- Design, deploy, integrate, administer, and optimize enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments
- Partner with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify risks and implement protections
- Perform API discovery, inventory, classification, and security posture management
- Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns
- Identify API vulnerabilities including BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, misconfigurations, and business-logic abuse
- Assess APIs against OWASP API Security Top 10 and organizational standards
- Investigate API security alerts and coordinate remediation
- Integrate API findings with SIEM, SOAR, vulnerability management, incident response, and ticketing workflows
- Design, deploy, configure, maintain, troubleshoot, and monitor eBPF-based API security agents and sensors across Linux, containers, Kubernetes, and cloud environments
- Integrate API security platforms with API gateways, middleware, reverse proxies, ingress controllers, and traffic-management technologies
- Review gateway policies for authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security weaknesses
- Deploy, configure, administer, and optimize WAF/WAAP controls; tune policies, custom rules, rate controls, network/IP controls, and application protections
- Analyze HTTP/HTTPS traffic and security events; investigate application-layer attacks and false positives
- Onboard applications and APIs to web and API protection services
- Perform security architecture reviews and threat modeling for APIs, web applications, microservices, gateways, middleware, Kubernetes, containers, and cloud environments
- Review OAuth 2.0, OIDC, JWT, API key, mTLS, IAM, and RBAC architectures
- Perform application and API security assessments using manual and automated testing
- Use intercepting proxies, API clients, command-line tools, SAST, DAST, SCA, and API security testing technologies
- Integrate security testing into CI/CD and DevSecOps pipelines
- Develop automation using Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies
- Automate agent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows
- Explain vulnerabilities to developers, recommend remediation, and validate fixes
- Serve as a technical subject-matter expert for enterprise API and application security and implement scalable secure-by-design solutions
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience; or equivalent combination of college education, technical training, industry certifications, and hands‑on cybersecurity experience
- Associate degree, relevant college coursework, technical certifications, or substantial professional experience may be considered in lieu of a four‑year degree
- Demonstrated professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering
- Hands‑on experience deploying and supporting enterprise API security, application security, API gateway, and traffic‑monitoring technologies strongly preferred
- Hands‑on experience with enterprise API security technologies
- Experience deploying, configuring, and tuning WAF/WAAP security controls
- Understanding of eBPF‑based agent/sensor deployment and troubleshooting in Linux, Kubernetes, containerized, and cloud environments
- Experience integrating API security platforms with enterprise API gateways and API management technologies
- Strong knowledge of HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures
- Strong understanding of the OWASP API Security Top 10 and OWASP Top 10
- Knowledge of OAuth 2.0, OIDC, JWT, API keys, IAM, RBAC, and modern API authorization models
- Experience performing security architecture reviews and threat modeling
- Working knowledge of public cloud platforms, Kubernetes, containers, Linux, and microservices
- Experience with secure SDLC, DevSecOps, CI/CD, vulnerability management, and incident‑response processes
- Ability to troubleshoot complex integrations across applications, gateways, middleware, networks, security controls, and cloud infrastructure
- Ability to work directly with developers, architects, API gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams
- Preferred experience with enterprise‑scale API and application security environments, eBPF‑based API traffic collection, Kubernetes/Linux sensor deployments, cloud‑based API management solutions, enterprise gateway appliances, API gateways, reverse proxies, service meshes, ingress controllers, load‑balancing technologies, SIEM/SOAR platforms, penetration testing, adversarial API/application security assessments, STRIDE, attack trees, and enterprise‑scale security tooling automation
- Relevant industry certifications are preferred but not required
Core Competencies
Demonstrates expertise in API security, application security, and WAF/WAAP engineering, with a strong focus on integrating security into CI/CD and DevSecOps pipelines. Proficient in analyzing and mitigating API vulnerabilities while collaborating with cross‑functional teams to implement secure solutions across diverse environments.
Highest-signal resume keywords
- API Security
- WAF/WAAP Engineering
- DevSecOps
- Security Architecture
- Vulnerability Management
Hard Skills
- API Discovery
- API Vulnerability Assessment
- EBPF‑Based Agent Deployment
- Security Testing Technologies
- HTTP/HTTPS Analysis
- OAuth 2.0
- JWT
- REST
- GraphQL
- Secure SDLC
Soft Skills
- Collaboration
- Communication
- Problem‑Solving
Industry Keywords
- OWASP API Security Top 10
- Cloud Security
- Microservices
- Incident Response
- Threat Modeling
Tools & Technologies
- SIEM
- SOAR
- API Gateways
- Kubernetes
- Linux
- Containers
- Traffic Management Technologies
- Command‑Line Tools
- Intercepting Proxies
- API Clients
API Security Engineer in brooklyn at Unknown Company
This position is listed as full time and hybrid.