Skip to content

Open nowPosted yesterday

Data Security Digital Product Manager - Gen AI/ Agile

American Express84 open roles

Where
Phoenix, AZ, United States
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowData Security Digital Product Manager - Gen AI/ AgileAmerican Express · Phoenix, AZ, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on American Express's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. American Express postings stay open a median of 3 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 34.0%30 days
This job: posted yesterday

American Express median: 3 days open

The posting

Job Description

Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues. The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.

At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.

Trust. Service. Security.

The Data Security team is responsible for safeguarding the organization’s most critical asset—its data—by ensuring confidentiality, integrity, and availability across all platforms and environments. Working at the intersection of cybersecurity, data governance, and privacy, the Data Security team focuses on capabilities such as data classification, encryption, secure data access, and monitoring. The team partners closely with engineering, risk, and business units to embed security controls throughout the data lifecycle—from creation and storage to sharing and archival.

As a Product Owner, you will lead the development of platforms and capabilities that enable internal teams to securely leverage enterprise data encryption services. This role focuses on building and enhancing a services portal for encryption solutions, as well as products that integrate with Hardware Security Modules (HSMs). You will play a critical role in shaping the direction of encryption products—driving innovation, accelerating AI adoption, improving automation, and enhancing the efficiency and scalability of security services across the organization. You will champion the responsible use of AI across the product lifecycle, identifying opportunities to improve customer experiences, streamline engineering workflows, and enable secure AI-powered capabilities within enterprise security platforms. You should have strong product mindset with the ability to translate complex technical capabilities into scalable, user-focused solutions.

How will you make an impact in this role?

The Product Owner is accountable for translating product direction into precise, executable work while ensuring strong alignment with engineering delivery and measurable outcomes. This role emphasizes disciplined backlog management, clear prioritization, and consistent execution patterns to improve delivery predictability, reduce fragmentation, and enhance overall product quality. You will act as the voice of the customer and the steward of execution excellence—ensuring that encryption services are delivered securely, reliably, and with a high degree of operational rigor.

This role also plays a key part in enabling the evolution of the platform to support AI-driven use cases—ensuring that encryption services are accessible, intuitive, and scalable for both human users and intelligent systems. The Product Owner will incorporate AI capabilities into product development in a disciplined, execution-focused manner, aligning innovation with secure, reliable delivery.

Responsibilities

Core Responsibilities

Cryptographic Product Strategy

  • Define the product direction for HSM services, key-management capabilities, encryption services, and supporting developer tools.
  • Identify customer and application needs related to cryptographic operations, key custody, secure integration, automation, and service accessibility.
  • Develop roadmaps that address platform modernization, HSM lifecycle management, capacity, resilience, crypto-agility, and regulatory requirements.
  • Establish standardized cryptographic services and integration patterns that can be reused across application teams.
  • Evaluate new HSM, key-management, cloud cryptography, automation, and related technologies for practical enterprise adoption.

Key Management and HSM Delivery

  • Define product requirements for key generation, import, export, distribution, rotation, backup, recovery, revocation, archival, and destruction.
  • Guide capabilities involving HSM partitions, security domains, access controls, quorum processes, administrative roles, audit logging, and operational monitoring.
  • Ensure requirements account for secure key custody, separation of duties, least privilege, traceability, and recoverability.
  • Partner with infrastructure and engineering teams on HSM deployment, configuration, migration, expansion, upgrade, and decommissioning initiatives.
  • Prioritize lifecycle and operational work alongside new product capabilities.

Developer Experience and Programming

  • Define APIs, SDK requirements, code samples, onboarding documentation, test utilities, and integration guidance for cryptographic-service consumers.
  • Collaborate with engineers to validate that user stories accurately describe expected cryptographic behavior, error handling, access controls, and nonfunctional requirements.
  • Apply working programming knowledge to review implementation examples, analyze defects, support proof-of-concept activities, and clarify integration requirements.
  • Promote automated testing for cryptographic workflows, including positive tests, negative tests, failure handling, performance testing, and recovery scenarios.
  • Improve the developer experience for teams integrating applications with HSMs and key-management services.
  • Support secure software-development practices for applications that generate, store, retrieve, or use cryptographic keys.
  • Evaluate appropriate uses of AI-assisted tools for documentation, requirements analysis, test design, and engineering productivity.
  • Ensure AI-generated content or code receives appropriate technical and security review.

Execution and Stakeholder Leadership

  • Own and prioritize a technically detailed backlog with measurable business, security, engineering, and operational outcomes.
  • Lead refinement sessions that include sufficient technical depth to identify dependencies, assumptions, security implications, and acceptance criteria.
  • Coordinate across cryptographic engineering, application development, architecture, infrastructure, risk, compliance, and operations.
  • Clearly communicate technical risks, lifecycle concerns, design trade-offs, and investment needs.
  • Measure platform adoption, integration lead time, automation coverage, service reliability, incident trends, and customer satisfaction.
  • Use AI-enabled tools where appropriate to improve product-management and software-delivery processes.

Qualifications

Minimum Qualifications

  • 7+ years of combined experience in cybersecurity, software engineering, cryptographic services, infrastructure engineering, technical product management, or related disciplines.
  • At least 3 years of direct experience with HSMs, key-management systems, cryptographic services, or payment-security technology.
  • Practical understanding of cryptographic keys and their use in encryption, digital signatures, authentication, payment processing, or data protection.
  • Experience with key-management policies, operational controls, and lifecycle processes.
  • Proficiency or meaningful working experience with at least one modern programming or scripting language.
  • Experience reading code, interpreting API documentation, understanding data formats, and evaluating software integration designs.
  • Experience defining functional and nonfunctional requirements for security platforms or technically complex services.
  • Experience using generative AI or similar productivity tools within product management, engineering, documentation, analysis, or software-delivery workflows.
  • General understanding of the opportunities, limitations, security considerations, and governance requirements associated with enterprise AI.
  • Ability to collaborate effectively with software developers, security engineers, infrastructure engineers, architects, and control functions.
  • Experience delivering capabilities through Agile engineering teams.
  • Strong analytical, prioritization, documentation, and stakeholder-management skills.
  • Bachelor’s degree in a technical discipline or equivalent professional experience.

Preferred Qualifications

  • Hands-on experience integrating applications with an HSM or key-management service.
  • Experience with Java, Python, C/C++, C#, JavaScript, PowerShell, Bash, or similar technologies.
  • Familiarity with cryptographic APIs and standards such as PKCS #11, JCA/JCE, Microsoft CNG, KMIP, REST, or vendor-specific SDKs.
  • Knowledge of payment cryptography, PIN security, DUKPT, key blocks, remote key distribution, or transaction-signing workflows.
  • Familiarity with PCI PIN, TR-31, TR-34, ISO 9564, FIPS 140-3, NIST guidance, or comparable cryptographic standards.
  • Experience with HSM migrations, firmware or software upgrades, capacity expansion, multi-datacenter designs, or disaster-recovery testing.
  • Experience with CI/CD, automated testing, infrastructure as code, configuration management, or DevSecOps practices.
  • Familiarity with the secure use of AI-assisted development and productivity tools in regulated environments.
  • Familiarity with cloud-based key-management and HSM offerings.
  • Understanding of post-quantum cryptography, crypto-agility planning, and cryptographic discovery or inventory.
  • Relevant Product Owner, cloud, security, payment, or cryptography certification.

Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against American Express's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on American Express's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    American Express's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.