Lead Information Security Consultant - API Security & Governance
Core
Senior subject matter expert responsible for evaluating and improving the organization's API security posture while ensuring API platforms, programs, and practices align with security standards, regulatory requirements, and industry best practices.
Role type
Lead Information Security Consultant (API Security & Governance)
Builds
Enterprise API security standards, controls, governance frameworks, and secure API adoption practices
Domain
Financial Services / API Security & Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
API security principles and frameworks, security standards development, threat modeling, risk assessment, secure API architecture, authentication and authorization, regulatory compliance, stakeholder influence, enterprise security governance
Preferred skills
API gateway technologies (Apigee, AWS API Gateway, GraphQL, Kong, MuleSoft), OWASP API Security Top 10, OAuth 2.0, OpenID Connect, JWT, mTLS, API penetration testing, cloud-native architectures, microservices, security reference architecture design
Technologies
Apigee, AWS API Gateway, GraphQL, Kong, MuleSoft, OAuth 2.0, OpenID Connect, JWT, mTLS
Responsibilities
Lead development of enterprise API security standards and governance practices; Assess and improve API security posture through reviews and risk evaluations; Provide guidance on secure API architecture and lifecycle management; Partner with security, risk, and engineering teams to mitigate API risks; Conduct architecture reviews and threat modeling for API-enabled applications; Define and promote API security best practices and reusable patterns; Influence technology teams to adopt secure-by-design practices; Support regulatory, compliance, and audit activities related to API security
Seniority
Senior, hands-on IC with strategic influence