Senior API Security Engineer

Motion Recruitment
AZ, United States
Full-time

Role Overview :

We are seeking a Senior API Security Engineer with extensive technical expertise and leadership skills to contribute to enterprise-wide API security initiatives at our client.

The ideal candidate will serve as a subject matter expert in API security, performing threat modeling, managing, monitoring, and reporting on API security risk reduction.

This role also includes evangelizing API security principles and controls, providing technical advice to application teams, and ensuring that API security standards are maintained across the organization.

Primary Responsibilities :

  • Governance & Implementation : Perform ongoing governance and follow-up with API owners to ensure the implementation of threat-based security requirements.
  • Security Standards Development : Develop, deliver, and maintain up-to-date API security standard requirements and design patterns.
  • Vulnerability Assessment : Validate the implementation of API security controls against outputs from vulnerability testing tools to ensure auditability and verifiability.
  • Technical Advisory : Act as a technical advisor on API security to application development teams.
  • Security Evangelism : Advocate for API security design principles and best practices across the organization.
  • Subject Matter Expertise : Be recognized as an API security subject matter expert within the company.

Required Security and Technical Experience :

  • API Development & Security : Hands-on experience in developing and securing web APIs and web applications, including REST, SOAP, and gRPC.
  • Security Testing : Direct experience with security testing of web services and APIs.
  • Threat Modeling : Experience leading threat modeling exercises for applications and services.
  • Risk Management & Security Architecture : Strong understanding of risk management, security architecture, and secure software development lifecycle (SDLC) practices.
  • Identity & Access Management : Deep knowledge of API identity and access management controls, such as OAuth 2.0, OIDC, and JWT.
  • Cryptography : Solid understanding of cryptography controls, including data at rest, in motion, and in use.
  • Industry Standards : Familiarity with industry standards and frameworks, including NIST 800-53, NIST CSF, OWASP, and SANS Top 25.
  • Programming Experience : Experience with Java, JavaScript, and mobile application development.
  • Database Knowledge : Familiarity with database architectures, including Oracle, SQL, and NoSQL databases.

Desired Skills :

  • Mentorship : Experience mentoring teams on application security and secure development practices.
  • DevOps & Cloud : Experience with DevOps processes in a Cloud / SaaS environment.
  • Cloud Security : Experience architecting, securing, and operating in one or more public cloud environments, such as AWS, Google App Engine, Azure, and Oracle Cloud.
  • Service-Oriented Architectures : Experience with service-oriented architectures and web services security.
  • Emerging Programming Languages : Proficiency with one or more emerging programming languages, such as Go or Rust.
  • Certifications : Information security professional certifications, such as SANS GIAC or CISSP, are encouraged.

This position offers a unique opportunity to work on cutting-edge API security initiatives at our client, with a chance to influence and shape the organization’s security posture.

If you have a passion for API security and meet the qualifications listed above, we encourage you to apply.

15 days ago
Related jobs
Promoted
Raytheon
Tucson, Arizona

Experience in the fields of System Security Engineering, computer technology reverse engineering, Anti Tamper, cybersecurity, or embedded security. Advanced Degree in Electrical Engineering, Systems Engineering, Mechanical Engineering, Engineering Mechanics, Computer Science, Engineering Science, Bu...

Promoted
Axway
Scottsdale, Arizona

Senior Cloud Security Engineer. The Axway Cloud Security team is critical to delivering secure cloud services to customers in government, banking, financial services, healthcare, life sciences, manufacturing, and other security-conscious industries. The Cloud Security Engineer will engage with inter...

Promoted
VirtualVocations
Tempe, Arizona

A company is looking for a Senior Application Security Engineer, AWS Generative AI Security. ...

Promoted
GeoLogics Corporation
Scottsdale, Arizona

Senior Advanced Systems Engineer. Geologics is currentlyseeking A Senior Advanced System Engineer out of our Scottsdale, AZ facility. Requires a Bachelor's degree in Systems Engineering, or a related Science, Engineering or Mathematics field. Department of Defense Secret security clearance is requir...

Promoted
VirtualVocations
Phoenix, Arizona

A company is looking for a Senior Software Engineer, Restful API's/Mobile. NET and Visual StudioExperience with RESTful API design and developmentWorking experience with deployment and maintenance of Postgres or similar SQL databases. ...

Promoted
GeoLogics Corporation
Scottsdale, Arizona

Senior Principal Systems Engineer with ACTIVE Secret Security Clearance (US Citizenship REQUIRED). Requires a Bachelor's degree in Systems Engineering, or a related Science, Engineering or Mathematics field. Geologics is currently seeking a Senior Principal Systems Engineer in our Scottsdale, AZ fac...

Promoted
VirtualVocations
Phoenix, Arizona

A company is looking for a Senior Cloud Security Engineer to enhance the security posture of their cloud infrastructure. ...

Promoted
Axway
Scottsdale, Arizona

Senior Cloud Security Engineer. The Axway Cloud Security team is critical to delivering secure cloud services to customers in government, banking, financial services, healthcare, life sciences, manufacturing, and other security-conscious industries. Perform architectural reviews of cloud solutions, ...

AMEX
Phoenix, Arizona

Collaborate with the rest of the API/Orchestration engineering team, the UI engineering team, quality engineering tam and product management to build scalable high performant quality API and Orchestration solutions. Enterprise Cloud offers dynamic rapid code-to-development models and services such a...

RTX (Formerly Raytheon Technologies)
Tucson, Arizona

Advanced Degree in Electrical Engineering, Systems Engineering, Mechanical Engineering, Engineering Mechanics, Computer Science, Engineering Science, Business Administration, and/or Robotics. Senior Principal Systems Security Engineer - Anti-Tamper. We want you to fulfill a systems engineer role dev...