Sr. Application Security Engineer
Yankton, Yankton County, South Dakota, 57078, USA
Listed on 2026-09-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
United States
Full time
J-84294
Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.
We are seeking an experienced Senior Application Security Engineer to join our team in the corporate travel industry. This remote position requires a unique blend of application development experience and security expertise to build, secure, and maintain our cloud-native infrastructure. The ideal candidate will have transitioned from application development into application security, bringing a developer's mindset to security and operations, and will mentor others while helping shape how the organization builds and governs secure software.
What You’ll Do:Work with Dev Ops teams to design, implement, and maintain secure CI/CD pipelines that integrate security testing at every stage of the software development lifecycle
Implement and tune automated security scanning, including SAST, DAST, SCA, and container scanning
Deploy and support API security tools, ensuring findings are consistently reported to a central aggregator
Collaborate with development teams to promote secure coding practices and provide security guidance throughout the development process
Evaluate and help govern the secure use of agentic AI coding tools across engineering teams, establishing guardrails and detection strategies to mitigate risks such as hallucinated dependencies, injected vulnerabilities, and insufficient oversight
Ensure compliance with industry standards relevant to the travel industry, including PCI-DSS, GDPR, and SOC 2
Build KPI and metrics reporting for application security initiatives and present findings to leadership as needed
Mentor junior engineers and promote a security-first culture across engineering teams
5+ years of professional software development experience with demonstrable expertise in major programming languages (Python, Go, Java, JavaScript/Type Script); 3+ years of hands‑on application security or Dev Sec Ops experience
Strong knowledge of OWASP Top 10 and related secure coding practices; deep understanding of API security, authentication protocols, and secure API design
Strong cloud security expertise with at least one major cloud service provider (AWS, Azure, or GCP); deep understanding of cloud-native security including IAM, network security, encryption, secrets management, and compliance frameworks
Proficiency with CI/CD tools and practical experience with infrastructure-as-code, containerization, and orchestration technologies; strong understanding of network security
Experience with agentic AI programming (AI-driven code generation and autonomous coding agents); deep understanding of risks including hallucinated dependencies, insecure code injection, and governance gaps; ability to help teams mitigate AI-specific security threats
Experience with threat modeling methodologies and risk assessment frameworks; ability to identify and communicate security risks to technical and non-technical audiences
Knowledge of compliance frameworks including PCI-DSS, GDPR, and CCPA; experience establishing or contributing to governance frameworks and guardrails for safe adoption of agentic AI coding tools
Background in penetration testing or red team operations; knowledge of MLSecOps practices including model security, data pipeline protection, and AI/ML supply chain security
Professional security certifications (CISSP, GIAC, OSCP, AWS Security Specialty, Azure Security Engineer, or similar); multi-cloud experience across AWS, Azure, and GCP
Experience in travel, hospitality, or e-commerce…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).