Back to the roster

Associate -Cyber Ops & Assurance

Remote Full-time Hiring now

About the position At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express. How will you make an impact in this role? Providing guidance on application security processes, controls, and compliance, and information security risk management to team members Developing plans and strategies for application security tools, processes, and programs Responding to changes in the regulatory environment and assisting other organizations in doing the same. Making strategic recommendations to enhance application security, including processes, procedures, governance approaches, and compliance. Responsible for producing application security processes flow for various controls related to the application security domain (e.g., operational process and documentation) Identify technical problems and facilitate resolution of complex risk. Consulted on application security functional flows for various controls related to the application security domain. Responsible for the delivery of roadmap work items assigned or assigned metrics/thresholds. Consulted as an application security domain subject matter expert as required by ASM processes or procedures. Consulted as required on enhancing existing ASM capabilities. Accountable for dispositioning findings as vulnerabilities for introduction into EVM or suppressing them as false positives. Responsible for drafting responses to Audit/Regulatory queries as required by ASM processes, and procedures.

Responsibilities

  • Providing guidance on application security processes, controls, and compliance, and information security risk management to team members
  • Developing plans and strategies for application security tools, processes, and programs
  • Responding to changes in the regulatory environment and assisting other organizations in doing the same.
  • Making strategic recommendations to enhance application security, including processes, procedures, governance approaches, and compliance.
  • Responsible for producing application security processes flow for various controls related to the application security domain (e.g., operational process and documentation)
  • Identify technical problems and facilitate resolution of complex risk.
  • Consulted on application security functional flows for various controls related to the application security domain.
  • Responsible for the delivery of roadmap work items assigned or assigned metrics/thresholds.
  • Consulted as an application security domain subject matter expert as required by ASM processes or procedures.
  • Consulted as required on enhancing existing ASM capabilities.
  • Accountable for dispositioning findings as vulnerabilities for introduction into EVM or suppressing them as false positives.
  • Responsible for drafting responses to Audit/Regulatory queries as required by ASM processes, and procedures.

Requirements

  • Bachelor's degree in computer science, Information Systems, Cybersecurity, and/or comparable experience
  • Knowledge of regulatory compliance and security standards
  • Knowledge of Identity & Access Management
  • Knowledge of Security Architecture Management
  • Knowledge of Security Governance and Operations
  • Knowledge of Security Testing & Remediation
  • Knowledge of Cloud Security Management
  • Knowledge of Data Privacy & Protection (DPP, GDPR)
  • Experience in cybersecurity operations, application security, security research, penetration testing, information security
  • Exposure to Technical Writing and Documentation Development
  • Experience with network security, understanding network security principles, including firewalls, VPNs, and network segmentation
  • Understanding of basic incident response concepts
  • Experience with application security scanning tools SCA/SAST, IAST/RASP, MAST, DAST, others (e.g., Sonatype/XRAY, Qualys, Rapid7) and basic remediation steps
  • Understanding of cybersecurity best practices
  • Exposure to Business Continuity Planning and Disaster Recovery
  • Experience with the CI/CD process and tools like Git, Docker, Jenkins, Release pipeline etc. is required.
  • At least one current certification application security relevant certification GCPN, GWEB, GMOB, GWAT, GPEN, CEH, C|ASE .NET, C|ASE Java, OSCP

Nice-to-haves

  • 2+ years of experience in application security, application penetration testing, research, red team, or security operations center (SOC) analyst.
  • 2+ years of object-oriented design and full stack development, using languages like Go, Java., C#, or Python.
  • Knowledge of CI/CD process and tools like Git, Docker, Jenkins, Release pipeline etc. is required.
  • Ability to effectively communicate with internal and external business partners.
  • At least two of the certifications GCPN, GWEB, GMOB, GWAT, GPEN, CEH, C|ASE .NET, C|ASE Java, OSCP

Benefits

  • Competitive base salaries
  • Bonus incentives
  • 6% Company Match on retirement savings plan
  • Free financial coaching and financial well-being support
  • Comprehensive medical, dental, vision, life insurance, and disability benefits
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities

Apply tot his job Apply To this Job

Related roles

Cvent and Data Specialist

Remote Full-time

Client Manager - US Large Market (Virtual - Chicago/MN/WI/OH)

Remote Full-time

Global Occupational Health Nurse, WHS Global Medical and Health

Remote Full-time

Supervisor - Volunteer Engagement (can reside anywhere but must work in East / Central Time zones)

Remote Full-time

Regional Volunteer Services Officer

Remote Full-time

Senior Software Engineer - Developer API, Poe (Remote)

Remote Full-time

Developer - Integration/API Development - Contingent

Remote Full-time

Remote Apple Home Advisor – Empower Customers, Shape Experiences (Entry-Level, No Experience Needed!)

Remote Full-time

Lead Application Architect

Remote Full-time

Mass Arbitration Associate

Remote Full-time

Experienced Full Stack Software Engineer – Web & Cloud Application Development

Remote Full-time

Lead Machine Learning Engineer (Team Lead)

Remote Full-time

Program and Training Coordinator

Remote Full-time

Aetna Remote Job Opportunities $25/Hour

Remote Full-time

Experienced Data Entry Specialist – Entry-Level Opportunity at careerzynith (Remote)

Remote Full-time

Compassionate Pediatric In‑Home Registered Nurse – Remote, Full‑Time Role Supporting Young Patients in Ankeny, Iowa

Remote Full-time

Beginner-Friendly Remote Chat Jobs | Earn $25-$35/hr in a Supportive Virtual Environment

Remote Full-time

Experienced Data Entry Specialist – Content Management System

Remote Full-time

Experienced Healthcare Customer Service Representative – Onsite at arenaflex

Remote Full-time

Experienced Chat Support Representative – Delivering Exceptional Customer Experiences in a Remote Setting at arenaflex

Remote Full-time