American Express Careers

Information Security Specialist – AppSec Engineer

Burgess Hill, United Kingdom
Digital Commerce Technology

Apply Get Referred

Job Description

Don’t just follow digital trends, Help create one. 
 
The Information Security Specialist will be responsible for supporting the Application Security organization, including performing pen tests, threat assessments, and leadership of the Application Security program. The ideal candidate should have experience in detecting security threats in the application space and can intelligently speak to the technical details of the threats. The ability to lead others and provide strategic direction of the program is a must.
 
This role is responsible for acting as a mobile security lead for the Application Security Management program. The Application Security Management team services multiple organizations to scan applications for vulnerabilities and work with application teams to reduce risks within American Express. To support these efforts, the program focuses on developer education, static analysis security testing (SAST), dynamic analysis security testing, (DAST) as well as program governance.
Responsibilities of this position will include but not be limited to the following:
  • Drive excellence in mobile application security by analyzing industry best practices, trends, and with a deep understanding of mobile development
  • Articulate mobile security risks to application teams and senior leadership
  • Develop next generation mobile security capabilities with a focus on customer needs
  • Lead both onshore and offshore team to balance managing emerging threats with operational tasks related to improving security posture
  • Develop and implement continuous service improvements to Application Security Management program
  • Works individually and with teams on both structured and unstructured assignments
  • May participate as subject matter expert or lead multiple moderately complex initiatives

 

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations

Qualifications

Required skills:

  • University degree in Computer Science, similar technical field of study, or equivalent practical experience.
  • Ability to effectively collaborate and communicate with others in English.
  • Significant experience in application penetration testing and tooling, advanced red team, or application security engineering and architecture, preferably in a large and distributed operating environment.
  • Expert knowledge of OWASP Top 10 and ability to articulate web security risks
  • Knowledge of automated DAST, SAST, and RASP tooling is preferred, including but not limited to OWASP Zed Attack Proxy, BURP Suite, Nessus, Metasploit, Postman, HP WebInspect, Qualys, or WhiteHat.
  • Operational understanding of TCP/IP and computer networking. Knowledge of the functions of security technologies such as IPS/IDS, Firewalls, Security Information and Event Management tools, etc a plus.
  • Possession of industry standard certification such as OSCP, CEH, GWAPT, GPEN and/or other relevant penetration testing related certifications a plus.
  • Demonstrated time management skills strong work ethic, attention to detail, able to multitask and have strong communication, time management and problem-solving skills.

Preferred qualifications:

  • A passion for learning new programming languages, software libraries, data layers, and development paradigms.
  • Ability to articulate at least one accomplishment that you are really proud of; what did you do and what was the outcome.
  • Professional Experience with any of the following:
    • Javascript, Java, .NET
    • Amazon Web Services (AWS)
    • Functional programming
    • Multiple data stores (SQL stores, MongoDB, CouchDB, Neo4J, Hadoop, Cassandra, DynamoDB, ElasticSearch, Solr, etc)

Why American Express?

 

There’s a difference between having a job and making a difference.

 

American Express has been making a difference in people’s lives for over 160 years, backing them in moments big and small, granting access, tools, and resources to take on their biggest challenges and reap the greatest rewards.

 

We’ve also made a difference in the lives of our people, providing a culture of learning and collaboration, and helping them with what they need to succeed and thrive. We have their backs as they grow their skills, conquer new challenges, or even take time to spend with their family or community. And when they’re ready to take on a new career path, we’re right there with them, giving them the guidance and momentum into the best future they envision.

 

Because we believe that the best way to back our customers is to back our people.

 

The powerful backing of American Express.

 

Don’t make a difference without it.

Don’t live life without it.

A competitive benefits offering designed to support our employees’ total health and wellbeing, including:

  • Health care scheme
  • Defined contribution pension plan
  • Dental scheme
  • Virtual GP
  • Life assurance
  • Income protection
  • Core holiday allowance with opportunity to buy or sell additional days
  • Car Allowance/Company Car Option
  • A range of flexible benefits to choose from designed to suit your lifestyle: healthcare plan options, health assessments, critical illness coverage, cycle to work, season ticket loans
  • Employee Discount Portal
  • Back up childcare/adultcare
  • Onsite facilities include; Fitness classes, Health Checks, Digital Health Kiosk, Physiotherapy, Healthy Living Nurse, Wellness Studio, Costa Coffee and subsidised staff restaurant

To complete your application please click on the links below. However, if you require any assistance with the completion of this process – or need any reasonable adjustments to be made – then please contact the Recruitment Team on recruitment.support.uk@aexp.com or 00800 83 000038 (for Russia based candidates 810 800 83 000038).

 

ReqID: 18019617
Schedule (Full-Time/Part-Time): Full-time
Date Posted: Dec 7, 2018, 10:34:11 AM
Apply Get Referred