AI/ML Security Engineer
Canada-Ontario-Toronto
American Express
Description
At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career.
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
American Express is seeking an AI/ML Security Engineer with proven strong competence in building implementing AI/ML application security governance and risk management processes. The Security Engineer serves as a domain expert in developing and maintaining comprehensive security requirements across a diverse number of technology stacks. This engineer plays a key role in assessing capabilities including, Generative AI augmented, LLM agentic cybersecurity solutions, emerging risk security technologies and conducting proof-of-concept evaluations to drive innovative capability adoption.
Primary Responsibilities:
- Identify, analyze, and benchmark Generative AI augmented, LLM agentic security solutions in the market.
- Conduct proof-of-concept (PoC) assessments of selected cybersecurity capabilities to validate effectiveness in real-world environments.
- Define security control baselines and evaluation criteria for emerging risk security solutions.
- Evaluate vendor claims, solution architecture, and technical scalability.
- Security testing of GenAI-powered cybersecurity tools.
- Publish detailed reports on the security, compliance, and efficacy of evaluated products.
- Deliver and integrate AI robustness, vulnerability, and stress testing capabilities with MLOps ecosystems.
- Evaluate and assess open-source AI security libraries to build into enterprise AI stress testing and audit capabilities.
- Implement secure model development life cycle practices with automated white box and black box assessments for AI/ML models.
- Consistently enable strong developer and customer experience when liaising with application teams. Uphold Blue Box values when liaising with application teams.
Minimum Qualifications:
- Bachelor’s Degree in Data Science, Statistics, Computer Science or Software Engineering.
- 2+ years' experience with Machine Learning Application Development.
- 3+ years of software engineering experience.
Preferred Qualifications:
- Master’s Degree, PhDs - Data Science, Statistics, Computer Science, or Software Engineering.
- Machine Learning Operation Professional Certifications.
- Demonstrated peer reviewed journal publications, conference presentations, open-source contributions, or similar activities.
- Strong knowledge of Adversarial Robustness techniques and tools for machine learning.
- Strong knowledge of AI Risk Management frameworks and Trustworthy AI practices.
- Hands-on experience with applying statistics, machine learning algorithms (DNN, NLP), big data, and data science toolkits.
- Hands-on experience designing, implementing, and operationalizing high performant AI/ML pipelines and writing production code.
- Hands-on experience with deploying and operationalizing AI/ML models to public cloud environments.
- Hands-on experience evaluating open-source ML tools, frameworks, and libraries.
- Hands-on experience with commonly used data science programming languages, packages, and tools.
- Hands-on experience with MLOps, DevOps, DataOps and API integrations.
- Hands-on experience with AI workload management.
- Hands-on experience with Cloud architecture, design, implementation, and operations.
- Knowledge of application security controls (Web, API, Mobile, AI)
- Knowledge of security domains, common information security management and application frameworks: NIST 800-53, CSF, OWASP ASVS.
- Knowledge of Secure SDLC, Application Security design and DevSecOps.
- Full stack knowledge of application architectures including: Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.
- Experience with Java, JavaScript and mobile application development.
- Knowledge or familiarity with database architectures including Oracle, SQL, DB2 and NoSQL Databases.
- Experience with Cloud security, architecture, design, implementation, and operations.
- Exposure to IAM Controls (OAuth 2.0, OIDC, JWT)
- Strong familiarity with Cryptography Controls (Data at rest, in motion).
- Certification - CISSP, CISM, CSSLP, CISA, CRISC.
Minimum Qualifications
We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:
- Competitive base salaries
- Bonus incentives
- Support for financial-well-being and retirement
- Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- Generous paid parental leave policies (depending on your location)
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities
American Express is committed to providing an inclusive and accessible work environment in which all people who apply for positions or who work for or on behalf of Amex are treated with dignity and respect and are provided with equal treatment with respect to employment, regardless of that person's age, sex, sexual orientation, gender identity, gender expression, race, colour, ancestry, ethnic or national origin, citizenship, religion or creed, marital status, family status, pregnancy, disability, record of offences, social condition or origin, political beliefs, association or activity or other factors prohibited under applicable Human Rights legislation (the “Prohibited Grounds”). If you have a disability and need accommodation, please speak with the Recruiter for more information.
Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.
Job
TechnologiesPrimary Location
Canada-Ontario-TorontoOrganization
A6693 - Security IntegrationSchedule
Full-timeJob Band 30Work Location Options HybridJob Posting
Jun 16, 2025, 5:23:43 PM - Jun 24, 2025, 3:59:00 AMRecruiter
Amy KuriakoseHiring Manager
Shankar Djeyassilane* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Application security Big Data Black box CISA CISM CISSP Cloud Compliance Computer Science CRISC Cryptography CSSLP DevOps DevSecOps Full stack Generative AI Governance IAM Java JavaScript LLMs Machine Learning NIST NIST 800-53 NLP NoSQL Oracle OWASP Risk management SDLC SQL White box
Perks/benefits: Career development Competitive pay Flex hours Health care Insurance Medical leave Parental leave Team events Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.