API Security Engineer

Remote
CompanyKeyBank
LocationBrooklyn, OH, Remote, United States
CategorySecurity
Seniority-
WorkplaceRemote
Posted2026-09-15
Viaworkday

Description

Location

4910 Tiedeman Road, Brooklyn Ohio

API Security Engineer

Role Overview

We are seeking an experienced  API & Application Security Engineer with expertise in  API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling .

This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments.

The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation.

Key Responsibilities

API Security

  • Deploy, configure, administer, and optimize enterprise  API security platforms and controls .
  • Perform continuous API discovery, inventory, classification, and security posture management.
  • Identify  shadow, rogue, zombie, deprecated, and undocumented APIs .
  • Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns.
  • Identify vulnerabilities including  BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, security misconfigurations, and business-logic abuse .
  • Assess APIs against the  OWASP API Security Top 10  and organizational security standards.
  • Investigate API security alerts and coordinate remediation with engineering and application teams.
  • Integrate API security findings with  SIEM, SOAR, vulnerability management, incident response, and ticketing workflows .

eBPF Agent / Sensor Deployment

  • Design, deploy, configure, and maintain  eBPF-based API security agents and sensors  across Linux, containerized, Kubernetes, and cloud environments.
  • Deploy traffic-collection components to provide visibility into API communications and application behavior.
  • Validate operating-system, kernel, container runtime, Kubernetes, networking, and infrastructure prerequisites for eBPF deployments.
  • Troubleshoot  agent installation, connectivity, permissions, kernel compatibility, traffic visibility, telemetry collection, and performance issues .
  • Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact.
  • Develop standards and automation for repeatable, enterprise-scale agent deployments.
  • Support agent upgrades, configuration changes, health monitoring, troubleshooting, and lifecycle management.
  • Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.

API Gateway & Middleware Integrations

  • Integrate API security platforms with  enterprise API gateways, middleware platforms, reverse proxies, ingress controllers, and traffic-management technologies .
  • Work with API proxies, products, policies, routing configurations, authentication mechanisms, and traffic-management controls.
  • Configure and validate API traffic visibility between gateways and API security platforms.
  • Review gateway policies for  authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security-control weaknesses .
  • Support integrations with both  cloud-native API management platforms and enterprise on-premises gateway appliances .
  • Configure and validate traffic forwarding, mirroring, logging, telemetry, or other supported collection mechanisms.
  • Troubleshoot connectivity, certificate, traffic collection, API discovery, and integration issues.
  • Partner with gateway administrators, middleware engineers, application teams, and platform owners to remediate identified security weaknesses.

Web Application Firewall / WAAP

  • Deploy, configure, administer, and optimize enterprise  WAF/WAAP security controls .
  • Configure and tune WAF policies, custom rules, rate controls, network/IP controls, and application protections.
  • Analyze HTTP/HTTPS traffic and security events to identify attacks, anomalous activity, and false positives.
  • Investigate  SQL injection, XSS, command injection, path traversal, file inclusion, malicious automation, and other application-layer attacks .
  • Onboard applications and APIs to enterprise web and API protection services.
  • Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic.
  • Support security incident investigations using WAF, API, application, and network telemetry.

Security Architecture & Threat Modeling

  • Perform security architecture reviews for  APIs, web applications, microservices, API gateways, middleware platforms, Kubernetes, containers, and cloud environments .
  • Conduct threat modeling to identify  attack surfaces, trust boundaries, abuse cases, authorization risks, sensitive-data exposure, and potential control gaps .
  • Review authentication and authorization architectures involving  OAuth 2.0, OIDC, JWT, API keys, mTLS, IAM, RBAC, and other access-control mechanisms .
  • Evaluate end-to-end API traffic flows from clients through edge-security controls, gateways, middleware, microservices, and backend applications.
  • Recommend preventive, detective, and compensating security controls based on identified risks.
  • Participate in application and infrastructure design reviews and promote  secure-by-design  engineering practices.

Application Security & Automation

  • Perform application and API security assessments using manual and automated testing techniques.
  • Apply the  OWASP Top 10 and OWASP API Security Top 10  to application and API assessments.
  • Perform HTTP/API request and response analysis, vulnerability validation, and remediation verification.
  • Work with  intercepting proxies, API clients, command-line testing tools, SAST, DAST, SCA, and API security testing technologies .
  • Integrate application and API security testing into  CI/CD and DevSecOps pipelines .
  • Develop automation using  Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies .
  • Automate  agent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows .
  • Work directly with developers to explain vulnerabilities, recommend practical remediation, and validate fixes.

Education & Experience

  • Bachelor’s degree  in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience;  or
  • An equivalent combination of  college education, technical training, industry certifications, and hands-on cybersecurity experience .
  • Candidates with an  Associate degree, relevant college coursework, technical certifications, or substantial professional experience  in lieu of a four-year degree may be considered.
  • Demonstrated professional experience in  API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering .
  • Hands-on experience deploying and supporting  enterprise API security, application security, API gateway, and traffic-monitoring technologies  is strongly preferred.

Required Technical Qualifications

  • Hands-on experience with  enterprise API security technologies .
  • Experience deploying, configuring, and tuning  WAF/WAAP security controls .
  • Understanding of  eBPF-based agent/sensor deployment and troubleshooting  in Linux, Kubernetes, containerized, and cloud environments.
  • Experience integrating API security platforms with  enterprise API gateways and API management technologies .
  • Strong knowledge of  HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures .
  • Strong und