Job Title : PI Security Engineer
Location : Miami, FL - Charlotte, NC - Raleigh, NC - Tampa, FL
Duration : 12 months
Job Summary :
We are seeking a skilled and motivated API Security Engineer to secure our growing portfolio of APIs and services. The candidate will be responsible for identifying, remediating, and preventing API-related vulnerabilities across various platforms (web, mobile, and cloud). This role involves collaborating with engineering, DevOps, and security teams to embed robust security controls into the API development lifecycle.
Key Responsibilities :
- Design, implement, and manage security controls for public and internal APIs.
- Conduct API threat modeling, code reviews, and security testing (manual & automated).
- Integrate and manage API security gateways (e.g., Apigee, Kong, AWS API Gateway, WAFs ).
- Implement and manage authentication, authorization, rate limiting , and token validation (OAuth 2.0, JWT, OpenID Connect).
- Conduct API vulnerability assessments using tools like Burp Suite, Postman, OWASP ZAP, APIsec, or 42Crunch .
- Perform security testing for REST, GraphQL, and gRPC endpoints.
- Drive remediation of vulnerabilities (e.g., injection, broken auth, insecure object references) per OWASP API Security Top 10 .
- Build and enforce secure API design standards and collaborate with developers on secure coding practices.
- Monitor API traffic for anomalies using WAF, SIEM, or API threat detection tools .
- ssist in integrating API security into CI / CD pipelines and DevSecOps processes.
Required Qualifications :
3-6 years of hands-on experience in AppSec, API development, or cybersecurity roles.Solid understanding of HTTP / S, REST, OAut., JWT, OpenID Connect , and TLS / SSL .Experience with API security testing tools and interpreting scan results.Familiarity with OWASP API Top 10 , OWASP ASVS , and secure SDLC principles.Knowledge of DevSecOps practices and security in containerized / cloud environments.Preferred Qualifications :
Experience with API management platforms (Apigee, AWS API Gateway, Kong, WSO2, etc.)Familiarity with GraphQL , gRPC , and microservices architecture .Scripting experience (e.g., Python, Bash ) for custom security automation.Certifications like OSWE, GWAPT, API Security Specialist , or CISSP are a plus.