Staff Security Engineer, API Security
Core
Build a unified API security capability plane integrating linting, gateway visibility, shadow-API detection, and schema security checks into the organization's shared policy-as-code enforcement architecture.
Role type
Staff Security Engineer (API Security)
Builds
End-state API security controls, DAST tooling strategy, and supply-chain security extensions for pipeline access and artifact verification.
Domain
Fintech / API Security / Cloud Infrastructure
Deliverable
production ML models | product features | infrastructure
Required skills
API architecture (REST, GraphQL, AsyncAPI), AuthZ/AuthN (OAuth2, token/session models), API gateway/service-mesh internals (Envoy), policy-as-code, DAST/SAST tooling internals, Python or Go
Preferred skills
AI threat modeling (agentic traffic, AI-driven abuse), cross-team technical leadership, roadmap shaping
Technologies
Python, Go, Envoy, GraphQL, AsyncAPI, OAuth2, DAST, SAST
Responsibilities
Design and consolidate API security capabilities into a shared enforcement engine; execute DAST tooling migration; extend security to pipeline access and artifact consumption; mentor engineers and drive delivery; shape team backlog and prioritize emerging risks.
Seniority
Staff, hands-on IC with technical leadership