Sr. Application Security Architect (AI & API)

Sr. Application Security Architect (AI & API)

Full-Time Hybrid
A

At a Glance

  • Tasks: Lead application security for AI and API systems, guiding teams to build secure software.
  • Company: Join Amex GBT, a travel company that values collaboration and innovation.
  • Benefits: Enjoy flexible benefits, travel perks, and access to 20,000+ courses for your growth.
  • Other info: Inclusive culture where your voice matters and career growth is encouraged.
  • Why this job: Make a real impact in the tech world while working with cutting-edge AI and API technologies.
  • Qualifications: 10+ years in software engineering or security architecture, with deep API and AI expertise.

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

We're looking for a Senior Application Security Architect with a deep specialization in AI and API security to help Amex GBT's development teams make sound architectural choices and build secure software. This role covers the full spectrum of application security — secure SDLC, vulnerability management, and secure coding practices — with a particular focus on the APIs and AI/agentic systems that are increasingly central to our platform. Rather than designing architectures in isolation, you'll guide engineering teams toward the right approach for their use case, educate them on the tradeoffs between options, and work hands-on to help implement and secure what they build. You'll also assess and strengthen the security of our existing application, API, and AI implementations, using tooling such as API and AI gateways, and act as a trusted technical advisor across engineering.

What you'll be doing:

  • Serve as a senior application security architect for Amex GBT's engineering organization, with a primary focus on API and AI/agentic systems while maintaining broad ownership of secure SDLC and application security practices.
  • Guide engineering teams in selecting the right application, API, and AI/agentic architecture patterns for their use case, clearly explaining the tradeoffs between approaches (e.g., REST vs. GraphQL vs. gRPC, synchronous vs. event-driven, different AI/agent frameworks).
  • Educate and advise development teams on the security, scalability, and maintainability implications of different application, API, and AI/agentic design choices.
  • Partner hands-on with development teams to implement and secure chosen application, API, and AI architectures, including authentication, authorization (OAuth 2.0, OpenID Connect, JOSE/JWT), and API/AI gateway configuration.
  • Assess and secure existing application, API, and AI implementations, using appropriate tooling (such as SAST/DAST/SCA, API gateways, and AI gateways) to identify and close security gaps.
  • Guide the secure adoption of AI-native and agentic development workflows (e.g., AI-assisted IDEs, agentic coding platforms) across engineering, balancing productivity gains with security and governance.
  • Lead threat modeling and secure design reviews across applications, APIs, AI/ML services, and agentic systems, identifying risks specific to LLM-powered and autonomous components (e.g., prompt injection, data exfiltration, model misuse).
  • Partner with engineering, security, legal, and product leadership to define governance policies and standards for application design, API design, and responsible AI/agentic tool usage.
  • Provide technical leadership and mentorship on applied cryptography, secure coding, secure API design, and cloud-native architecture (Kubernetes, AWS/GCP/Azure).
  • Represent Amex GBT in industry standards efforts related to application and API security and AI governance (e.g., OAuth, JOSE, emerging AI/agent security standards).
  • Develop and maintain decision frameworks, tradeoff guides, and documentation to help teams evaluate and secure their application, API, and AI architecture choices.
  • Generate security KPI and metrics reporting across security programs to measure progress and effectiveness, and present findings to senior leadership.

What we're looking for:

  • 10+ years of experience in software engineering, application security, or security architecture, including experience guiding or reviewing both application and API architecture decisions at scale.
  • Strong foundation in application security fundamentals — secure SDLC, vulnerability management (SAST/DAST/SCA), secure coding practices, and OWASP Top 10 — in addition to deep API- and AI-specific expertise.
  • Deep expertise in API design and security, including OAuth 2.0, OpenID Connect, JWT/JOSE, and API gateway/service mesh architectures.
  • Strong ability to evaluate and clearly communicate architectural tradeoffs, translating complex technical decisions into guidance that development teams can act on.
  • Experience assessing and securing existing application, API, and AI implementations, including working with API gateways and/or AI gateways.
  • Hands-on experience with cloud-native architectures (AWS, Azure, or GCP) and container orchestration (Kubernetes).
  • Practical experience with AI-native and agentic development tools (e.g., Claude Code, GitHub Copilot, Cursor, or similar) and a clear understanding of the security implications of AI-assisted and autonomous development workflows.
  • Strong background in applied cryptography and secure software design.
  • Proven ability to lead threat modeling, secure design reviews, and architecture governance for both traditional applications and AI/API-centric systems across cross-functional engineering organizations.
  • Proficiency in multiple programming languages (e.g., Go, Java, Python).
  • Excellent written and verbal communication skills, including experience developing technical policy, standards, or training materials.
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.

Preferred qualities

  • Advanced degree (M.Sc./Ph.D.) in Computer Science, Artificial Intelligence, or a related field.
  • Track record of thought leadership: publications, conference talks, published CVEs, or contributions to security/API standards bodies (e.g., IETF OAuth/JOSE working groups).
  • Experience with regulatory or compliance frameworks such as PCI-DSS.
  • Experience securing AI/LLM-powered systems and agentic architectures, including AI gateway deployments.
  • Background in broader application security program leadership (e.g., vulnerability management, secure SDLC rollout) beyond API- and AI-specific initiatives.
  • Experience leading or mentoring engineering teams in a principal/staff-level individual contributor or architect capacity.

Location

United Kingdom

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Click Here for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;" please apply anyway. You may be exactly the person we’re looking for!

Sr. Application Security Architect (AI & API) employer: Amex

At Amex GBT, we pride ourselves on being an inspiring employer that values collaboration and inclusivity, making it a fantastic place for Account Managers to thrive. Our UK-based team enjoys flexible benefits tailored to individual needs, extensive learning opportunities with access to over 20,000 courses, and a supportive work culture that champions diversity and personal growth. Join us to make a meaningful impact in the business travel industry while enjoying unique travel perks and a commitment to your professional development.

A

Contact Details:

Amex Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Sr. Application Security Architect (AI & API)

✨Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Amex or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

✨Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Amex.

✨Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Amex.

✨Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Amex that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Sr. Application Security Architect (AI & API)

Application Security
API Security
AI Security
Secure SDLC
Vulnerability Management
Secure Coding Practices
OAuth 2.0

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Amex.

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Amex and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at Amex

✨Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

✨Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Amex uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

✨Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

✨Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.