Sr. DevSecOps Engineer

Posted Yesterday
Be an Early Applicant
2 Locations
Remote
Senior level
Fintech • Software • Travel • Business Intelligence • Consulting • App development • Big Data Analytics
We are the world’s leading B2B travel platform, providing software and services to companies of all sizes.
The Role
Design, implement, and maintain secure cloud-native CI/CD pipelines with integrated security testing (SAST/DAST/SCA), deploy API security and container scanning, guide developers on secure coding, ensure compliance (PCI-DSS, GDPR, SOC 2), mentor engineers, and support cloud-native security (IAM, encryption, secrets management).
Summary Generated by Built In

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

We are seeking an experienced Senior DevSecOps Engineer to join our dynamic team in the corporate travel industry. This remote position requires a unique blend of application development experience and security expertise to build, secure, and maintain our cloud-native infrastructure. The ideal candidate will have transitioned from application development into DevSecOps, bringing a developer’s mindset to security and operations.

What You'll Do

  • Work with DevOps teams to design, implement, and maintain secure CI/CD pipelines integrating security testing at every stage of the software development lifecycle
  • Implement automated security scanning including SAST, DAST, SCA, container scanning
  • Deploy and support API Security tools
  • Ensure tools consistently report to aggregator
  • Collaborate with development teams to promote secure coding practices and provide security guidance throughout the development process
  • Ensure compliance with industry standards relevant to the travel industry including PCI-DSS, GDPR, and SOC 2
  • Mentor junior engineers and promote a security-first culture across engineering teams

What We’re Looking For

  • 5+ years of professional software development experience with demonstrable expertise in at least one major programming language (Python, Go, Java, JavaScript/TypeScript, or similar)
  • 3+ years of hands-on DevSecOps or Security Engineering experience
  • Strong knowledge of OWASP
  • Strong cloud security expertise with at least one major cloud service provider (AWS, Azure, or GCP)
  • Strong knowledge of API Security and associated security tools (Salt, Akamai, Cloudflare, or similar)
  • Deep understanding of cloud-native security including IAM, network security, encryption, secrets management, and compliance frameworks
  • Proficiency with CI/CD tools (Jenkins, GitLab CI, GitHub Actions, CircleCI, or similar)
  • Experience with Infrastructure as Code tools (Terraform, CloudFormation, Ansible, or similar)
Preferred Qualifications
  • Experience in the travel, hospitality, or e-commerce industry
  • Multi-cloud experience across AWS, Azure, and GCP
  • Professional security certifications (CISSP, CEH, OSCP, AWS Security Specialty, Azure Security Engineer, or similar)
  • Knowledge of compliance frameworks specific to payment processing and international data protection (PCI-DSS, GDPR, CCPA)
  • Background in penetration testing or red team operations
  • Experience with threat modeling methodologies (STRIDE, PASTA, OCTAVE) and risk assessment frameworks
  • Knowledge of MLSecOps practices including model security, data pipeline protection, and AI/ML supply chain security
  • Open-source contributions or security research publications

Technical Skills

  • Programming & Scripting: Python, Go, Bash, PowerShell, JavaScript/TypeScript
  • Cloud Platforms: AWS (EC2, ECS, EKS, Lambda, S3, IAM, CloudWatch, GuardDuty) or Azure (VMs, AKS, Functions, Key Vault, Sentinel) or GCP (Compute Engine, GKE, Cloud Functions, IAM, Security Command Center)
  • Security Tools: SAST/DAST scanners, WAF solutions, SIEM platforms, vulnerability scanners, secrets management tools
  • CI/CD: Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, Azure DevOps
  • Infrastructure: Terraform, Docker, Kubernetes, Helm, Ansible
  • Version Control: Git, GitHub, GitLab, Bitbucket

     

Location

India

     

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Click Here for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;" please apply anyway. You may be exactly the person we’re looking for!

Skills Required

  • 5+ years of professional software development experience with expertise in at least one major programming language (Python, Go, Java, JavaScript/TypeScript, or similar)
  • 3+ years of hands-on DevSecOps or Security Engineering experience
  • Strong knowledge of OWASP
  • Strong cloud security expertise with at least one major cloud service provider (AWS, Azure, or GCP)
  • Strong knowledge of API Security and associated security tools (Salt, Akamai, Cloudflare, or similar)
  • Deep understanding of cloud-native security including IAM, network security, encryption, secrets management, and compliance frameworks
  • Proficiency with CI/CD tools (Jenkins, GitLab CI, GitHub Actions, CircleCI, or similar)
  • Experience with Infrastructure as Code tools (Terraform, CloudFormation, Ansible, or similar)
  • Proficiency with programming and scripting languages (Python, Go, Bash, PowerShell, JavaScript/TypeScript)
  • Experience with container and orchestration technologies (Docker, Kubernetes, Helm)
  • Experience with security scanners and tools (SAST, DAST, SCA, container scanning, WAF, SIEM, vulnerability scanners, secrets management)
  • Experience in the travel, hospitality, or e-commerce industry
  • Multi-cloud experience across AWS, Azure, and GCP
  • Professional security certifications (CISSP, CEH, OSCP, AWS Security Specialty, Azure Security Engineer, or similar)
  • Knowledge of compliance frameworks specific to payment processing and international data protection (PCI-DSS, GDPR, CCPA)
  • Background in penetration testing or red team operations
  • Experience with threat modeling methodologies (STRIDE, PASTA, OCTAVE) and risk assessment frameworks
  • Knowledge of MLSecOps practices including model security, data pipeline protection, and AI/ML supply chain security
  • Open-source contributions or security research publications

American Express Global Business Travel Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about American Express Global Business Travel and has not been reviewed or approved by American Express Global Business Travel.

  • Healthcare Strength Healthcare coverage is described as comprehensive, including medical, dental, vision, life, disability, and access to physician consultations in some cases. Emotional and mental-health resources are also highlighted, including counseling, crisis support, and webinars for employees and immediate families.
  • Leave & Time Off Breadth Time off and flexibility options are portrayed as broad, including PTO that combines vacation and sick time, with potential to purchase additional vacation in some locations. Flexible arrangements are described as available in parts of the organization, including remote work and options like part-time schedules, job sharing, and sabbaticals where supported.
  • Retirement Support Retirement support is positioned as available through locally competitive programs, including a U.S. 401(k) with employer matching after a service period. Ownership-related benefits are also present via an employee stock purchase plan offered in many countries.

American Express Global Business Travel Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Jersey City, NJ
18,000 Employees
Year Founded: 2014

What We Do

American Express Global Business (Amex GBT) is the world’s leading B2B travel platform, providing software and services to manage travel, expenses, meetings & events for companies of all sizes. Our solutions include: Egencia: the leading software as service travel platform for small and medium-sized enterprises (SMEs). Ovation: the solution synonymous with high-touch travel service. The Neo Technology Group: a technology-focused team that builds cloud-based travel solutions. Meetings & Events: providing solutions for a single meeting or an entire meetings portfolio. Global Business Consulting: customized services to help clients optimize their travel program.

Why Work With Us

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success. Ready to explore a career path? Start your journey with us - apply now!

Gallery

Gallery

Similar Jobs

BETSOL Logo BETSOL

Senior Cloud Engineer

Cloud • Information Technology
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
775 Employees
Remote
India
185 Employees

Micron Technology Logo Micron Technology

Engineer Manufacturing

Artificial Intelligence • Hardware • Information Technology • Machine Learning
Remote
Gujarat, IND
45000 Employees

Optum Logo Optum

Data Scientist

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote
India
160000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account