Sr. Application Security Engineer

American Express Global Business Travel

Northern (KY)

Hybrid

USD 104,000 - 194,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible benefits by country
Travel perks
Learning platform access

Job summary

Amex GBT is seeking a Senior Application Security Engineer to join a remote, cloud-native security team. You will integrate security into the software lifecycle, design secure CI/CD pipelines, and guide engineers on secure coding practices.

Ideal candidates bring 5+ years of software development and 3+ years in security, with expertise in OWASP Top 10, cloud security (AWS/Azure/GCP), and AI tooling governance. The role offers global travel perks and a learning platform.

Qualifications

  • 5+ years of professional software development with Python/Go/Java/JS/TS.
  • 3+ years in application security or DevSecOps.
  • Strong knowledge of OWASP Top 10 and API security; cloud security expertise.

Responsibilities

  • Design, implement, and maintain secure CI/CD pipelines with integrated security testing.
  • Deploy and tune SAST/DAST/DAST scanners and container scanning.
  • Govern API security, authentication, and secure design practices across teams.
  • Mentor engineers and promote a security-first culture in development workflows.
  • Evaluate guardrails for agentic AI coding tools and mitigate AI-specific risks.

Skills

Python
Go
Java
JavaScript/TypeScript
DevSecOps
OWASP Top 10
Cloud security
CI/CD pipelines
Agentic AI tools
Threat modeling

Education

Bachelor's degree in Computer Science or related field
Security certifications (CISSP, GIAC, OSCP, AWS Security Specialty)

Tools

SAST/DAST scanners
WAF
SIEM
Terraform
Docker
Kubernetes
Jenkins
GitHub Actions
CircleCI
Cloud platforms (AWS/Azure/GCP)

Job description

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. We are seeking an experienced Senior Application Security Engineer to join our team in the corporate travel industry. This remote position requires a unique blend of application development experience and security expertise to build, secure, and maintain our cloud-native infrastructure. The ideal candidate will have transitioned from application development into application security, bringing a developer's mindset to security and operations, and will mentor others while helping shape how the organization builds and governs secure software.

What You'll Do
  • Work with DevOps teams to design, implement, and maintain secure CI/CD pipelines that integrate security testing at every stage of the software development lifecycle
  • Implement and tune automated security scanning, including SAST, DAST, SCA, and container scanning
  • Deploy and support API security tools, ensuring findings are consistently reported to a central aggregator
  • Collaborate with development teams to promote secure coding practices and provide security guidance throughout the development process
  • Evaluate and help govern the secure use of agentic AI coding tools across engineering teams, establishing guardrails and detection strategies to mitigate risks such as hallucinated dependencies, injected vulnerabilities, and insufficient oversight
  • Ensure compliance with industry standards relevant to the travel industry, including PCI-DSS, GDPR, and SOC 2
  • Build KPI and metrics reporting for application security initiatives and present findings to leadership as needed
  • Mentor junior engineers and promote a security-first culture across engineering teams
What We're Looking For
  • 5+ years of professional software development experience with demonstrable expertise in major programming languages (Python, Go, Java, JavaScript/TypeScript);
  • 3+ years of hands-on application security or DevSecOps experience
  • Strong knowledge of OWASP Top 10 and related secure coding practices; deep understanding of API security, authentication protocols, and secure API design
  • Strong cloud security expertise with at least one major cloud service provider (AWS, Azure, or GCP); deep understanding of cloud-native security including IAM, network security, encryption, secrets management, and compliance frameworks
  • Proficiency with CI/CD tools and practical experience with infrastructure-as-code, containerization, and orchestration technologies; strong understanding of network security
  • Experience with agentic AI programming (AI-driven code generation and autonomous coding agents); deep understanding of risks including hallucinated dependencies, insecure code injection, and governance gaps; ability to help teams mitigate AI-specific security threats
  • Experience with threat modeling methodologies and risk assessment frameworks; ability to identify and communicate security risks to technical and non-technical audiences
  • Knowledge of compliance frameworks including PCI-DSS, GDPR, and CCPA; experience establishing or contributing to governance frameworks and guardrails for safe adoption of agentic AI coding tools
  • Background in penetration testing or red team operations; knowledge of MLSecOps practices including model security, data pipeline protection, and AI/ML supply chain security
  • Professional security certifications (CISSP, GIAC, OSCP, AWS Security Specialty, Azure Security Engineer, or similar); multi-cloud experience across AWS, Azure, and GCP
  • Experience in travel, hospitality, or e-commerce industry; open-source contributions or security research publications demonstrating commitment to the security community
Technical Skills
  • Programming & Scripting: Three or more languages, such as Python, Go, Java, C#, Ruby, JavaScript/TypeScript, Bash, PowerShell, Swift, Kotlin, Objective-C, or Dart, among others
  • Cloud Platforms: AWS (EC2, ECS, EKS, Lambda, S3, IAM, CloudWatch, GuardDuty), Azure (VMs, AKS, Functions, Key Vault, Sentinel), or GCP (Compute Engine, GKE, Cloud Functions, IAM, Security Command Center)
  • Security Tools: SAST/DAST scanners, WAF solutions, SIEM platforms, vulnerability scanners, secrets management tools
  • AI-Assisted Development: GitHub Copilot, Cursor, Claude Code, or similar agentic coding tools
  • AI Security Tooling: AI/agentic code security scanners and governance platforms
  • CI/CD: Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, Azure DevOps
  • Infrastructure: Terraform, Docker, Kubernetes, Helm, Ansible
  • Version Control: Git, GitHub, GitLab, Bitbucket
Location

