API Security Engineer
Brooklyn, NY - USA
Job Summary
Location:
4910 Tiedeman Road Brooklyn OhioAPI Security Engineer
Role Overview
We are seeking an experiencedAPI & Application Security Engineer with expertise inAPI security Web Application Firewall (WAF/WAAP) application security API gateway integrations security architecture and threat modeling.
This role is responsible for designing deploying integrating administering and optimizing enterprise API and application security controls across cloud on-premises containerized and hybrid environments.
The engineer will partner directly with application development security architecture DevOps/SRE cloud network SOC middleware and platform engineering teams to identify security risks implement protections investigate threats automate security processes and drive remediation.
Key Responsibilities
API Security
- Deploy configure administer and optimize enterpriseAPI security platforms and controls.
- Perform continuous API discovery inventory classification and security posture management.
- Identifyshadow rogue zombie deprecated and undocumented APIs.
- Analyze API traffic endpoints parameters authentication mechanisms sensitive-data flows and behavioral patterns.
- Identify vulnerabilities includingBOLA/IDOR broken authentication and authorization injection SSRF excessive data exposure security misconfigurations and business-logic abuse.
- Assess APIs against theOWASP API Security Top 10and organizational security standards.
- Investigate API security alerts and coordinate remediation with engineering and application teams.
- Integrate API security findings withSIEM SOAR vulnerability management incident response and ticketing workflows.
eBPF Agent / Sensor Deployment
- Design deploy configure and maintaineBPF-based API security agents and sensorsacross Linux containerized Kubernetes and cloud environments.
- Deploy traffic-collection components to provide visibility into API communications and application behavior.
- Validate operating-system kernel container runtime Kubernetes networking and infrastructure prerequisites for eBPF deployments.
- Troubleshootagent installation connectivity permissions kernel compatibility traffic visibility telemetry collection and performance issues.
- Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact.
- Develop standards and automation for repeatable enterprise-scale agent deployments.
- Support agent upgrades configuration changes health monitoring troubleshooting and lifecycle management.
- Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.
API Gateway & Middleware Integrations
- Integrate API security platforms withenterprise API gateways middleware platforms reverse proxies ingress controllers and traffic-management technologies.
- Work with API proxies products policies routing configurations authentication mechanisms and traffic-management controls.
- Configure and validate API traffic visibility between gateways and API security platforms.
- Review gateway policies forauthentication authorization rate limiting TLS/mTLS data exposure routing and security-control weaknesses.
- Support integrations with bothcloud-native API management platforms and enterprise on-premises gateway appliances.
- Configure and validate traffic forwarding mirroring logging telemetry or other supported collection mechanisms.
- Troubleshoot connectivity certificate traffic collection API discovery and integration issues.
- Partner with gateway administrators middleware engineers application teams and platform owners to remediate identified security weaknesses.
Web Application Firewall / WAAP
- Deploy configure administer and optimize enterpriseWAF/WAAP security controls.
- Configure and tune WAF policies custom rules rate controls network/IP controls and application protections.
- Analyze HTTP/HTTPS traffic and security events to identify attacks anomalous activity and false positives.
- InvestigateSQL injection XSS command injection path traversal file inclusion malicious automation and other application-layer attacks.
- Onboard applications and APIs to enterprise web and API protection services.
- Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic.
- Support security incident investigations using WAF API application and network telemetry.
Security Architecture & Threat Modeling
- Perform security architecture reviews forAPIs web applications microservices API gateways middleware platforms Kubernetes containers and cloud environments.
- Conduct threat modeling to identifyattack surfaces trust boundaries abuse cases authorization risks sensitive-data exposure and potential control gaps.
- Review authentication and authorization architectures involvingOAuth 2.0 OIDC JWT API keys mTLS IAM RBAC and other access-control mechanisms.
- Evaluate end-to-end API traffic flows from clients through edge-security controls gateways middleware microservices and backend applications.
- Recommend preventive detective and compensating security controls based on identified risks.
- Participate in application and infrastructure design reviews and promotesecure-by-designengineering practices.
Application Security & Automation
- Perform application and API security assessments using manual and automated testing techniques.
- Apply theOWASP Top 10 and OWASP API Security Top 10to application and API assessments.
- Perform HTTP/API request and response analysis vulnerability validation and remediation verification.
- Work withintercepting proxies API clients command-line testing tools SAST DAST SCA and API security testing technologies.
