API Security Engineer
Core
Build a best-in-class API security program for modern financial services, securing APIs end-to-end from design through runtime using protection technologies and analytics.
Role type
Senior IC API Security Engineer
Builds
Runtime API protection controls, secure API design patterns, CI/CD automation, and security governance frameworks for financial institutions.
Domain
Fintech / Payments / API Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
API security concepts (authN/authZ, OAuth2/OIDC, JWT, rate limiting, schema validation), runtime protection (API gateways, WAF/WAAP, service mesh), CI/CD automation (policy-as-code, pipelines), data analytics (logs, traces, metrics), secure software development, DevSecOps practices
Preferred skills
Open API tooling, API testing/fuzzing, threat modeling, financial industry audit alignment
Technologies
Traceable, Salt Security, NoName, Open API, JSON Schema, mTLS, OAuth, JWT, NIST, ISO 27001, PCI DSS, FAPI, OWASP
Responsibilities
Implement and tune runtime API protection controls across gateways and service meshes; Partner with engineering to define secure API design patterns; Build automation embedding security into CI/CD pipelines; Develop dashboards and analytics from API telemetry; Define governance for API inventories and security requirements; Integrate security requirements into backlog planning and release readiness; Map controls to industry frameworks (NIST, ISO, PCI DSS, FAPI)
Seniority
Senior, hands-on IC