American Express

AI/ML Security Engineer

Toronto, Ontario Remote Hybrid
API Java JavaScript Oracle SQL Machine Learning
Description

You Lead the Way. We’ve Got Your Back.

With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create a career journey that’s unique and meaningful to you with benefits, programs, and flexibility that support you personally and professionally.

At American Express, you’ll be recognized for your contributions, leadership, and impact—every colleague has the opportunity to share in the company’s success. Together, we’ll win as a team, striving to uphold our company values and powerful backing promise to provide the world’s best customer experience every day. And we’ll do it with the utmost integrity, and in an environment where everyone is seen, heard and feels like they belong.

Join Team Amex and let's lead the way together.

How will you make an impact in this role?

American Express is seeking an AI/ML Security Engineer with proven strong competence in building implementing AI/ML application security governance and risk management processes. The Security Engineer serves as a domain expert in developing and maintaining comprehensive security requirements across a diverse number of technology stacks. This engineer plays a key role in assessing capabilities including, Generative AI augmented, LLM agentic cybersecurity solutions, emerging risk security technologies and conducting proof-of-concept evaluations to drive innovative capability adoption.

    Primary Responsibilities:

    • Perform threat modeling for Applications.
    • Develop security governance processes and procedures for the threat modeling program with key focus on AI/ML.
    • Assist in the development of threat modeling governance documentation.
    • Develops reports for management concerning residual risk and non-compliance.
    • Monitor and track compliance with application owners to ensure implementation of security controls as planned.
    • Review issued security controls with application owners to ensure identified requirements are implemented.
    • Validate implementation of security controls against outputs of scanning tools to enable auditability and verifiability.
    • Assist application owners in filing appropriate security standard exceptions as identified through threat modeling.
    • Develop, Maintain, update and enhance secure design patterns and secure coding standards.
    • Develop, Maintain, update and enhance threat libraries.
    • Socialize secure design patterns and secure coding standards with engineering teams.
    • Assist application teams with threat modeling consultancy questions.
    • Consistently enable strong developer and customer experience when liaising with application teams. Uphold Blue Box values when liaising with application teams.
    • Implement secure model development life cycle practices with automated white box and black box assessments for AI/ML models.
    • Identify, analyze, and benchmark Generative AI augmented, LLM agentic security solutions in the market.
    • Conduct proof-of-concept (PoC) assessments of selected cybersecurity capabilities to validate effectiveness in real-world environments.
    • Define security control baselines and evaluation criteria for emerging risk security solutions.
    • Evaluate vendor claims, solution architecture, and technical scalability.
    • security testing of GenAI-powered cybersecurity tools.
    • Publish detailed reports on the security, compliance, and efficacy of evaluated products. `
    • Deliver and integrate AI robustness, vulnerability, and stress testing capabilities with MLOps ecosystems.
    • Evaluate and assess open-source AI security libraries to build into enterprise AI stress testing and audit capabilities.

    Minimum Qualifications:

    • Bachelor's Degree in Data Science, Statistics, Computer Science or Software Engineering.
    • 2+ years experience with Machine Learning Application Development.
    • 3+ years of software engineering experience. 

    Preferred Qualifications:

    • Master's Degree - Data Science, Statistics, Computer Science, or Software Engineering.
    • Machine Learning Operation Professional Certifications.
    • Strong knowledge of Adversarial Robustness techniques and tools for machine learning. 
    • Strong knowledge of AI Risk Management frameworks and Trustworthy AI practices. 
    • Hands-on experience with applying statistics, machine learning algorithms (DNN, NLP), big data, and data science toolkits. Hands-on experience designing, implementing, and operationalizing high performant AI/ML pipelines and writing production code.
    • Hands-on experience with deploying and operationalizing AI/ML models to public cloud environments.
    • Hands-on experience evaluating open-source ML tools, frameworks, and libraries.
    • Hands-on experience with commonly used data science programming languages, packages, and tools.
    • Hands-on experience with MLOps, DevOps, DataOps and API integrations.
    • Hands-on experience with AI workload management.
    • Hands-on experience with Cloud architecture, design, implementation, and operations.
    • Demonstrated peer reviewed journal publications, conference presentations, open-source contributions, or similar activities.
    • Experience with threat modeling frameworks, attack vectors and vulnerability analysis: CAPEC, ATT&CK, STRIDE.
    • Experience with application security controls (Web, API, Mobile, AI).
    • Experience with common information security management and application frameworks: NIST 800-53, CSF, OWASP ASVS.
    • Experience with Application Security design and DevSecOps.
    • Full stack knowledge of application architectures including: Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.
    • Experience with Java, JavaScript and mobile application development.
    • Knowledge or familiarity with database architectures including Oracle, SQL, DB2 and NoSQL Databases.
    • Experience with Cloud security, architecture, design, implementation, and operations.
    • Exposure to IAM Controls (OAuth 2.0, OIDC, JWT).
    • Strong familiarity with Cryptography Controls (Data at rest, in motion).
    • Certification - CISSP, CISM, CSSLP, CISA, CRISC.

