> Markdown version of [/jobs/ext/2831348-sr-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2831348-sr-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Application Security Engineer - **Company:** Global Business Travel Group, Inc. - **Location:** Boston, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $104,300.0 - $193,700.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Software System Penetration Testing, Authentication Protocols, Microsoft Azure, Bash Shell, C Sharp (Programming Language), Cloud Computing Security, Code Generation, Computer Programming, Continuous Integration, Cursor (Graphical User Interface Elements), DevOps, Github, Identity and Access Management, Python (Programming Language), Key Management, Network Security, Open Web Application Security, PCI Data Security Standards, Windows PowerShell, Cloud Services, Ansible, Red Team (Cyber Security), Ruby, Secure Coding, Security Information and Event Management, Software Engineering, TypeScript, Circleci, Scripting, Google Cloud, GitHub Copilot, Software Security, Multi-Cloud, Swift (Programming Language), Gitlab, Git, Kotlin, Containerization, Gitlab-ci, Kubernetes, Google Cloud Functions, Free and Open-Source Software, Dart, Bitbucket, Virtual Agents, Functional Programming, Cloudwatch, Objective C++, Terraform, Software Version Control, Data Pipelines, Devsecops, Docker, Key Vault, Jenkins, Static Application Security Testing, Vulnerability Analysis, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** September 10, 2026 - **Apply:** https://dejobs.org/x/x/6C17BE11EA934117A196D5DA45755E88/job/ ## About the Role * 5+ years of professional software development experience with demonstrable expertise in major programming languages (Python, Go, Java, JavaScript/TypeScript); 3+ years of hands-on application security or DevSecOps experience * Strong knowledge of OWASP Top 10 and related secure coding practices; deep understanding of API security, authentication protocols, and secure API design * Strong cloud security expertise with at least one major cloud service provider (AWS, Azure, or GCP); deep understanding of cloud-native security including IAM, network security, encryption, secrets management, and compliance frameworks * Proficiency with CI/CD tools and practical experience with infrastructure-as-code, containerization, and orchestration technologies; strong understanding of network security * Experience with agentic AI programming (AI-driven code generation and autonomous coding agents); deep understanding of risks including hallucinated dependencies, insecure code injection, and governance gaps; ability to help teams mitigate AI-specific security threats * Experience with threat modeling methodologies and risk assessment frameworks; ability to identify and communicate security risks to technical and non-technical audiences * Knowledge of compliance frameworks including PCI-DSS, GDPR, and CCPA; experience establishing or contributing to governance frameworks and guardrails for safe adoption of agentic AI coding tools * Background in penetration testing or red team operations; knowledge of MLSecOps practices including model security, data pipeline protection, and AI/ML supply chain security * Professional security certifications (CISSP, GIAC, OSCP, AWS Security Specialty, Azure Security Engineer, or similar); multi-cloud experience across AWS, Azure, and GCP * Experience in travel, hospitality, or e-commerce industry; open-source contributions or security research publications demonstrating commitment to the security community Technical Skills: * Programming & Scripting: Three or more languages, such as Python, Go, Java, C#, Ruby, JavaScript/TypeScript, Bash, PowerShell, Swift, Kotlin, Objective-C, or Dart, among others * Cloud Platforms: AWS (EC2, ECS, EKS, Lambda, S3, IAM, CloudWatch, GuardDuty), Azure (VMs, AKS, Functions, Key Vault, Sentinel), or GCP (Compute Engine, GKE, Cloud Functions, IAM, Security Command Center) * Security Tools: SAST/DAST scanners, WAF solutions, SIEM platforms, vulnerability scanners, secrets management tools * AI-Assisted Development: GitHub Copilot, Cursor, Claude Code, or similar agentic coding tools * AI Security Tooling: AI/agentic code security scanners and governance platforms * CI/CD: Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, Azure DevOps * Infrastructure: Terraform, Docker, Kubernetes, Helm, Ansible * Version Control: Git, GitHub, GitLab, Bitbucket ## Description * Work with DevOps teams to design, implement, and maintain secure CI/CD pipelines that integrate security testing at every stage of the software development lifecycle * Implement and tune automated security scanning, including SAST, DAST, SCA, and container scanning * Deploy and support API security tools, ensuring findings are consistently reported to a central aggregator * Collaborate with development teams to promote secure coding practices and provide security guidance throughout the development process * Evaluate and help govern the secure use of agentic AI coding tools across engineering teams, establishing guardrails and detection strategies to mitigate risks such as hallucinated dependencies, injected vulnerabilities, and insufficient oversight * Ensure compliance with industry standards relevant to the travel industry, including PCI-DSS, GDPR, and SOC 2 * Build KPI and metrics reporting for application security initiatives and present findings to leadership as needed * Mentor junior engineers and promote a security-first culture across engineering teams, * Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family. * Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals. * Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first. * We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action. * And much more! All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law. Click Here (https://explorer.amexglobalbusinesstravel.com/rs/346-POJ-129/images/Additional%20Disclosures%20in%20Accordance%20with%20the%20LA%20County%20Fair%20Chance%20Ordinance.pdf?version=2) for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance. ## Related Videos - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Dart - a language believed dead, experiences a new bloom](https://www.wearedevelopers.com/videos/442-dart-a-language-believed-dead-experiences-a-new-bloom) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Applying DevOps in Flutter mobile development](https://www.wearedevelopers.com/videos/60-applying-devops-in-flutter-mobile-development) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss)