API Security Engineer
Core
Design, deploy, and optimize enterprise API and application security controls across cloud, on-premises, and hybrid environments.
Role type
Senior IC API Security Engineer
Builds
Enterprise API security platforms, eBPF agents, WAF/WAAP policies, and automated DevSecOps pipelines
Domain
Cybersecurity, API Security, Cloud Security, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
API security architecture, WAF/WAAP configuration, eBPF agent deployment, API gateway integration, threat modeling, vulnerability assessment, OWASP API Security Top 10, OAuth 2.0/OIDC/JWT, HTTP/HTTPS/TLS, REST/GraphQL/OpenAPI, CI/CD automation, Python/Bash/Go/JavaScript
Preferred skills
Hands-on experience with enterprise API security technologies, eBPF troubleshooting in Kubernetes, DevSecOps pipeline integration
Technologies
eBPF, Kubernetes, Linux, WAF/WAAP, API Gateways, SIEM, SOAR, SAST, DAST, SCA, Python, Bash, PowerShell, Go, JavaScript
Responsibilities
Deploy and tune WAF/WAAP policies to mitigate application-layer attacks; Manage API inventory and classify security posture; Integrate security platforms with API gateways and middleware; Conduct threat modeling and security architecture reviews; Automate security testing and agent deployment in CI/CD pipelines; Investigate security alerts and coordinate remediation with engineering teams
Seniority
Senior, hands-on IC