← Back to jobs

eTeam Logo
API Security Engineer

eTeam

 

Seattle, WA, USA

Posted On: 11 days ago
Experience: 8+ years
Availability: Onsite
Openings: 2
Category: API Security Engineer
Tenure: No Preference/Any
Related Jobs

No related jobs found

Description

You will secure RESTful and GraphQL APIs across internal, partner, and third-party integrations in cloud-native, containerized environments.

This role is on-site.

Responsibilities

  • Implement OAuth, OpenID Connect, JWT, and API key-based authentication and authorization.
  • Enforce security policies through API gateways and configure WAF settings.
  • Perform API threat modeling, risk assessments, and penetration testing.
  • Integrate security testing tools into CI/CD pipelines to address OWASP API Top 10 issues.
  • Monitor for API abuse, broken access control, and excessive data exposure.

Required Skills

  • 8–10 years of experience in Information Security, AppSec, or Cloud Security.
  • 3–5 years specifically focused on API security.
  • Proficiency with OAuth, OpenID Connect, JWT, mTLS, and HMAC signatures.
  • Experience with API gateway platforms and WAF configuration.
  • Deep understanding of OWASP Top 10 vulnerabilities and remediation.
  • Knowledge of DevSecOps, security automation, and CI/CD tools.
  • Familiarity with cloud-native environments (AWS, GCP, or Azure).
  • Experience with container security using Docker and Kubernetes.
  • Scripting skills in Python, Shell, or JavaScript for automation.

Preferred Skills

  • Security certifications such as CISSP, CSSLP, GWAPT, or APIsec.
  • Experience with runtime protection, API abuse detection, or SIEM/SOAR tools.

Education

Any Graduate

Related Jobs

No related jobs found

← Back to jobs