Associate Software Engineer

CBRE

Hyderabad

On-site

INR 1,500,000 - 2,100,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

CBRE seeks a Cybersecurity Engineer focused on API Security to strengthen enterprise protections. You will collaborate with CBRE Digital and Technology, Compliance, Risk Management, Audit, and Legal to embed secure API practices across cloud and on‑prem environments.

You will lead API security assessments, threat modeling, and integration of security controls, gate policies, and CI/CD security. Familiarity with OWASP API Top 10, OAuth/OIDC, mTLS, and API gateways is essential.

Qualifications

  • Bachelor's degree in a related field with 2+ years in API security.
  • Experience with API security assessment and testing across REST, GraphQL, gRPC.
  • Knowledge of OWASP API Security Top 10.
  • Experience with cloud platforms and CI/CD security practices.

Responsibilities

  • Implement and maintain API security controls for REST, GraphQL, gRPC across cloud and hybrid deployments.
  • Conduct API security assessments, threat modeling, and attack surface analysis.
  • Support API authentication/authorization standards (OAuth 2.0, OIDC, mTLS) lifecycles.
  • Configure API gateway security policies: rate limiting, input validation, traffic inspection.
  • Integrate API and MCP security scanning into CI/CD pipelines (shift-left).
  • Collaborate on security governance, design patterns and risk classifications.
  • Monitor API runtime for anomalies and abuse with SIEM and observability tooling.
  • Participate in incident response related to API abuse and data exposure.

Skills

API security
Threat modeling
CI/CD security
OAuth 2.0 / OIDC
mTLS
SIEM / observability
Incident response
Cloud & hybrid security
Communication
OpenAPI / Swagger

Education

Bachelor's degree in related field

Tools

WSO2
Kong
Apigee
AWS API Gateway
Azure API Management
BurpSuite
OWASP ZAP
Postman
Traceable AI
Salt Security
Terraform
GitHub Actions
Jenkins
HashiCorp Vault
CyberArk

Job description

Job Summary

Themission of the individual in this role is to leverage their understanding ofenterprise security practices to help mitigate cybersecurity risk. They willwork with the CBRE business, Digital and Technology, and other partnerorganizations (Compliance, Risk Mgmt., Audit, and Legal) to integrate securityprocesses, tools, and people into the business culture, contributing to aholistic security ecosystem and supporting continuous improvements inprotection and monitoring capabilities globally. Executes on assignedinitiatives and contributes to problem resolution as part of a collaborativesecurity team.

Cybersecurity Engineer
API Security
Job Summary

Themission of the individual in this role is to leverage their understanding ofenterprise security practices to help mitigate cybersecurity risk. They willwork with the CBRE business, Digital and Technology, and other partnerorganizations (Compliance, Risk Mgmt., Audit, and Legal) to integrate securityprocesses, tools, and people into the business culture, contributing to aholistic security ecosystem and supporting continuous improvements inprotection and monitoring capabilities globally. Executes on assignedinitiatives and contributes to problem resolution as part of a collaborativesecurity team.

Experiencein all skills listed is not necessary to be qualified for the position. If youhave relevant similar experience, we still want to talk to you.

Essential Duties And Responsibilities
  • Implementand maintain security controls for API environments, including REST, GraphQL,gRPC, and event-driven interfaces across cloud and hybrid deployments
  • ConductAPI security assessments, threat modeling, and attack surface analysis,covering authentication gaps, injection risk, excessive data exposure, andbroken authorization patterns
  • Supportthe implementation of API authentication and authorization standards, includingOAuth 2.0, OIDC, mTLS, and API key lifecycle management
  • Configureand maintain API gateway security policies covering rate limiting, inputvalidation, payload inspection, anomaly detection, and traffic routing controls
  • Supportsecurity design reviews and operational controls for Model Context Protocol(MCP) server implementations, addressing tool permission scoping, promptinjection risk, Sampling and Elicitation primitive controls, and agenticworkflow safeguards
  • IntegrateAPI and MCP security scanning into CI/CD pipelines for shift-left discovery ofsecrets, authentication gaps, and insecure API patterns
  • Contributeto API security governance documentation, gate compliance checklists, andsecurity design patterns aligned to enterprise control frameworks
  • Collaboratewith development and platform teams to operationalize secure API designpatterns and drive resolution of security findings
  • MonitorAPI runtime behavior for anomalies, abuse patterns, unauthorized access, and AIagent tool-use irregularities using SIEM and API observability tooling
  • Supportthird-party API and MCP server assessment workflows, including intakeevaluation, risk classification, and approval routing
  • Participatein incident response activities related to API abuse, data exposure via APIendpoints, and agentic AI tool misuse scenarios
  • Shareknowledge with engineering teams on API security best practices, OWASP APISecurity Top 10, and secure development patterns for both human-facing andagent-facing interfaces
  • Developreporting on operational metrics and product performance
  • Participatein on-call rotation for ensuring uptime and functionality of critical internalcustomer services
  • Otherduties as assigned
Supervisory Responsibilities

Noformal supervisory responsibilities. Contributes to team knowledge sharing andpeer development.

