Enable job alerts via email!

Information Security Specialist

American Express

Toronto

Hybrid

CAD 90,000 - 130,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

American Express is seeking an Information Security Specialist specialized in Application Security Architect in Toronto. The role involves conducting security risk assessments, developing governance processes, and supporting secure application development practices. Ideal candidates will have strong experience in information security, particularly in threat modeling and application security standards.

Benefits

Comprehensive medical, dental, and vision insurance
Flexible working model with hybrid arrangements
Generous paid parental leave policies
Free access to wellness centers
Career development and training opportunities

Qualifications

  • 6-9 years of information security experience.
  • Experience with application threat modeling.
  • Knowledge of NIST 800-53 and OWASP ASVS.

Responsibilities

  • Conduct security risk assessments of applications.
  • Develop security governance processes.
  • Socialize secure design patterns with engineering teams.

Skills

Application Security Governance
Risk Management
Threat Modeling
Vulnerability Analysis
Information Security Management

Education

Master's degree in computer science
PhD in Cybersecurity

Job description

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

How will you make an impact in this role?

American Express is seeking an Information Security Specialist specialized in Application Security Architect with proven strong competence in building implementing application security governance and risk management processes. The Application Security Architect serves as a domain expert in developing and maintaining comprehensive security requirements across a diverse number of technology stacks. The Application Security Architect supports the security champion practice by evangelizing secure design and secure coding controls.

Primary Responsibilities :

  • Conducts security risk assessments of applications with respect to design and implementation of system and application code.
  • Develop security governance processes and procedures for the threat modeling program.
  • Assist in the development of threat modeling governance documentation.
  • Works with information security leadership to develop strategies and plans to enforce threat modeling and address identified control gaps.
  • Develops reports for management concerning residual risk and non compliance.
  • Monitor and track compliance with application owners to ensure implementation of security controls as planned.
  • Review issued security controls with application owners to ensure identified requirements are implemented.
  • Validate implementation of security controls against outputs of scanning tools to enable auditability and verifiability.
  • Assist application owners in filing appropriate security standard exceptions as identified through threat modeling.
  • Develop, Maintain, update and enhance secure design patterns and secure coding standards.
  • Develop, Maintain, update and enhance threat libraries.
  • Socialize secure design patterns and secure coding standards with engineering teams.
  • Assist application teams with threat modeling consultancy questions.
  • Develop innovative attack techniques to foil protective design and in-place mitigations.
  • Participate in the development of strategies for information security processes and programs.
  • Consistently enable strong developer and customer experience when liaising with application teams. Uphold Blue Box values when liaising with application teams.

Minimum Qualifications :

  • Master's degree in computer science, information systems, or cybersecurity.
  • 6-9 years of information security experience.
  • Experience with implementing security governance and risk management processes.
  • 6+ years information security risk concepts and principles, as a means of relating business needs to security controls.
  • 1+ years' experience in developing, documenting and maintaining security policies, processes, procedures and standards.
  • 2+ years' experience with application threat modeling.
  • 2+ years with threat modeling frameworks, attack vectors and vulnerability analysis : CAPEC, ATT&CK, STRIDE.
  • 3 + experience with common information security management and application frameworks : NIST 800-53, CSF, OWASP ASVS.
  • 3+ years full stack knowledge of application architectures including : Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.

Preferred Qualifications :

  • PhD degree or Master's degree in Cybersecurity, Quantum, AI / ML, Computer Science, Computational Math, Statistics, Combinatorics & Optimization or related technical field.
  • Experience with threat modeling frameworks, attack vectors and vulnerability analysis : CAPEC, ATT&CK, STRIDE.
  • Experience with application security controls (Web, API, Mobile, AI).
  • Experience with common information security management and application frameworks : NIST 800-53, CSF, OWASP ASVS.
  • Experience with Application Security design and DevSecOps.
  • Full stack knowledge of application architectures including : AI / ML, GenAI, Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.
  • Knowledge or familiarity with database architectures including Oracle, SQL, DB2 and NoSQL Databases.
  • Experience with Cloud security, architecture, design, implementation, and operations.
  • Exposure to IAM Controls (OAuth 2.0, OIDC, JWT).
  • Strong familiarity with Cryptography Controls (Data at rest, in motion).
  • Certification - CISSP, CISM, CSSLP, CISA, CRISC.

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include :

  • Support for financial-well-being and retirement
  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • Generous paid parental leave policies (depending on your location)
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities

American Express is committed to providing an inclusive and accessible work environment in which all people who apply for positions or who work for or on behalf of Amex are treated with dignity and respect and are provided with equal treatment with respect to employment, regardless of that person's age, sex, sexual orientation, gender identity, gender expression, race, colour, ancestry, ethnic or national origin, citizenship, religion or creed, marital status, family status, pregnancy, disability, record of offences, social condition or origin, political beliefs, association or activity or other factors prohibited under applicable Human Rights legislation (the “Prohibited Grounds”). If you have a disability and need accommodation, please speak with the Recruiter for more information.

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.

J-18808-Ljbffr

Create a job alert for this search

Information Security Specialist • Toronto, ON, Canada

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Information Security Specialist

ProViso Staffing

Toronto

On-site

CAD 80,000 - 120,000

Yesterday
Be an early applicant

Information Security Specialist

Services de Gestion Quantum Ltée

Toronto

On-site

CAD 70,000 - 100,000

2 days ago
Be an early applicant

IT - Security Specialist V

ICONMA

Toronto

Hybrid

CAD 90,000 - 120,000

2 days ago
Be an early applicant

IT Security Specialist

Bevertec

Toronto

On-site

CAD 90,000 - 130,000

5 days ago
Be an early applicant

Information Security Specialist

TD Bank

Toronto

Hybrid

CAD 91,000 - 137,000

27 days ago

Senior Software Engineer

Zone & Co

Toronto

Remote

CAD 85,000 - 120,000

Today
Be an early applicant

Senior Software Developer (Future Openings)

Zensurance

Old Toronto

Remote

CAD 90,000 - 130,000

Yesterday
Be an early applicant

Software Engineer, CTO (Remote)

TOPOLIO

Toronto

Remote

CAD 70,000 - 120,000

Yesterday
Be an early applicant

Information Security Specialist - Cyber Threat Management

TD

Toronto

On-site

CAD 91,000 - 137,000

19 days ago