Cyber Security Engineer-Application Security Tooling (SCA/SAST/ DAST/ MAST/ API Security)

American Express — United States · Posted ~3 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Job Description Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues. The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights. At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company. Trust. Service. Security. As an Application Security Cybersecurity Engineer, you will be part of a team focused on strengthening application security and helping engineering teams build and operate secure technology at scale. This role combines cybersecurity engineering (including AI/ML), application security, software development, automation, and secure software development lifecycle (SDLC) practices. You will work closely with software engineers, architects, product teams, and cybersecurity partners to identify and reduce security risk throughout the application lifecycle. You will contribute to the development and operation of security capabilities, help integrate security testing and controls into engineering workflows, analyze vulnerabilities and emerging threats, and provide technical guidance that enables teams to remediate security issues effectively. This is a hands-on engineering role suited for someone who enjoys solving security problems through a combination of software engineering, automation, security testing, research, and collaboration. You will have opportunities to work across modern application architectures, APIs, cloud and container environments, CI/CD pipelines, and application security technologies while continuing to grow your cybersecurity and engineering expertise. You will also contribute to the continuous improvement of application security processes, tooling, documentation, and engineering practices that help protect American Express applications, systems, and data. Responsibilities Designs, develops, tests, and debugs software applications and systemsCompletes software builds through consistent development practices, including the use of tools, common components, and documentation with guidance from peers and leadersCompletes code reviews/Secure code reviews and automated testing to maintain high-quality code standards with guidance from peers and leadersSupports and monitors software across test, integration, and production environmentsAdheres to security and regulatory best practices to ensure software complianceCollaborates and co-creates effectively with teams in product and the business to align technology initiatives with business objectivesCompletes the development and maintenance of security policies, procedures, and best practices to ensure compliance with industry standards and regulatory requirementsCollaborates with software development teams to integrate security into the software development lifecycle, including conducting code reviews and providing support on secure coding practicesImplements encryption technologies to protect sensitive data in transit and at rest, ensuring the confidentiality and integrity of the organization's data, with guidance from peers and leadersConducts research on emerging security threats and technologies to stay updated and maintain situation awareness on emerging and disruptive technologiesConducts testing and evaluation of new cybersecurity technologies, following SDLC practices for deployment and testing, while managing changes in release management to maintain system integrity and securityDrafts detailed technical documentation and reports on security assessments, findings, and remediation efforts to provide insights and recommendations for improving the organization's security posture, under guidance from peers and leadersApplies AI-enabled security tooling and automation capabilities to improve threat detection, investigation efficiency, and operational observability across cybersecurity environmentsSupports the implementation of security controls and monitoring practices for AI-enabled applications and workflows, ensuring alignment with enterprise security standards and risk requirementsDesigns and refines prompts that improve the effectiveness of AI agent-enabled cybersecurity engineering activities, including threat detection, observability, automation, secure development, control implementation, and security research, while identifying opportunities to incorporate Agentic AI workflows into engineering processes. Qualifications Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, and/or comparable experience; advanced degree preferredKnowledge of regulatory compliance and security standardsKnowledge of Application Development & SecurityKnowledge of Data EngineeringKnowledge of Cloud Security ManagementKnowledge of Data Privacy & Protection (DPP, GDPR)Knowledge of Data Security ManagementKnowledge of scripting languages such as Python, Bash, or PowerShell for automating security tasksKnowledge of distributed (multi-tiered) systems, algorithms, NoSQL and relational databasesKnowledge of the core tools used in the planning, analyzing, crafting, building, testing, configuring, and maintaining of assigned application(s)knowledge of event driven architecture and messaging: Kafka, web hooks, asynchronous API design preferred.Experience in application design, software development, and automated testingExperience in object-oriented design and coding with variety of languagesExperience in distributed (multi-tiered) systems, algorithms, and relational databasesExperience in Agile software development methodologies and practices such as Scrum/Kanban, iterations, user storiesExperience in automation testing and documentation (i.e. automated, functional, and performance)Experience with Testing Frameworks: Unit testing, Regression TestingExperience with Java 8+, Spring Suite Framework preferredExperience with Python, Django framework preferredExperience with React JS, Node JS, Go-lang preferredExperience with Kubernetes, Docker, Jenkins, Cloud deployment (CI/CD) preferredExperience with PostgreSQL, Oracle, or equivalent relational databases preferredKnowledge of AI security concepts, including risks associated with generative AI, model integrity, prompt security, and protection of sensitive enterprise dataKnowledge of AI-assisted cybersecurity operations and automation frameworks used to enhance detection, response, and security engineering workflowsAt least one security related certification preferred like: CSSLP, GWEB, GCIH, CEH, GSEC, C|ASE, CCNA, etc.At least one developer related certification preferred like: OCP. OCA, OCM, DCD, DVA-C02, CKAD, ACE, CCSP, Profession Cloud Developer, etc. Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.