Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.
At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.
Trust. Service. Security.
As an Application Security Cybersecurity Engineer, you will be part of a team focused on strengthening application security and helping engineering teams build and operate secure technology at scale. This role combines cybersecurity engineering (including AI/ML), application security, software development, automation, and secure software development lifecycle (SDLC) practices.
You will work closely with software engineers, architects, product teams, and cybersecurity partners to identify and reduce security risk throughout the application lifecycle. You will contribute to the development and operation of security capabilities, help integrate security testing and controls into engineering workflows, analyze vulnerabilities and emerging threats, and provide technical guidance that enables teams to remediate security issues effectively.
This is a hands-on engineering role suited for someone who enjoys solving security problems through a combination of software engineering, automation, security testing, research, and collaboration. You will have opportunities to work across modern application architectures, APIs, cloud and container environments, CI/CD pipelines, and application security technologies while continuing to grow your cybersecurity and engineering expertise.
You will also contribute to the continuous improvement of application security processes, tooling, documentation, and engineering practices that help protect American Express applications, systems, and data.
Responsibilities
- Designs, develops, tests, and debugs software applications and systems
- Completes software builds through consistent development practices, including the use of tools, common components, and documentation with guidance from peers and leaders
- Completes code reviews/Secure code reviews and automated testing to maintain high-quality code standards with guidance from peers and leaders
- Supports and monitors software across test, integration, and production environments
- Adheres to security and regulatory best practices to ensure software compliance
- Collaborates and co-creates effectively with teams in product and the business to align technology initiatives with business objectives
- Completes the development and maintenance of security policies, procedures, and best practices to ensure compliance with industry standards and regulatory requirements
- Collaborates with software development teams to integrate security into the software development lifecycle, including conducting code reviews and providing support on secure coding practices
- Implements encryption technologies to protect sensitive data in transit and at rest, ensuring the confidentiality and integrity of the organization's data, with guidance from peers and leaders
- Conducts research on emerging security threats and technologies to stay updated and maintain situation awareness on emerging and disruptive technologies
- Conducts testing and evaluation of new cybersecurity technologies, following SDLC practices for deployment and testing, while managing changes in release management to maintain system integrity and security
- Drafts detailed technical documentation and reports on security assessments, findings, and remediation efforts to provide insights and recommendations for improving the organization's security posture, under guidance from peers and leaders
- Applies AI-enabled security tooling and automation capabilities to improve threat detection, investigation efficiency, and operational observability across cybersecurity environments
- Supports the implementation of security controls and monitoring practices for AI-enabled applications and workflows, ensuring alignment with enterprise security standards and risk requirements
- Designs and refines prompts that improve the effectiveness of AI agent-enabled cybersecurity engineering activities, including threat detection, observability, automation, secure development, control implementation, and security research, while identifying opportunities to incorporate Agentic AI workflows into engineering processes.
Qualifications
- Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, and/or comparable experience; advanced degree preferred
- Knowledge of regulatory compliance and security standards
- Knowledge of Application Development & Security
- Knowledge of Data Engineering
- Knowledge of Cloud Security Management
- Knowledge of Data Privacy & Protection (DPP, GDPR)
- Knowledge of Data Security Management
- Knowledge of scripting languages such as Python, Bash, or PowerShell for automating security tasks
- Knowledge of distributed (multi-tiered) systems, algorithms, NoSQL and relational databases
- Knowledge of the core tools used in the planning, analyzing, crafting, building, testing, configuring, and maintaining of assigned application(s)
- knowledge of event driven architecture and messaging: Kafka, web hooks, asynchronous API design preferred.
- Experience in application design, software development, and automated testing
- Experience in object-oriented design and coding with variety of languages
- Experience in distributed (multi-tiered) systems, algorithms, and relational databases
- Experience in Agile software development methodologies and practices such as Scrum/Kanban, iterations, user stories
- Experience in automation testing and documentation (i.e. automated, functional, and performance)
- Experience with Testing Frameworks: Unit testing, Regression Testing
- Experience with Java 8+, Spring Suite Framework preferred
- Experience with Python, Django framework preferred
- Experience with React JS, Node JS, Go-lang preferred
- Experience with Kubernetes, Docker, Jenkins, Cloud deployment (CI/CD) preferred
- Experience with PostgreSQL, Oracle, or equivalent relational databases preferred
- Knowledge of AI security concepts, including risks associated with generative AI, model integrity, prompt security, and protection of sensitive enterprise data
- Knowledge of AI-assisted cybersecurity operations and automation frameworks used to enhance detection, response, and security engineering workflows
- At least one security related certification preferred like: CSSLP, GWEB, GCIH, CEH, GSEC, C|ASE, CCNA, etc.
- At least one developer related certification preferred like: OCP. OCA, OCM, DCD, DVA-C02, CKAD, ACE, CCSP, Profession Cloud Developer, etc.
Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.