Enable America Jobs

Enable America Logo

Job Information

American Express Application Security Threat Modeler in Toronto, Ontario

Description

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

American Express is seeking an Application Security Architect with proven strong competence in building implementing application security governance and risk management processes. The Application Security Architect serves as a domain expert in developing and maintaining comprehensive security requirements across a diverse number of technology stacks. The Application Security Architect supports the security champion practice by evangelizing secure design and secure coding controls.

Primary Responsibilities:

  • Develop security governance processes and procedures for the threat modeling program.

  • Assist in the development of threat modeling governance documentation.

  • Works with information security leadership to develop strategies and plans to enforce threat modeling and address identified control gaps.

  • Develops reports for management concerning residual risk and non-compliance.

  • Monitor and track compliance with application owners to ensure implementation of security controls as planned.

  • Review issued security controls with application owners to ensure identified requirements are implemented.

  • Validate implementation of security controls against outputs of scanning tools to enable auditability and verifiability.

  • Assist application owners in filing appropriate security standard exceptions as identified through threat modeling.

  • Develop, Maintain, update and enhance secure design patterns and secure coding standards.

  • Develop, Maintain, update and enhance threat libraries.

  • Socialize secure design patterns and secure coding standards with engineering teams.

  • Assist application teams with threat modeling consultancy questions.

  • Consistently enable strong developer and customer experience when liaising with application teams. Uphold Blue Box values when liaising with application teams.

Minimum Qualifications:

  • Bachelor's degree in computer science, information systems, or cybersecurity

  • 6 years Application Security and Technical Experience

  • Experience with implementing security governance and risk management processes.

  • 6 years information security risk concepts and principles, as a means of relating business needs to security controls.

  • 3 years experience in developing, documenting and maintaining security policies, processes, procedures and standards.

  • 3 years experience with application threat modeling. Threat assessment, security architecture reviews

  • 3 years of software engineering experience

  • Certification CISSP

Preferred Qualifications:

  • Experience with threat modeling frameworks, attack vectors and vulnerability analysis: CAPEC, ATT&CK, STRIDE.

  • Experience with application security controls (Web, API, Mobile, AI).

  • Experience with common information security management and application frameworks: NIST 800-53, CSF, OWASP ASVS.

  • Experience with Machine Learning Application Development

  • Knowledge of Adversarial Robustness techniques and tools for machine learning

  • Knowledge of AI Risk Management frameworks and Trustworthy AI practices.

  • Experience with deploying and operationalizing AI/ML models to public cloud environments.

  • Experience with Application Security design and DevSecOps.

  • Full stack knowledge of application architectures including: Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.

  • Experience with Java, JavaScript and mobile application development.

  • Knowledge or familiarity with database architectures including Oracle, SQL, DB2 and NoSQL Databases

  • Experience with Cloud security, architecture, design, implementation, and operations.

  • Exposure to IAM Controls (OAuth 2.0, OIDC, JWT)

  • Strong familiarity with Cryptography Controls (Data at rest, in motion).

  • CISSP, CISM, CSSLP, CISA, CRISC

Qualifications

We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

  • Competitive base salaries

  • Bonus incentives

  • Support for financial-well-being and retirement

  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)

  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need

  • Generous paid parental leave policies (depending on your location)

  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)

  • Free and confidential counseling support through our Healthy Minds program

  • Career development and training opportunities

American Express is committed to providing an inclusive and accessible work environment in which all people who apply for positions or who work for or on behalf of Amex are treated with dignity and respect and are provided with equal treatment with respect to employment, regardless of that person's age, sex, sexual orientation, gender identity, gender expression, race, colour, ancestry, ethnic or national origin, citizenship, religion or creed, marital status, family status, pregnancy, disability, record of offences, social condition or origin, political beliefs, association or activity or other factors prohibited under applicable Human Rights legislation (the “Prohibited Grounds”). If you have a disability and need accommodation, please speak with the Recruiter for more information.

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.

Job: Technology

Primary Location: Canada-Ontario-Toronto

Schedule Full-time

Req ID: 24003270

DirectEmployers