Director - Security Integration & Engineering-Application Security/ Vulnerability Management
American ExpressAbout the role
Description
ĀAt American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.
As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
American Express is committed to delivering secure, resilient, and scalable technology solutions that protect our customers and enable business growth. As part of this mission, the Director ā Security Integration & Engineering will lead the engineering backbone of enterprise Security Posture Validation. This role drives the strategy, architecture, integration, automation, and sustained operation of the security tooling ecosystem that enables scalable, observable, and enforceable security controls across the software development lifecycle.
The Director will oversee the design and execution of application and code-to-cloud security integrations, ensuring that tooling, automation, and telemetry pipelines generate accurate, defensible insights while supporting developer velocity and regulatory compliance. This leader will collaborate across cybersecurity, engineering, infrastructure, and risk domains to mature posture validation capabilities and align security controls with enterprise standards and global regulatory expectations.
This position demands a strategic and technically deep leader who can operate at both executive and hands-on engineering levels, prioritize operational excellence alongside long-term transformation, and build high-performing teams that deliver measurable risk reduction.
Minimum Qualifications
- Define and execute the multi-year strategy and roadmap for Security Integration & Engineering aligned with enterprise cybersecurity and business priorities.
- Lead the design, integration, automation, and continuous evolution of the enterprise security tooling platform, ensuring reliability, scalability, resiliency, and operational excellence.
- Provide engineering enablement and integration support across security validation domains including:
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Dynamic Application Security Testing (DAST)
- API Security
- Penetration Testing intake and integration
- Infrastructure Vulnerability Management
- External Attack Surface Management (EASM)
- Sensitive Data Element (SDE) detection
- Enterprise vulnerability reporting and executive dashboards
- Ensure normalized data models, scalable automation, exception workflows, SLO enforcement, and audit-ready reporting across security telemetry pipelines.
- Own and maintain the Source Code Security Standard and ensure alignment with enterprise security controls and architecture governance.
- Support regulatory and audit engagements by delivering defensible evidence, metrics, and documentation aligned to global cybersecurity standards.
- Lead response to complex security and operational events, coordinating cross-functiona
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights ā in under 60 seconds.
Apply Now āGenerate Application KitFree account required ā sign up in 30s