
  • Authentication and account activity
  • Fraud and security events
  • Threat intelligence feeds and external data sources

·  Develop and optimize Elasticsearch queries to investigate security events, correlate signals, identify behavioral patterns, and support detection use cases.

·  Use Python and REST APIs to collect, enrich, correlate, process, and analyze security data from multiple systems.

·  Identify repetitive manual investigation and analysis activities and convert them into reusable, scalable automation.

·  Correlate signals across WAF, bot management, application, authentication, fraud, and threat intelligence platforms to distinguish legitimate users and automation from malicious activity.

·  Work with large-scale datasets and distributed data-processing environments to identify trends and attack patterns that may not be visible from individual events.

·  Evaluate and apply Generative AI to security analytics and engineering workflows, including investigation assistance, query generation, data analysis, code development, and automation.

·  Effectively use AI-assisted engineering tools such as GitHub Copilot and ChatGPT to accelerate development while applying appropriate validation and secure engineering practices.

·  Document investigation methodologies, detection logic, automation workflows, and operational procedures.

·  Collaborate with cybersecurity, application engineering, fraud, infrastructure, and data teams to improve detection capabilities and strengthen protection of internet-facing services.

Qualifications

Minimum Qualifications:

·  Bachelor's degree in Computer Science, Cybersecurity, Engineering, Data Science, or a related technical field.

·  5+ years of software engineering, security engineering, security analytics, or related technical experience.

·  Strong programming and automation skills using Python.

·  Strong experience working with REST APIs and structured/semi-structured data.

·  Hands-on experience with Elasticsearch, including querying and analyzing large datasets.

·  Strong understanding of HTTP/HTTPS, REST APIs, Layer 7 protocols, web applications, and internet-facing application architectures.

·  Ability to independently perform detailed investigations, formulate hypotheses, analyze data, and distinguish legitimate activity from suspicious or malicious behavior.

·  Demonstrated ability to convert manual analytical processes into Python-based automation and repeatable engineering solutions.

· Practical experience using Generative AI and AI-assisted development tools, including ChatGPT, GitHub Copilot, or comparable technologies.

·  Familiarity with modern software engineering practices, including Git, CI/CD, testing, code reviews, and secure development practices.

·  Strong analytical, problem-solving, and communication skills.

Preferred Qualifications

:

·  Experience working on Docker, Kubernetes and Kafka.

·  Experience analyzing large-scale application logs, security telemetry, network data, API traffic, or cybersecurity datasets.

·  Working knowledge of cybersecurity concepts related to bots, application security, API security, fraud, account takeover, and automated attacks.

·  Experience with cloud security platforms such as Cloudflare, Akamai WAF/Bot manager, or comparable technologies.

·  Experience with SIEM, security analytics, observability, or threat detection platforms.

At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.

As part of Team Amex, you’ll experience our powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

Sponsorship evidence

Why Openbound reached the conclusions above.

Visa sponsorship evidence

Current posting

Silent on sponsorship

Employer H-1B history

658
recent certified H-1B filings
315
new-hire petitions
115
filings for similar roles
505
so far in FY2026

Filed titles like this role: software engineer · director software engineering · manager software engineering · director - software engineering

More evidence details
  • 115 certified H-1B filings for this same role, 315 new-hire petitions across the employer, and 270 new hires already this year
  • 115 certified H-1B filings for this same role
  • 658 recent certified H-1B filings across the employer
  • Still filing this year — 505 filings in FY2026
  • 127 USCIS H-1B new-employment approvals, counted separately from LCA filings
  • 916 further USCIS approvals for extensions or transfers
  • The posting says nothing about sponsorship either way
  • No filing activity is recorded for this job's location

Green card sponsorship evidence

Employer PERM history

101
recent certified PERM filings
4
filings for similar roles
Certified PERM filings by fiscal year
2023102
202491
2025107
2026105YTD

Filing history reflects past employer behavior; it isn't a promise for this opening.

All open roles at American Express
How Openbound evaluates sponsorship

Visa history uses official U.S. Department of Labor H-1B LCA disclosure data and USCIS H-1B petition history. Green card history uses DOL PERM disclosure data. Each is read for the employer as a whole, for roles like this one, and for this location, weighted toward the most recent fiscal years.

An employer is matched to its filing entities by verified legal name and reviewed aliases; a match is never made on a name resemblance alone. Where no verified entity can be matched, the page says so and draws no conclusion from the absence. 344 filing titles were examined for this employer.

What this posting states outranks history in both directions, and an employer's published policy outranks past filings. Filing history reflects past behavior; it is not a promise of sponsorship for this opening, and none of this is legal advice.