API Security Architect
Coral Springs, FL - USA
Job Summary
Calling all innovators - find your future at Fiserv.
Were Fiserv a global leader in Fintech and payments and we move money and information in a way that moves the world. We connect financial institutions corporations merchants and consumers to one another millions of times a day - quickly reliably and securely. Any time you swipe your credit card pay through a mobile app or withdraw money from the bank were involved. If you want to make an impact on a global scale come make a difference at Fiserv.
Job Title
API Security ArchitectCalling all innovators find your future at Fiserv.
Were Fiserv a global leader in Fintech and payments and we move money and information in a way that moves the world. We connect financial institutions corporations merchants and consumers to one another millions of times a day quickly reliably and securely. Any time you swipe your credit card pay through a mobile app or withdraw money from the bank were involved. If you want to make an impact on a global scale come make a difference at Fiserv.
About your role:
Our API security function is about 18 months in and growing fast and were looking for an API Security Architect / SME to step into a role with real impact not maintaining someone elses playbook but shaping the strategy and technical direction for a program thats scaling quickly. Youll step into the gap left by the architect who built most of the program owning API design review risk profiling identity and incident/exploitation analysis while helping mature our runtime protection strategy (Traceable) and setting the technical direction going forward.
What youll do:
- Own end-to-end API security architecture design review risk profiling identity and incident/exploitation analysis for a fast-growing high-scale financial-services API ecosystem.
- Set the technical direction for the API security program and mature it from where the previous architect left off rather than simply operating an existing playbook.
- Guide the strategy behind our runtime protection platform (Traceable) partnering with the engineers who handle day-to-day tuning false positives and blocking-mode operations.
- Design identity and access patterns for APIs (OAuth2/OIDC JWT scopes/claims token handling) closing gaps such as overly broad token authorization.
- Lead technical investigation of API security incidents and exploitation attempts translating findings into durable architectural fixes.
- Partner closely with a strong hands-on engineering team (including automation/infrastructure-as-code talent) to turn architectural direction into secure API designs.
- Bring architectural judgment to the table explain the why not just the what across design reviews and cross-team security decisions.
- Responsibilities listed are not intended to be all-inclusive and may be modified as necessary.
Experience youll need to have:
- Significant experience owning API security architecture (or a comparable security architecture discipline) ideally having built or matured a program from the ground up.
- Hands-on personal experience with runtime API protection platforms such as Traceable Salt Security or NoName including configuring tuning and investigating alerts (not just research-based familiarity).
- Demonstrated experience designing identity and access patterns for APIs (OAuth2/OIDC JWT scopes/claims token handling).
- A proven track record investigating and resolving API security incidents or exploitation attempts with real analytical depth.
- Strong architectural judgment the ability to explain the reasoning behind a design decision not just implement it.
- Excellent written and verbal communication skills comfortable working shoulder-to-shoulder with engineering product and security teams.
- Bachelors degree in Computer Science Information Security or a related field or equivalent professional experience.
Experience that would be great to have:
- Experience building automation or CI/CD integration for API security (policy-as-code OpenAPI-based checks pipelines).
- Experience in financial services or another highly regulated industry.
- Relevant certifications (e.g. CISSP CCSP or API/security-specific credentials).
- Experience mentoring engineers or leading cross-functional architecture reviews.
- A background transitioning from hands-on security engineering into an architecture-level SME role.
How youll work:
- This role is on-site Monday through Friday based at our Alpharetta GA cybersecurity tech hub where much of the API security team and engineering support is located. Fiserv considers in-person collaboration essential to onboarding mentorship and stronger productivity. Were open to other Fiserv cybersecurity locations (e.g. Berkeley Heights NJ; Columbus OH; Coral Springs FL) for exceptional candidates.
Travel:
- Approximately 10% travel off-site or to other office locations is expected.
Sponsorship:
- You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including but not limited to F-1 (OPT CPT STEM) H-1B H-2 or TN or any candidate requiring sponsorship now or in the future will not be considered.
Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion national origin gender gender identity sexual orientation age disability protected veteran status or any other category protected by law.
If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process please contact Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiservs Disability Accommodation Policy for additional information.
Note to agencies: Fiserv does not accept resume submissions from agencies outside of existing agreements. Please do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.
Warning about fake job posts: Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.
Salary Range
$128000.00 - $216000.00These pay ranges apply to employees in New Jersey and New York. Pay ranges for employees in other states may differ.
It is unlawful to discriminate against a prospective employee due to the individuals status as a veteran.
For incentive eligible associates the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Companys sole discretion.Thank you for considering employment with Fiserv. Please:
- Apply using your legal name
- Complete the step-by-step profile and attach your resume (either is acceptable both are preferable).
Our commitment to Equal Opportunity:
Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion national origin gender gender identity sexual orientation age disability protected veteran status or any other category protected by law.
If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process please contact. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiservs Disability Accommodation Policy for additional information.
Note to agencies:
Fiserv does not accept resume submissions from agencies outside of existing do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.
Warning about fake job posts:
Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.
Required Experience:
Staff IC
About Company
Fiserv is a global fintech and payments company with solutions for banking, global commerce, merchant acquiring, billing and payments, and point-of-sale.