Unknown Company

API Security Engineer

brooklyn, oh • Posted 1 weeks ago
Hybrid Full Time IT & Technology

  • Design, deploy, integrate, administer, and optimize enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments
  • Partner with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify risks and implement protections
  • Perform API discovery, inventory, classification, and security posture management
  • Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns
  • Identify API vulnerabilities including BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, misconfigurations, and business-logic abuse
  • Assess APIs against OWASP API Security Top 10 and organizational standards
  • Investigate API security alerts and coordinate remediation
  • Integrate API findings with SIEM, SOAR, vulnerability management, incident response, and ticketing workflows
  • Design, deploy, configure, maintain, troubleshoot, and monitor eBPF-based API security agents and sensors across Linux, containers, Kubernetes, and cloud environments
  • Integrate API security platforms with API gateways, middleware, reverse proxies, ingress controllers, and traffic-management technologies
  • Review gateway policies for authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security weaknesses
  • Deploy, configure, administer, and optimize WAF/WAAP controls; tune policies, custom rules, rate controls, network/IP controls, and application protections
  • Analyze HTTP/HTTPS traffic and security events; investigate application-layer attacks and false positives
  • Onboard applications and APIs to web and API protection services
  • Perform security architecture reviews and threat modeling for APIs, web applications, microservices, gateways, middleware, Kubernetes, containers, and cloud environments
  • Review OAuth 2.0, OIDC, JWT, API key, mTLS, IAM, and RBAC architectures
  • Perform application and API security assessments using manual and automated testing
  • Use intercepting proxies, API clients, command-line tools, SAST, DAST, SCA, and API security testing technologies
  • Integrate security testing into CI/CD and DevSecOps pipelines
  • Develop automation using Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies
  • Automate agent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows
  • Explain vulnerabilities to developers, recommend remediation, and validate fixes
  • Serve as a technical subject-matter expert for enterprise API and application security and implement scalable secure-by-design solutions

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience; or equivalent combination of college education, technical training, industry certifications, and hands‑on cybersecurity experience
  • Associate degree, relevant college coursework, technical certifications, or substantial professional experience may be considered in lieu of a four‑year degree
  • Demonstrated professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering
  • Hands‑on experience deploying and supporting enterprise API security, application security, API gateway, and traffic‑monitoring technologies strongly preferred
  • Hands‑on experience with enterprise API security technologies
  • Experience deploying, configuring, and tuning WAF/WAAP security controls
  • Understanding of eBPF‑based agent/sensor deployment and troubleshooting in Linux, Kubernetes, containerized, and cloud environments
  • Experience integrating API security platforms with enterprise API gateways and API management technologies
  • Strong knowledge of HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures
  • Strong understanding of the OWASP API Security Top 10 and OWASP Top 10
  • Knowledge of OAuth 2.0, OIDC, JWT, API keys, IAM, RBAC, and modern API authorization models
  • Experience performing security architecture reviews and threat modeling
  • Working knowledge of public cloud platforms, Kubernetes, containers, Linux, and microservices
  • Experience with secure SDLC, DevSecOps, CI/CD, vulnerability management, and incident‑response processes
  • Ability to troubleshoot complex integrations across applications, gateways, middleware, networks, security controls, and cloud infrastructure
  • Ability to work directly with developers, architects, API gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams
  • Preferred experience with enterprise‑scale API and application security environments, eBPF‑based API traffic collection, Kubernetes/Linux sensor deployments, cloud‑based API management solutions, enterprise gateway appliances, API gateways, reverse proxies, service meshes, ingress controllers, load‑balancing technologies, SIEM/SOAR platforms, penetration testing, adversarial API/application security assessments, STRIDE, attack trees, and enterprise‑scale security tooling automation
  • Relevant industry certifications are preferred but not required

Core Competencies

Demonstrates expertise in API security, application security, and WAF/WAAP engineering, with a strong focus on integrating security into CI/CD and DevSecOps pipelines. Proficient in analyzing and mitigating API vulnerabilities while collaborating with cross‑functional teams to implement secure solutions across diverse environments.

Highest-signal resume keywords

  • API Security
  • WAF/WAAP Engineering
  • DevSecOps
  • Security Architecture
  • Vulnerability Management

Hard Skills

  • API Discovery
  • API Vulnerability Assessment
  • EBPF‑Based Agent Deployment
  • Security Testing Technologies
  • HTTP/HTTPS Analysis
  • OAuth 2.0
  • JWT
  • REST
  • GraphQL
  • Secure SDLC

Soft Skills

  • Collaboration
  • Communication
  • Problem‑Solving

Industry Keywords

  • OWASP API Security Top 10
  • Cloud Security
  • Microservices
  • Incident Response
  • Threat Modeling

Tools & Technologies

  • SIEM
  • SOAR
  • API Gateways
  • Kubernetes
  • Linux
  • Containers
  • Traffic Management Technologies
  • Command‑Line Tools
  • Intercepting Proxies
  • API Clients

#J-18808-Ljbffr

API Security Engineer in brooklyn at Unknown Company

This position is listed as full time and hybrid.

Back to Job Search