API Security Engineer
Description
Location
4910 Tiedeman Road, Brooklyn Ohio
API Security Engineer
Role Overview
We are seeking an experienced API & Application Security Engineer with expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling .
This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments.
The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation.
Key Responsibilities
API Security
- Deploy, configure, administer, and optimize enterprise API security platforms and controls .
- Perform continuous API discovery, inventory, classification, and security posture management.
- Identify shadow, rogue, zombie, deprecated, and undocumented APIs .
- Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns.
- Identify vulnerabilities including BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, security misconfigurations, and business-logic abuse .
- Assess APIs against the OWASP API Security Top 10 and organizational security standards.
- Investigate API security alerts and coordinate remediation with engineering and application teams.
- Integrate API security findings with SIEM, SOAR, vulnerability management, incident response, and ticketing workflows .
eBPF Agent / Sensor Deployment
- Design, deploy, configure, and maintain eBPF-based API security agents and sensors across Linux, containerized, Kubernetes, and cloud environments.
- Deploy traffic-collection components to provide visibility into API communications and application behavior.
- Validate operating-system, kernel, container runtime, Kubernetes, networking, and infrastructure prerequisites for eBPF deployments.
- Troubleshoot agent installation, connectivity, permissions, kernel compatibility, traffic visibility, telemetry collection, and performance issues .
- Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact.
- Develop standards and automation for repeatable, enterprise-scale agent deployments.
- Support agent upgrades, configuration changes, health monitoring, troubleshooting, and lifecycle management.
- Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.
API Gateway & Middleware Integrations
- Integrate API security platforms with enterprise API gateways, middleware platforms, reverse proxies, ingress controllers, and traffic-management technologies .
- Work with API proxies, products, policies, routing configurations, authentication mechanisms, and traffic-management controls.
- Configure and validate API traffic visibility between gateways and API security platforms.
- Review gateway policies for authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security-control weaknesses .
- Support integrations with both cloud-native API management platforms and enterprise on-premises gateway appliances .
- Configure and validate traffic forwarding, mirroring, logging, telemetry, or other supported collection mechanisms.
- Troubleshoot connectivity, certificate, traffic collection, API discovery, and integration issues.
- Partner with gateway administrators, middleware engineers, application teams, and platform owners to remediate identified security weaknesses.
Web Application Firewall / WAAP
- Deploy, configure, administer, and optimize enterprise WAF/WAAP security controls .
- Configure and tune WAF policies, custom rules, rate controls, network/IP controls, and application protections.
- Analyze HTTP/HTTPS traffic and security events to identify attacks, anomalous activity, and false positives.
- Investigate SQL injection, XSS, command injection, path traversal, file inclusion, malicious automation, and other application-layer attacks .
- Onboard applications and APIs to enterprise web and API protection services.
- Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic.
- Support security incident investigations using WAF, API, application, and network telemetry.
Security Architecture & Threat Modeling
- Perform security architecture reviews for APIs, web applications, microservices, API gateways, middleware platforms, Kubernetes, containers, and cloud environments .
- Conduct threat modeling to identify attack surfaces, trust boundaries, abuse cases, authorization risks, sensitive-data exposure, and potential control gaps .
- Review authentication and authorization architectures involving OAuth 2.0, OIDC, JWT, API keys, mTLS, IAM, RBAC, and other access-control mechanisms .
- Evaluate end-to-end API traffic flows from clients through edge-security controls, gateways, middleware, microservices, and backend applications.
- Recommend preventive, detective, and compensating security controls based on identified risks.
- Participate in application and infrastructure design reviews and promote secure-by-design engineering practices.
Application Security & Automation
- Perform application and API security assessments using manual and automated testing techniques.
- Apply the OWASP Top 10 and OWASP API Security Top 10 to application and API assessments.
- Perform HTTP/API request and response analysis, vulnerability validation, and remediation verification.
- Work with intercepting proxies, API clients, command-line testing tools, SAST, DAST, SCA, and API security testing technologies .
- Integrate application and API security testing into CI/CD and DevSecOps pipelines .
- Develop automation using Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies .
- Automate agent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows .
- Work directly with developers to explain vulnerabilities, recommend practical remediation, and validate fixes.
Education & Experience
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience; or
- An equivalent combination of college education, technical training, industry certifications, and hands-on cybersecurity experience .
- Candidates with an Associate degree, relevant college coursework, technical certifications, or substantial professional experience in lieu of a four-year degree may be considered.
- Demonstrated professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering .
- Hands-on experience deploying and supporting enterprise API security, application security, API gateway, and traffic-monitoring technologies is strongly preferred.
Required Technical Qualifications
- Hands-on experience with enterprise API security technologies .
- Experience deploying, configuring, and tuning WAF/WAAP security controls .
- Understanding of eBPF-based agent/sensor deployment and troubleshooting in Linux, Kubernetes, containerized, and cloud environments.
- Experience integrating API security platforms with enterprise API gateways and API management technologies .
- Strong knowledge of HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures .
- Strong und