-
View all jobs
You Lead the Way. We’ve Got Your Back.
With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.
At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.
Join Team Amex and let's lead the way together.
How will you make an impact in this role?
American Express is seeking an Information Security Specialist specialized in Application Security Architect with proven strong competence in building implementing application security governance and risk management processes. The Application Security Architect serves as a domain expert in developing and maintaining comprehensive security requirements across a diverse number of technology stacks. The Application Security Architect supports the security champion practice by evangelizing secure design and secure coding controls.
Primary Responsibilities:
Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.
With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.
At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.
Join Team Amex and let's lead the way together.
How will you make an impact in this role?
American Express is seeking an Information Security Specialist specialized in Application Security Architect with proven strong competence in building implementing application security governance and risk management processes. The Application Security Architect serves as a domain expert in developing and maintaining comprehensive security requirements across a diverse number of technology stacks. The Application Security Architect supports the security champion practice by evangelizing secure design and secure coding controls.
Primary Responsibilities:
- Conducts security risk assessments of applications with respect to design and implementation of system and application code.
- Develop security governance processes and procedures for the threat modeling program.
- Assist in the development of threat modeling governance documentation.
- Works with information security leadership to develop strategies and plans to enforce threat modeling and address identified control gaps.
- Develops reports for management concerning residual risk and non compliance.
- Monitor and track compliance with application owners to ensure implementation of security controls as planned.
- Review issued security controls with application owners to ensure identified requirements are implemented.
- Validate implementation of security controls against outputs of scanning tools to enable auditability and verifiability.
- Assist application owners in filing appropriate security standard exceptions as identified through threat modeling.
- Develop, Maintain, update and enhance secure design patterns and secure coding standards.
- Develop, Maintain, update and enhance threat libraries.
- Socialize secure design patterns and secure coding standards with engineering teams.
- Assist application teams with threat modeling consultancy questions.
- Develop innovative attack techniques to foil protective design and in-place mitigations.
- Participate in the development of strategies for information security processes and programs.
- Consistently enable strong developer and customer experience when liaising with application teams. Uphold Blue Box values when liaising with application teams.
- Master's degree in computer science, information systems, or cybersecurity.
- 6-9 years of information security experience.
- Experience with implementing security governance and risk management processes.
- 6+ years information security risk concepts and principles, as a means of relating business needs to security controls.
- 1+ years' experience in developing, documenting and maintaining security policies, processes, procedures and standards.
- 2+ years' experience with application threat modeling.
- 2+ years with threat modeling frameworks, attack vectors and vulnerability analysis: CAPEC, ATT&CK, STRIDE.
- 3 + experience with common information security management and application frameworks: NIST 800-53, CSF, OWASP ASVS.
- 3+ years full stack knowledge of application architectures including: Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.
- PhD degree or Master's degree in Cybersecurity, Quantum, AI/ML, Computer Science, Computational Math, Statistics, Combinatorics & Optimization or related technical field.
- Experience with threat modeling frameworks, attack vectors and vulnerability analysis: CAPEC, ATT&CK, STRIDE.
- Experience with application security controls (Web, API, Mobile, AI).
- Experience with common information security management and application frameworks: NIST 800-53, CSF, OWASP ASVS.
- Experience with Application Security design and DevSecOps.
- Full stack knowledge of application architectures including: AI/ML, GenAI, Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.
- Experience with Python, Java, JavaScript and mobile application development.
- Knowledge or familiarity with database architectures including Oracle, SQL, DB2 and NoSQL Databases.
- Experience with Cloud security, architecture, design, implementation, and operations.
- Exposure to IAM Controls (OAuth 2.0, OIDC, JWT).
- Strong familiarity with Cryptography Controls (Data at rest, in motion).
- Certification - CISSP, CISM, CSSLP, CISA, CRISC.
- Competitive base salaries
- Bonus incentives
- Support for financial-well-being and retirement
- Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- Generous paid parental leave policies (depending on your location)
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities
Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.
Key Skills
Ranked by relevance
design patterns
owasp
nist
cloud security
cybersecurity
javascript
python
oracle
nosql
cissp
oauth
cloud
java
cisa
cism
sql
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
DevSecOps Expert
2026-05-28
Contract
Not Applicable
Belgium
IT Services
Other
View Job Details
Related
Staff Product Manager - Customer Service & Operator Platform
2026-05-21
Full-time
Mid-Senior
Finland
Financial Services
Other
View Job Details
Related
Dotnet Developer
2026-05-28
Full-time
Mid-Senior
France
IT Services
Information Technology
Login to Apply
- Posted
- Feb 12, 2025
- Type
- Full-time
- Level
- Entry
- Location
- Toronto
- Company
- American Express
Industries
Financial Services
Categories
Other
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
DevSecOps Expert
2026-05-28
Contract
Not Applicable
Belgium
IT Services
Other
View Job Details
Related
Staff Product Manager - Customer Service & Operator Platform
2026-05-21
Full-time
Mid-Senior
Finland
Financial Services
Other
View Job Details
Related
Dotnet Developer
2026-05-28
Full-time
Mid-Senior
France
IT Services
Information Technology