United States

Salary

The US national base salary range for this position is from $104,300.00 - $193,700.00 The national range provided includes the base salary that Amex GBT expects to pay for the role. Actual base salary will be based on factors include the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location. In addition to base salary, the anticipated range of which is posted above, this role is eligible for a discretionary annual bonus, which rewards participants based on company and individual performance. For information about our comprehensive US benefits programs and eligibility, please review our Benefits-at-a-Glance document.

Benefits at a glance

The #TeamGBT Experience Work and life: Find your happy medium at Amex GBT. Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family. Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals. Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first. We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action. And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities.

Please let your recruiter know if you need an accommodation at any point during the hiring process.

For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Job Posting Title Director, Government Product Management
Job Posting Title Director, Government Product Management

American Express Global Business Travel • Northern (KY)

Hybrid
USD 130,000 - 242,000
Health and welfare insurance
Retirement programs
Parental leave
+2
Dedicated Account Representative
Dedicated Account Representative

American Express Global Business Travel • United States

On-site
USD 60,000 - 112,000
Health insurance
Retirement programs
Parental leave
+4
Dedicated Account Representative
Dedicated Account Representative

American Express Global Business Travel • Northern (KY)

Hybrid
USD 60,000 - 112,000
Health and welfare insurance
Travel perks and learning programs
Senior Cyber IAM Project Manager
Senior Cyber IAM Project Manager

American Express Global Business Travel • Trenton (NJ)

On-site
USD 88,000 - 164,000
Flexible benefits
Travel perks
Learning platform access
+1
Senior Cyber IAM Project Manager
Senior Cyber IAM Project Manager

American Express Global Business Travel • Atlanta (GA)

On-site
USD 88,000 - 164,000
Flexible benefits
Travel perks
Learning & development opportunities
+1
Job Posting Title Director, Government Product Management
Job Posting Title Director, Government Product Management

American Express Global Business Travel • Jackson (MS)

On-site
USD 130,000 - 242,000
Flexible benefits
Travel perks
Learning & development
Job Posting Title Director, Government Product Management
Job Posting Title Director, Government Product Management

American Express Global Business Travel • Nashville (TN)

On-site
USD 130,000 - 242,000
Flexible benefits
Travel perks
Learning platform access
+1
Senior Cyber IAM Project Manager
Senior Cyber IAM Project Manager

American Express Global Business Travel • Olympia (WA)

On-site
USD 88,000 - 164,000
Flexible benefits
Travel perks
Professional development and training
Specialized Travel Consultant
Specialized Travel Consultant

American Express Global Business Travel • Frankfort (KY)

On-site
USD 46,200 - 85,800
Flexible benefits
Travel perks
Access to over 20,000 courses
Dedicated Account Representative
Dedicated Account Representative

American Express Global Business Travel • Lansing (MI)

On-site
USD 60,000 - 112,000
Flexible benefits
Travel perks
Learning platform access
+1