Senior Security GRC Engineer, AI & Automation

American Express Global Business Travel
•$104,300 - $193,700•Onsite

About The Position

Amex GBT's Security GRC team is looking for a talented Senior Security GRC Engineer to design, build, and scale automation and AI-driven solutions that modernize our governance, risk, and compliance program. This role sits at the intersection of security engineering and GRC, translating manual, evidence-heavy processes into automated, data-driven workflows. The ideal candidate combines hands-on engineering skills with a strong understanding of GRC principles, and is excited to apply AI and automation to reduce risk, improve control coverage, and free up the team to focus on higher-value analysis.

Requirements

  • Bachelor’s degree in computer science, information security, information systems, or a related field (or equivalent experience).
  • 5+ years of experience in security engineering, GRC, or a related field, with demonstrated experience building automation or AI-enabled solutions.
  • Strong programming/scripting skills (e.g., Python, JavaScript, or similar) and experience working with APIs, databases, and workflow automation tools.
  • Hands-on experience applying AI or machine learning technologies (including LLMs and generative AI) to real-world business or security use cases.
  • Solid understanding of cybersecurity frameworks (NIST, ISO 27001, SOC 2) and regulatory compliance requirements (GDPR, PCI DSS).
  • Experience with GRC platforms such as Onspring, Archer, MetricStream, or similar tools, including configuration or integration work.
  • Familiarity with risk assessment methodologies, control frameworks, and audit evidence requirements.
  • Strong analytical and problem-solving skills, with the ability to translate complex, manual processes into automated solutions.
  • Excellent communication and reporting skills, with the ability to present technical solutions and their risk/compliance impact to both technical and non-technical stakeholders.

Responsibilities

  • Design, build, and maintain automation pipelines that continuously collect, normalize, and validate compliance and control evidence across security and business systems.
  • Evaluate, prototype, and deploy AI and large language model (LLM)-based solutions to accelerate GRC workflows, including control testing, evidence review, policy mapping, and risk narrative generation.
  • Integrate GRC tooling (e.g., Onspring, Archer, MetricStream, or similar platforms) with security and IT systems via APIs to enable automated data flows, dashboards, and reporting.
  • Develop and maintain scripts, bots, and workflow tools that automate recurring GRC tasks such as evidence gathering, control monitoring, and audit preparation.
  • Partner with Security GRC analysts and program managers to identify manual, repetitive processes and re-engineer them into scalable, automated solutions.
  • Establish guardrails, testing, and quality controls to ensure AI-assisted outputs are accurate, explainable, and compliant with regulatory and audit requirements.
  • Monitor and report on the performance, reliability, and risk posture of automation and AI tools used within the GRC program.
  • Stay current with emerging AI, automation, and GRC technologies, and recommend adoption of new tools and techniques to continuously improve program maturity.
  • Collaborate with other AmexGBT teams (security, engineering, data, and business) to align automation initiatives with broader security posture and compliance goals.

Benefits

  • health and welfare insurance plans
  • retirement programs
  • parental leave
  • adoption assistance
  • wellbeing resources
  • Travel perks
  • access to over 20,000 courses on our learning platform
  • leadership courses
  • new job openings available to internal candidates first
  • global INclusion Groups
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service