EDUCATION And EXPERIENCE

Bachelor'sdegree (BA/BS) in a related field of work plus a minimum of 2 years relatedwork experience; or equivalent combination of education and experience(equivalent work experience = 2 years of related experience for every year ofhigher level education).

  • Intermediateexperience with API security assessment and testing across REST, GraphQL, gRPC,and event-driven API architectures, including familiarity with OWASP APISecurity Top 10
  • Intermediateexperience with API gateway platforms; experience with tools like WSO2, Kong,Apigee, AWS API Gateway, or Azure API Management, including policyconfiguration for authentication, rate limiting, and traffic inspection
  • Workingknowledge of API security testing and scanning tools; familiarity with BurpSuite, OWASP ZAP, Postman, or 42Crunch for API-specific vulnerability discoveryand spec validation
  • Workingknowledge of API discovery and runtime security observability; familiarity withtools like Traceable AI, Salt Security, or Noname Security for continuous APIinventory, risk scoring, and behavioral monitoring
  • Workingknowledge of secrets management and credential lifecycle management for API andservice identities; familiarity with tools such as HashiCorp Vault, CyberArk,or cloud-native secrets managers (AWS Secrets Manager, Azure Key Vault)
  • Workingknowledge of SAST, DAST, and software composition analysis integrated intoCI/CD pipelines; familiarity with tools like Checkmarx, Veracode, Semgrep, orSnyk
  • Foundationalawareness of the Model Context Protocol (MCP) specification, including itstwo-layer architecture and the security implications of agentic AI tool-usepatterns
  • Workingknowledge of cloud provider API and security services across one or more ofAWS, Azure, or GCP
  • Foundationalexperience writing and running infrastructure as code; familiarity with toolslike Terraform
  • FoundationalLinux systems administration experience or equivalent skills
  • Workingknowledge of DevOps and CI/CD pipelines; familiarity with tools like GitHubActions, GitLab CI, or Jenkins
  • Workingknowledge of automating security workflows using Python or another scriptinglanguage
  • Foundationalunderstanding of source control management and practices using Git and GitHub
OTHER SKILLS And/or ABILITIES
  • Experiencewith the Microsoft ecosystem
  • Familiaritywith directory services including Active Directory and LDAP, with understandingof OAuth/OIDC integration patterns for API authorization
  • Familiaritywith API specification formats including OpenAPI/Swagger and AsyncAPI
  • Awarenessof microservice and service mesh architectures and their security implications,including mTLS, service-to-service authentication, and sidecar proxy patterns
  • Awarenessof zero trust principles as applied to API and service authentication acrosscloud and hybrid environments
  • Familiaritywith NIST SP 800-204 (security guidance for microservices-based applicationsystems) and related frameworks
Communication Skills

Strongwritten and verbal communication skills with the ability to explain API andsecurity concepts clearly across technical teams. Able to contribute tostandards documentation, author technical reports, and collaborate effectivelyacross engineering, operations, and compliance teams.

REASONING ABILITY

Analyticalproblem-solving skills with experience addressing API security challengesacross heterogeneous environments. Able to evaluate technical approaches, applyrisk-based reasoning, and contribute to strategies that measurably reduce APIattack surface and improve enterprise security posture.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Software Engineer
Associate Software Engineer

CBRE Group, Inc. • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 2,400,000
Senior Engineer - Cyber Security
Senior Engineer - Cyber Security

Adani Group • Mumbai

On-site
INR 1,200,000 - 2,000,000
Pre-Sales Application Security Engineers Min. 7 Year
Pre-Sales Application Security Engineers Min. 7 Year

Rapifuzz • India

Hybrid
INR 2,500,000 - 4,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Senior Software Engineer / Integration Engineer
Senior Software Engineer / Integration Engineer

IntraEdge • Hyderabad

On-site
INR 4,500,000 - 7,000,000
Security Engineer
Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000