    We back our colleagues and their loved ones with benefits and programs that support their holistic well-being. That means we prioritize their physical, financial, and mental health through each stage of life. Benefits include:

    • Competitive base salaries 
    • Bonus incentives 
    • Support for financial-well-being and retirement 
    • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location) 
    • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need 
    • Generous paid parental leave policies (depending on your location) 
    • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location) 
    • Free and confidential counseling support through our Healthy Minds program 
    • Career development and training opportunities

    American Express is committed to providing an inclusive and accessible work environment in which all people who apply for positions or who work for or on behalf of Amex are treated with dignity and respect and are provided with equal treatment with respect to employment, regardless of that person's age, sex, sexual orientation, gender identity, gender expression, race, colour, ancestry, ethnic or national origin, citizenship, religion or creed, marital status, family status, pregnancy, disability, record of offences, social condition or origin, political beliefs, association or activity or other factors prohibited under applicable Human Rights legislation (the “Prohibited Grounds”).   If you have a disability and need accommodation, please speak with the Recruiter for more information.

    Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.

    American Express
    American Express
    Debit Cards Finance Financial Services Payments Travel

    0 applies

    5 views

    Other Jobs from American Express

    Senior AI/ML Security Dev Ops Engineer

    Bengaluru, India Remote Hybrid

    Engineer II - Java + React

    Bengaluru, India Remote Hybrid

    Java Backend Engineer

    Gurugram, India Bengaluru, India

    Senior Engineer II

    Gurugram, India Remote Hybrid

    Manager II - Project Management

    Gurugram, India Remote Hybrid

    Senior Engineer II

    Chennai, India Remote Hybrid

    There are more than 50,000 engineering jobs:

    Subscribe to membership and unlock all jobs

    Engineering Jobs

    60,000+ jobs from 4,500+ well-funded companies

    Updated Daily

    New jobs are added every day as companies post them

    Refined Search

    Use filters like skill, location, etc to narrow results

    Become a member

    🥳🥳🥳 452 happy customers and counting...

    Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

    To try it out

    For active job seekers

    For those who are passive looking

    Cancel anytime

    Frequently Asked Questions

    • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
    • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
    • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
    • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
    • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
    • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
    • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

    What Fellow Engineers Say

    Sid avatar
    Sid
    Very nice portal for searching jobs in this rough market.
    Mar 6, 2025
    Michael Duran avatar
    Michael Duran
    Software Engineer
    I've been using this job search site for a while now, and it’s honestly one of the best out there! The clean and easy-to-navigate UI makes the whole job-hunting process so much smoother. Plus, the job postings are always up-to-date, so I never feel like I’m wasting time. The cherry on top is the owner—super kind and always quick to respond. Definitely recommend checking it out if you're on the job hunt!
    Aug 21, 2024
    Sai avatar
    Sai
    It’s really great website for finding jobs based on skills it’s really helpful give a go
    Aug 21, 2024
    Adinadh avatar
    Adinadh
    What I like most about Echo Jobs is how easy it is to use. The platform helps me quickly find jobs that match my skills and interests, thanks to its great recommendations and filters. Yes, I would definitely recommend Echo Jobs to a friend. It makes job searching simple and efficient, making it a great tool for anyone looking for a new job.
    Jul 23, 2024
    As a student navigating the job market, I've found LinkedIn increasingly frustrating due to numerous fake postings by consultancies. In contrast, this job posting website has been a game-changer for me. It offers genuine opportunities and a straightforward application process, making it much easier to find and apply for real jobs. Highly recommend it to fellow students seeking reliable job listings!
    Jul 16, 2024
    Cliff Gor avatar
    Echo Jobs has been exceptional in my job hunt where it provides one platform to job hunt and I don't have to open 10 websites just to look for a job. It has also helped me focus much on the job skill and the location filtering out the onsite jobs and remote ones. The only feature that I would request is to display fully remote jobs that are not restricted to a country since the one available shows ie, Remote, US yet. But if it could show remote only, that would be helpful not only to me but to other people applying for full remote and not tied to only US candidates
    Apr 22, 2024
    I found EchoJobs in 2022, and I love it. It has a lot of remote jobs. It's exclusive to software and technology jobs (helpful for devs like me). What I like the most are its filters and its API. If you're a tech professional seeking remote work, I highly recommend giving it a try to EchoJobs.
    Mar 4, 2024
    Would definitely recommend it! Excellent product, dedicated founder, Jobs are easier to find. Congrats 🎉 to the entire team!
    Mar 3, 2024
    Brandon Banks avatar
    Brandon Banks
    Echo Jobs is really impressive. It provides a great user experience with an ability to quickly search through the many job postings. There is an impressive amount of jobs here and it is quickly updated. The details in the each job posting is helpful when determining if it is worth pursuing. I would highly recommend using Echo Jobs to find the next step in your career.
    Mar 2, 2024
    Tyler Young avatar
    Tyler Young
    tylerayoung.com
    Best wishes with EchoJobs—it's become my favorite job board overnight!
    Dec 16, 2023
    Simply put, it's the most up to date tech jobs aggregator I’ve found. I'm like... "I don't have to check 10+ jobs boards daily just to see if there's a new job listing? sign me up!" The filters are also quite helpful! The UI is very clean and straightforward. Love it!
    Oct 5, 2023