CyberSecurity Engineer 1

American Express Global Business Travel
$84,700 - $157,300Onsite

About The Position

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. The Cybersecurity Analyst, Threat Intelligence & Red Team is a hybrid role supporting our Counter Adversary Operations function. This position splits its time between working as a Threat Intelligence Analyst ingesting, enriching, and actioning threat intel from multiple sources and fulfilling intel requests from partner teams and supporting our Red Team as a contributor to hands-on offensive security testing. This role is well suited to an analyst early in their offensive security career who wants to build technical red team skills while developing strong threat intelligence fundamentals. The candidate will work closely with senior red teamers, threat hunters, detection engineers, and IR to help mature our security posture across a global, highly distributed travel and hospitality technology enterprise.

Requirements

  • 1–3 years in cybersecurity with exposure to threat intel and/or offensive security
  • Foundational knowledge of MITRE ATT&CK
  • Familiarity with IOCs, TTPs, Diamond Model, kill chain analysis
  • Basic scripting (Python, PowerShell, or Bash)
  • Ability to learn and support SOAR/CAO workflows
  • Strong written communication for reports and documentation
  • Interest in offensive security and willingness to learn
  • Understanding of APIs and workflow integration

Nice To Haves

  • Experience with a TIP (e.g., Cyber6Gill/Bitsight, ISACs, CrowdStrike CAO Elite)
  • Exposure to AD attacks (BloodHound, Kerberoasting) or cloud security (AWS/Azure)
  • CTF, home lab, or self-directed offensive security practice
  • Certifications/coursework (Security+, GCTI, eJPT, OSCP progress)
  • Experience with Atomic Red Team or similar frameworks

Responsibilities

  • Monitor, triage, and ingest threat intel from OSINT, ISACs, and vendor feeds into the TIP
  • Enrich IOCs/TTPs and correlate with internal telemetry
  • Respond to RFIs from IR, DSI, and leadership
  • Produce threat briefs, IOC packages, and actor profiles for travel/hospitality
  • Map threat actor TTPs to MITRE ATT&CK
  • Translate intel into hunt leads and detection opportunities
  • Assist with scoped engagements (recon, scanning, exploitation, lateral movement) under supervision
  • Perform atomic/scenario testing aligned to ATT&CK
  • Support Purple Team exercises and validate closed detection gaps
  • Build familiarity with offensive tools (Kali, Burp Suite, BloodHound, C2) via mentorship
  • Contribute to documentation, evidence capture, and reporting
  • Partner with Detection Engineering, Threat Hunting, IR, and Red Team to close gaps
  • Communicate findings clearly to technical and non-technical audiences

Benefits

  • health and welfare insurance plans
  • retirement programs
  • parental leave
  • adoption assistance
  • wellbeing resources
  • travel perks
  • access to over 20,000 courses on our learning platform
  • leadership courses
  • new job openings available to internal candidates first
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service