- Build, lead, and mentor high-performing cybersecurity teams
- Lead the enterprise Security Remediation Operations program across application, infrastructure, cloud, and platform security domains
- Partner with technology, application development, product, and cybersecurity teams to prioritize remediation based on risk, exploitability, and enterprise impact
- Improve the end-to-end vulnerability management lifecycle, workflows, developer adoption, and remediation outcomes
- Develop enterprise remediation strategies, governance models, operational controls, and performance metrics
- Coordinate with vulnerability management, penetration testing, application security, infrastructure security, and security engineering teams
- Lead automation, workflow optimization, and operational efficiency initiatives
- Develop executive reporting, dashboards, and risk metrics for senior leadership
- Oversee complex security and operational events, remediation activities, root cause analysis, and continuous improvement
- Establish security policies, standards, and procedures aligned with governance, regulations, and industry best practices
- Support regulatory examinations, audits, compliance activities, remediation evidence, metrics, and control validation
- Improve developer education, vulnerability awareness, and secure development practices
- Drive adoption and governance of AI-enabled cybersecurity operations, including secure Prompt Design practices
Requirements
- 10+ years of progressive cybersecurity experience, including senior leadership of enterprise security operations, vulnerability management, or remediation programs
- Experience leading cross-functional cybersecurity organizations in large, complex enterprise environments
- Strong understanding of vulnerability management, application security, infrastructure security, cloud security, and enterprise risk management
- Experience developing enterprise remediation strategies, operational governance, and metrics-driven security programs
- Ability to influence engineering organizations, application owners, and executive stakeholders
- Understanding of security frameworks, governance models, and global regulatory requirements
- Knowledge of network security, application security, threat modeling, IAM, cloud security, data security, security architecture, and security governance
- Experience with SIEM platforms such as Splunk, ArcSight, QRadar, or Elastic
- Experience with EDR platforms including CrowdStrike, Carbon Black, SentinelOne, or Microsoft Defender
- Experience with endpoint protection technologies such as Symantec Endpoint Protection, McAfee Endpoint Security, or CrowdStrike Falcon
- Working knowledge of TCP/IP, DNS, HTTP, and enterprise networking fundamentals
- Experience using Python, Bash, or PowerShell for workflow automation
- Understanding of cybersecurity technologies, threat intelligence, incident response, vulnerability management, and operational risk management
- Experience leading cybersecurity transformation initiatives involving AI-enabled monitoring, detection, automation, or threat management
- Knowledge of AI-enabled security architectures, automated threat detection and response, AI governance, adversarial AI risks, and enterprise AI security
- Bachelor's Degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent professional experience
- Employment eligibility to work with American Express in the United States required; visa sponsorship unavailable
Core Competencies
Demonstrates extensive experience in leading cybersecurity operations, developing enterprise remediation strategies, and managing vulnerability management programs. Proficient in leveraging automation and metrics-driven approaches to enhance security governance and operational efficiency.
Highest-signal resume keywords
- 10+ Years Cybersecurity Experience
- Enterprise Security Operations Leadership
- Vulnerability Management Expertise
- Experience with SIEM Platforms
- Knowledge of Security Frameworks
ATS Optimization Keywords
Hard Skills
- Vulnerability Management
- Application Security
- Infrastructure Security
- Cloud Security
- Security Architecture
- Python Programming
- Bash Scripting
- PowerShell Scripting
- Network Security
- Threat Modeling
Soft Skills
- Leadership
- Mentoring
- Influencing Stakeholders
- Collaboration
- Communication
Industry Keywords
- Cybersecurity Governance
- Regulatory Compliance
- Operational Risk Management
- AI-Enabled Security
- Security Policies and Standards
Tools & Technologies
- Splunk
- ArcSight
- QRadar
- Elastic
- CrowdStrike
- Carbon Black
- SentinelOne
- Microsoft Defender
- Symantec Endpoint Protection
- McAfee Endpoint Security