API Security Engineer
New Today
We are seeking a skilled and security-focused API Security Engineer to join our DevSecOps and Application Security team. This role will focus on securing API ecosystems across multiple environments, ensuring that all API integrations follow security best practices and meet industry compliance standards. Key Responsibilities:
Design, implement, and enforce security controls for public, private, and partner APIs.
Perform API threat modeling, vulnerability assessments, and security testing (including OWASP API Top ).
Work closely with development and DevOps teams to integrate API security controls into CI/CD pipelines.
Lead API security reviews and provide secure coding guidance to developers.
Monitor API traffic and behavior to detect anomalies, abuse, or unauthorized access.
Automate API security testing with tools such as Postman, Burp Suite, OWASP ZAP, or APIsec.
Implement and manage API gateways and identity access mechanisms (, , OpenID Connect, JWT).
Collaborate with architects and engineering leads to design secure, scalable API solutions.
Required Qualifications:
Bachelor's degree in Cybersecurity, Computer Science, or a related technical field.
+ years of experience in API security, application security, or DevSecOps.
Deep knowledge of API standards (REST, SOAP, GraphQL) and security protocols.
Strong understanding of authentication, authorization, and encryption methods used in APIs.
Hands-on experience with tools such as APIsec, Postman, Burp Suite, OWASP ZAP, or Fuzzers.
Experience with API gateways (, Kong, Apigee, AWS API Gateway, Azure API Management).
Familiarity with cloud platforms (AWS, Azure, GCP) and container security practices.
Preferred Qualifications:
Working knowledge of DevSecOps and CI/CD integration (, GitHub Actions, GitLab CI, Jenkins).
Experience with infrastructure as code and security-as-code (Terraform, Helm, Kubernetes).
Industry certifications such as API Security Engineer by APIsec University, CSSLP, GWAPT, or CISSP.
Programming/scripting knowledge (, Python, JavaScript, Go) is a plus.
- Location:
- Richmond