Sr. Application Security Architect (AI & API)

American Express Global Business Travel
•Onsite

About The Position

Amex GBT is seeking a Senior Application Security Architect with a deep specialization in AI and API security to guide engineering teams in making sound architectural choices and building secure software. This role encompasses the full spectrum of application security, including secure SDLC, vulnerability management, and secure coding practices, with a particular emphasis on APIs and AI/agentic systems. The architect will guide engineering teams, educate them on architectural tradeoffs, and work hands-on to implement and secure their solutions. Responsibilities also include assessing and strengthening existing application, API, and AI implementations using tools like API and AI gateways, and serving as a trusted technical advisor to engineering teams.

Requirements

  • 10+ years of experience in software engineering, application security, or security architecture, including experience guiding or reviewing both application and API architecture decisions at scale.
  • Strong foundation in application security fundamentals — secure SDLC, vulnerability management (SAST/DAST/SCA), secure coding practices, and OWASP Top 10 — in addition to deep API- and AI-specific expertise.
  • Deep expertise in API design and security, including OAuth 2.0, OpenID Connect, JWT/JOSE, and API gateway/service mesh architectures.
  • Strong ability to evaluate and clearly communicate architectural tradeoffs, translating complex technical decisions into guidance that development teams can act on.
  • Experience assessing and securing existing application, API, and AI implementations, including working with API gateways and/or AI gateways.
  • Hands-on experience with cloud-native architectures (AWS, Azure, or GCP) and container orchestration (Kubernetes).
  • Practical experience with AI-native and agentic development tools (e.g., Claude Code, GitHub Copilot, Cursor, or similar) and a clear understanding of the security implications of AI-assisted and autonomous development workflows.
  • Strong background in applied cryptography and secure software design.
  • Proven ability to lead threat modeling, secure design reviews, and architecture governance for both traditional applications and AI/API-centric systems across cross-functional engineering organizations.
  • Proficiency in multiple programming languages (e.g., Go, Java, Python).
  • Excellent written and verbal communication skills, including experience developing technical policy, standards, or training materials.
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.

Nice To Haves

  • Advanced degree (M.Sc./Ph.D.) in Computer Science, Artificial Intelligence, or a related field.
  • Track record of thought leadership: publications, conference talks, published CVEs, or contributions to security/API standards bodies (e.g., IETF OAuth/JOSE working groups).
  • Experience with regulatory or compliance frameworks such as PCI-DSS.
  • Experience securing AI/LLM-powered systems and agentic architectures, including AI gateway deployments.
  • Background in broader application security program leadership (e.g., vulnerability management, secure SDLC rollout) beyond API- and AI-specific initiatives.
  • Experience leading or mentoring engineering teams in a principal/staff-level individual contributor or architect capacity.

Responsibilities

  • Serve as a senior application security architect for Amex GBT's engineering organization, with a primary focus on API and AI/agentic systems while maintaining broad ownership of secure SDLC and application security practices.
  • Guide engineering teams in selecting the right application, API, and AI/agentic architecture patterns for their use case, clearly explaining the tradeoffs between approaches (e.g., REST vs. GraphQL vs. gRPC, synchronous vs. event-driven, different AI/agent frameworks).
  • Educate and advise development teams on the security, scalability, and maintainability implications of different application, API, and AI/agentic design choices.
  • Partner hands-on with development teams to implement and secure chosen application, API, and AI architectures, including authentication, authorization (OAuth 2.0, OpenID Connect, JOSE/JWT), and API/AI gateway configuration.
  • Assess and secure existing application, API, and AI implementations, using appropriate tooling (such as SAST/DAST/SCA, API gateways, and AI gateways) to identify and close security gaps.
  • Guide the secure adoption of AI-native and agentic development workflows (e.g., AI-assisted IDEs, agentic coding platforms) across engineering, balancing productivity gains with security and governance.
  • Lead threat modeling and secure design reviews across applications, APIs, AI/ML services, and agentic systems, identifying risks specific to LLM-powered and autonomous components (e.g., prompt injection, data exfiltration, model misuse).
  • Partner with engineering, security, legal, and product leadership to define governance policies and standards for application design, API design, and responsible AI/agentic tool usage.
  • Provide technical leadership and mentorship on applied cryptography, secure coding, secure API design, and cloud-native architecture (Kubernetes, AWS/GCP/Azure).
  • Represent Amex GBT in industry standards efforts related to application and API security and AI governance (e.g., OAuth, JOSE, emerging AI/agent security standards).
  • Develop and maintain decision frameworks, tradeoff guides, and documentation to help teams evaluate and secure their application, API, and AI architecture choices.
  • Generate security KPI and metrics reporting across security programs to measure progress and effectiveness, and present findings to senior leadership.

Benefits

  • Health and welfare insurance plans
  • Retirement programs
  • Parental leave
  • Adoption assistance
  • Wellbeing resources
  • Travel perks
  • Access to over 20,000 courses on our learning platform
  • Leadership courses
  • New job openings available to internal candidates first
  • Global INclusion Groups
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service