- Integrate application and API security testing intoCI/CD and DevSecOps pipelines.
- Develop automation usingPython Bash PowerShell Go JavaScript APIs or similar technologies.
- Automateagent deployment configuration validation API onboarding security testing reporting alert enrichment and vulnerability-management workflows.
- Work directly with developers to explain vulnerabilities recommend practical remediation and validate fixes.
Education & Experience
- Bachelors degreein Cybersecurity Computer Science Information Technology Information Systems Computer Engineering Software Engineering or a related technical discipline and relevant professional experience;or
- An equivalent combination ofcollege education technical training industry certifications and hands-on cybersecurity experience.
- Candidates with anAssociate degree relevant college coursework technical certifications or substantial professional experiencein lieu of a four-year degree may be considered.
- Demonstrated professional experience inAPI security application security WAF/WAAP engineering security architecture DevSecOps cloud security vulnerability management or security engineering.
- Hands-on experience deploying and supportingenterprise API security application security API gateway and traffic-monitoring technologiesis strongly preferred.
Required Technical Qualifications
- Hands-on experience withenterprise API security technologies.
- Experience deploying configuring and tuningWAF/WAAP security controls.
- Understanding ofeBPF-based agent/sensor deployment and troubleshootingin Linux Kubernetes containerized and cloud environments.
- Experience integrating API security platforms withenterprise API gateways and API management technologies.
- Strong knowledge ofHTTP/HTTPS DNS TLS/mTLS REST GraphQL JSON OpenAPI/Swagger web services and API gateway architectures.
- Strong understanding of theOWASP API Security Top 10 and OWASP Top 10.
- Knowledge ofOAuth 2.0 OIDC JWT API keys IAM RBAC and modern API authorization models.
- Experience performingsecurity architecture reviews and threat modeling.
- Working knowledge of public cloud platforms Kubernetes containers Linux and microservices.
- Experience withsecure SDLC DevSecOps CI/CD vulnerability management and incident-response processes.
- Ability to troubleshoot complex integrations across applications gateways middleware networks security controls and cloud infrastructure.
- Ability to work directly withdevelopers architects API gateway teams middleware engineers DevOps/SRE cloud network SOC and infrastructure teams.
Preferred Qualifications
- Experience operating enterprise-scaleAPI security and application security environments.
- Experience witheBPF-based API traffic collection and Kubernetes/Linux sensor deployments.
- Advanced experience integrating security platforms withcloud-based API management solutions and enterprise gateway appliances.
- Experience with API gateways reverse proxies service meshes ingress controllers and load-balancing technologies.
- Experience integrating security telemetry withSIEM/SOAR platforms.
- Experience with penetration testing and adversarial API/application security assessments.
- Familiarity withSTRIDE attack trees or comparable threat-modeling methodologies.
- Experience developing security tooling and automation at enterprise scale.
- Relevant industry certifications ininformation security application security penetration testing cloud security or DevSecOpsare preferred but not required.
Key Technical Skills
API Security Application Security WAF/WAAP eBPF Linux Kubernetes API Gateway Security API Management API Discovery API Posture Management REST GraphQL OWASP API Top 10 OWASP Top 10 OAuth 2.0 OIDC JWT TLS/mTLS OpenAPI/Swagger DevSecOps CI/CD Python Security Automation Threat Modeling Security Architecture Cloud Security SIEM/SOAR Vulnerability Management
What Success Looks Like
The successful candidate will serve as a technical subject-matter expert forenterprise API and application security with the ability to deploy and troubleshooteBPF-based security agents integrate security capabilities withcloud and on-premises API gateway technologies and secure complex enterprise API architectures.
The engineer will combine hands-on security engineering with API security WAF/WAAP application security security architecture threat modeling cloud security DevSecOps and automation expertise while working directly with engineering teams to implement scalablesecure-by-design solutions.
COMPENSATION AND BENEFITS
This position is eligible to earn a base salary in the range of $116000.00 - $216000.00 annually. Placement within the pay range may differ based upon various factors including but not limited to skills experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production commission and/or discretionary incentives.Please click here for a list of benefits for which this position is eligible.
Key has implemented an approach to employee workspaces which prioritizes in-office presence while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.
Job Posting Expiration Date: 10/26/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin age genetic information pregnancy disability veteran status or any other characteristic protected by law.Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing
#LI-RemoteRequired Experience:
IC