Enter a job title or keyword

API Security Engineer

Fiserv


Job Location:

Alpharetta, GA - USA

Yearly Salary: USD 128000 - 216000
Posted: 6 August 2026 (28 days ago)
Application Deadline: 1 December 2026
Vacancies: 1 Vacancy

Job Summary

Calling all innovators - find your future at Fiserv.

Were Fiserv a global leader in Fintech and payments and we move money and information in a way that moves the world. We connect financial institutions corporations merchants and consumers to one another millions of times a day - quickly reliably and securely. Any time you swipe your credit card pay through a mobile app or withdraw money from the bank were involved. If you want to make an impact on a global scale come make a difference at Fiserv.

Job Title

API Security Engineer

What does a successful API Security Engineer do at Fiserv

Help build a best-in-class API security program designed for the speed of modern financial services. This role is an opportunity to shape how APIs are secured end-to-end design through runtime using cutting-edge protection technologies and analytics partnering closely with top engineers across product platform and security. You will help turn API telemetry into actionable intelligence reduce risk at scale and raise the bar for secure engineering across the
organization. As an API Security Engineer you will focus on protecting critical API ecosystems by combining secure-by-design guidance runtime protections automation and data-driven governance. You will be hands-on with modern API security capabilities (discovery posture threat detection abuse prevention and response) and help integrate them into the DevSecOps lifecycle so teams can move fast without compromising trust. Youll have the space and support
to help build a program that is measurable automated and resilientone that protects customers and enables teams to deliver with confidence. If you enjoy solving tough security problems working shoulder-to-shoulder with strong engineers and turning complex signals into simple scalable controls this is the role for you.

What youll do:

  • Runtime API protection: Implement and tune runtime controls (e.g. behavioral detection anomaly and abuse prevention bot defense schema enforcement mTLS/OAuth validation rate limiting and threat response) across API gateways service mesh and edge layers.
  • Secure API design guidance: Partner with engineering teams to define and promote secure API patterns (authentication/authorization input validation error handling pagination idempotency versioning and least-privilege access). Provide practical guidance aligned to OWASP API Security Top 10 and modern design standards (OpenAPI/JSON Schema).
  • Automation and integration: Build automation that embeds API security into CI/CD (policy-as1code automated checks against OpenAPI specs secrets scanning SAST/DAST/API testing and runtime-to-ticket workflows). Reduce friction through reusable tooling and self-service guardrails.
  • Data analytics and insights: Develop dashboards and analytics using API telemetry and security findings to measure risk adoption control effectiveness and program outcomes.
  • Translate signals into prioritized actions for engineering and leadership.
  • API security governance: Help define governance for API inventories ownership
  • classification security requirements exception handling and control validation. Drive consistent standards across teams while enabling delivery velocity.
  • DevSecOps lifecycle partnership: Work with product and platform teams to integrate security requirements into backlog planning threat modeling design reviews testing release readiness and incident response.
  • Framework alignment (financial services): Map controls and program outcomes to relevant industry frameworks and expectations (e.g. NIST ISO 27001 PCI DSS FAPI and OWASP guidance).
  • Support audit readiness through clear control documentation and evidence automation.
  • Continuous improvement and innovation: Evaluate emerging technologies and technique for API discovery posture management and runtime detection.
  • Pilot measure and scale what works.

Experience youll need to have:

  • 5 years related IT and cyber protection experience desired.
  • MS preferred or bachelors degree with equivalent work experience
  • Strong foundation in API security concepts: authN/authZ (OAuth2/OIDC JWT) session/token handling scopes/claims rate limiting schema validation and common API abuse patterns.
  • Practical experience with runtime protection in one or more of: API gateways WAF/WAAP service mesh ingress controllers or specialized API security platforms.
  • Experience building automation in CI/CD and cloud-native environments (policy-as-code scripting pipelines Git-based workflows).
  • Ability to use data and telemetry (logs traces metrics) to detect issues tell a clear story and drive priorities.
  • Working knowledge of secure software development and DevSecOps practices and the ability to influence engineering outcomes through partnerships.
  • Comfort collaborating across security SRE platform and application teamsclear communication pragmatic decision-making and strong follow-through.
  • Experience communicating with CISO/CIO/CTO level leadership.
  • CISSP or other professional cyber certification desirable
  • Expert knowledge of and experience with maintaining cyber technologies that can protect operational API systems such as:
  • o Traceable
  • o Salt Security
  • o NoName

What would be great to have:

  • Experience with OpenAPI tooling API testing fuzzing and contract testing.
  • Familiarity with threat modeling approaches and abuse-case analysis for APIs.
  • Experience aligning security controls to financial industry expectations and producing evidence that stands up to audit scrutiny

Sponsorship:

  • You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including but not limited to F-1 (OPT CPT STEM) H-1B H-2 or TN or any candidate requiring sponsorship now or in the future will not be considered.
Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion national origin gender gender identity sexual orientation age disability protected veteran status or any other category protected by law.
If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process please contact Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiservs Disability Accommodation Policy for additional information.
Note to agencies: Fiserv does not accept resume submissions from agencies outside of existing agreements. Please do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.
Warning about fake job posts: Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.

Salary Range

$128000.00 - $216000.00

These pay ranges apply to employees in New Jersey and New York. Pay ranges for employees in other states may differ.

It is unlawful to discriminate against a prospective employee due to the individuals status as a veteran.

For incentive eligible associates the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Companys sole discretion.

Thank you for considering employment with Fiserv. Please:

  • Apply using your legal name
  • Complete the step-by-step profile and attach your resume (either is acceptable both are preferable).

Our commitment to Equal Opportunity:

Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion national origin gender gender identity sexual orientation age disability protected veteran status or any other category protected by law.

If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process please contact. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiservs Disability Accommodation Policy for additional information.

Note to agencies:

Fiserv does not accept resume submissions from agencies outside of existing do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.

Warning about fake job posts:

Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.


Required Experience:

IC


About Company

Company Logo

Fiserv is a global fintech and payments company with solutions for banking, global commerce, merchant acquiring, billing and payments, and point-of-sale.

View Profile View Profile