← Back to jobs

eTeam Logo
API Security Engineer

eTeam

 

Tucson, AZ, USA

Posted On: 11 days ago
Experience: 8+ years
Availability: Hybrid
Openings: 1
Category: API Security Engineer
Tenure: No Preference/Any
Related Jobs

No related jobs found

Description

You will design and enforce security practices for RESTful and GraphQL APIs across cloud-native and containerized environments.

This role is on-site.

Responsibilities

  • Analyze and secure APIs across internal, partner, and third-party integrations.
  • Implement OAuth, OpenID Connect, JWT, and API key-based authentication and authorization.
  • Build and enforce security policies through API gateways such as Apigee, Kong, MuleSoft, AWS API Gateway, or Azure API Management.
  • Perform API threat modeling, risk assessments, and penetration testing.
  • Monitor for API abuse, misconfiguration, broken access control, and excessive data exposure.

Required Skills

  • 8–10 years of experience in Information Security, AppSec, or Cloud Security.
  • 3–5 years of specialized experience in API security.
  • Proficiency with OAuth, OpenID Connect, JWT, mTLS, and HMAC signatures.
  • Strong experience with API gateway platforms and WAF configuration.
  • Deep understanding of OWASP Top 10 (API & Web) vulnerabilities and remediation.
  • Knowledge of DevSecOps, security automation, and CI/CD tools.
  • Experience with cloud-native security (AWS, GCP, Azure) and container security (Docker, Kubernetes).
  • Scripting skills in Python, Shell, or JavaScript for automation.

Preferred Skills

  • Security certifications such as CISSP, CSSLP, GWAPT, or APIsec.
  • Experience with runtime protection, API abuse detection, or zero-day threat analysis.

Education

Any Graduate

Related Jobs

No related jobs found

← Back to jobs