Sr. Application Security Architect; AI & API
Listed on 2026-10-06
-
Software Development
AI Engineer (Applied/Software), Software Architect
Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. We're looking for a Senior Application Security Architect with a deep specialization in AI and API security to help Amex GBT's development teams make sound architectural choices and build secure software.
This role covers the full spectrum of application security — secure SDLC, vulnerability management, and secure coding practices — with a particular focus on the APIs and AI/agentic systems that are increasingly central to our platform. Rather than designing architectures in isolation, you'll guide engineering teams toward the right approach for their use case, educate them on the tradeoffs between options, and work hands‑on to help implement and secure what they build.
You'll also assess and strengthen the security of our existing application, API, and AI implementations, using tooling such as API and AI gateways, and act as a trusted technical advisor across engineering.
- Serve as a senior application security architect for Amex GBT's engineering organization, with a primary focus on API and AI/agentic systems while maintaining broad ownership of secure SDLC and application security practices.
- Guide engineering teams in selecting the right application, API, and AI/agentic architecture patterns for their use case, clearly explaining the tradeoffs between approaches (e.g., REST vs. GraphQL vs. gRPC, synchronous vs. event‑driven, different AI/agent frameworks).
- Educate and advise development teams on the security, scalability, and maintainability implications of different application, API, and AI/agentic design choices.
- Partner hands‑on with development teams to implement and secure chosen application, API, and AI architectures, including authentication, authorization (OAuth
2.0, OpenID Connect, JOSE/JWT), and API/AI gateway configuration. - Assess and secure existing application, API, and AI implementations, using appropriate tooling (such as SAST/DAST/SCA, API gateways, and AI gateways) to identify and close security gaps.
- Guide the secure adoption of AI‑native and agentic development workflows (e.g., AI‑assisted IDEs, agentic coding platforms) across engineering, balancing productivity gains with security and governance.
- Lead threat modeling and secure design reviews across applications, APIs, AI/ML services, and agentic systems, identifying risks specific to LLM‑powered and autonomous components (e.g., prompt injection, data exfiltration, model misuse).
- Partner with engineering, security, legal, and product leadership to define governance policies and standards for application design, API design, and responsible AI/agentic tool usage.
- Provide technical leadership and mentorship on applied cryptography, secure coding, secure API design, and cloud‑native architecture (Kubernetes, AWS/GCP/Azure).
- Represent Amex GBT in industry standards efforts related to application and API security and AI governance (e.g., OAuth, JOSE, emerging AI/agent security standards).
- Develop and maintain decision frameworks, trade‑off guides, and documentation to help teams evaluate and secure their application, API, and AI architecture choices.
- Generate security KPI and metrics reporting across security programs to measure progress and effectiveness, and present findings to senior leadership.
- 10+ years of experience in software engineering, application security, or security architecture, including experience guiding or reviewing both application and API architecture decisions at scale.
- Strong foundation in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).