Cybersecurity Engineer
API Security
JOB SUMMARY
The mission of the individual in this role is to leverage their understanding of enterprise security practices to help mitigate cybersecurity risk. They will work with the CBRE business, Digital and Technology, and other partner organizations (Compliance, Risk Mgmt., Audit, and Legal) to integrate security processes, tools, and people into the business culture, contributing to a holistic security ecosystem and supporting continuous improvements in protection and monitoring capabilities globally. Executes on assigned initiatives and contributes to problem resolution as part of a collaborative security team.
Experience in all skills listed is not necessary to be qualified for the position. If you have relevant similar experience, we still want to talk to you.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
- Implement and maintain security controls for API environments, including REST, GraphQL, gRPC, and event-driven interfaces across cloud and hybrid deployments
- Conduct API security assessments, threat modeling, and attack surface analysis, covering authentication gaps, injection risk, excessive data exposure, and broken authorization patterns
- Support the implementation of API authentication and authorization standards, including OAuth 2.0, OIDC, mTLS, and API key lifecycle management
- Configure and maintain API gateway security policies covering rate limiting, input validation, payload inspection, anomaly detection, and traffic routing controls
- Support security design reviews and operational controls for Model Context Protocol (MCP) server implementations, addressing tool permission scoping, prompt injection risk, Sampling and Elicitation primitive controls, and agentic workflow safeguards
- Integrate API and MCP security scanning into CI/CD pipelines for shift-left discovery of secrets, authentication gaps, and insecure API patterns
- Contribute to API security governance documentation, gate compliance checklists, and security design patterns aligned to enterprise control frameworks
- Collaborate with development and platform teams to operationalize secure API design patterns and drive resolution of security findings
- Monitor API runtime behavior for anomalies, abuse patterns, unauthorized access, and AI agent tool-use irregularities using SIEM and API observability tooling
- Support third-party API and MCP server assessment workflows, including intake evaluation, risk classification, and approval routing
- Participate in incident response activities related to API abuse, data exposure via API endpoints, and agentic AI tool misuse scenarios
- Share knowledge with engineering teams on API security best practices, OWASP API Security Top 10, and secure development patterns for both human-facing and agent-facing interfaces
- Develop reporting on operational metrics and product performance
- Participate in on-call rotation for ensuring uptime and functionality of critical internal customer services
- Other duties as assigned
SUPERVISORY RESPONSIBILITIES
No formal supervisory responsibilities. Contributes to team knowledge sharing and peer development.
EDUCATION and EXPERIENCE:
Bachelor's degree (BA/BS) in a related field of work plus a minimum of 2 years related work experience; or equivalent combination of education and experience (equivalent work experience = 2 years of related experience for every year of higher level education).
- Intermediate experience with API security assessment and testing across REST, GraphQL, gRPC, and event-driven API architectures, including familiarity with OWASP API Security Top 10
- Intermediate experience with API gateway platforms; experience with tools like WSO2, Kong, Apigee, AWS API Gateway, or Azure API Management, including policy configuration for authentication, rate limiting, and traffic inspection
- Working knowledge of API security testing and scanning tools; familiarity with Burp Suite, OWASP ZAP, Postman, or 42Crunch for API-specific vulnerability discovery and spec validation
- Working knowledge of API discovery and runtime security observability; familiarity with tools like Traceable AI, Salt Security, or Noname Security for continuous API inventory, risk scoring, and behavioral monitoring
- Working knowledge of secrets management and credential lifecycle management for API and service identities; familiarity with tools such as HashiCorp Vault, CyberArk, or cloud-native secrets managers (AWS Secrets Manager, Azure Key Vault)
- Working knowledge of SAST, DAST, and software composition analysis integrated into CI/CD pipelines; familiarity with tools like Checkmarx, Veracode, Semgrep, or Snyk
- Foundational awareness of the Model Context Protocol (MCP) specification, including its two-layer architecture and the security implications of agentic AI tool-use patterns
- Working knowledge of cloud provider API and security services across one or more of AWS, Azure, or GCP
- Foundational experience writing and running infrastructure as code; familiarity with tools like Terraform
- Foundational Linux systems administration experience or equivalent skills
- Working knowledge of DevOps and CI/CD pipelines; familiarity with tools like GitHub Actions, GitLab CI, or Jenkins
- Working knowledge of automating security workflows using Python or another scripting language
- Foundational understanding of source control management and practices using Git and GitHub
OTHER SKILLS and/or ABILITIES
- Experience with the Microsoft ecosystem
- Familiarity with directory services including Active Directory and LDAP, with understanding of OAuth/OIDC integration patterns for API authorization
- Familiarity with API specification formats including OpenAPI/Swagger and AsyncAPI
- Awareness of microservice and service mesh architectures and their security implications, including mTLS, service-to-service authentication, and sidecar proxy patterns
- Awareness of zero trust principles as applied to API and service authentication across cloud and hybrid environments
- Familiarity with NIST SP 800-204 (security guidance for microservices-based application systems) and related frameworks
COMMUNICATION SKILLS
Strong written and verbal communication skills with the ability to explain API and security concepts clearly across technical teams. Able to contribute to standards documentation, author technical reports, and collaborate effectively across engineering, operations, and compliance teams.
REASONING ABILITY
Analytical problem-solving skills with experience addressing API security challenges across heterogeneous environments. Able to evaluate technical approaches, apply risk-based reasoning, and contribute to strategies that measurably reduce API attack surface and improve enterprise security posture.
Keep up to date with exciting career
opportunities and the latest news.