An innovative firm is seeking a skilled API Security Engineer to enhance the security of APIs and directory services. In this role, you will configure secured APIs, implement security measures, and ensure compliance with industry standards. Your expertise in API security mechanisms and tools will be crucial in protecting against vulnerabilities. Join a forward-thinking team where your contributions will make a significant impact on the security landscape. If you are passionate about API security and want to work in a dynamic environment, this opportunity is for you.
Qualifications
Extensive experience with API security configurations and best practices.
Deep knowledge of authentication protocols and API token management.
Responsibilities
Configure APIs to ensure security against threats and vulnerabilities.
Enhance security of directory services using certificate-based communication.
Skills
API security mechanisms (OAuth 2.0, OpenID Connect)
API security tools (Postman, Burp Suite, OWASP ZAP)
Authentication protocols (OAuth, SAML)
Knowledge of OWASP API Security Top 10
Scripting languages (Python, Bash)
Tools
WAFs
API Gateways
SIEM tools
Job description
Job Description
Configuring Secured APIs: The primary responsibility is to configure APIs to ensure they are secure. This involves implementing security measures to protect APIs from threats and vulnerabilities.
Enhancing Security for Directory Services: The engineer is responsible for enhancing the security of directory services using certificate-based communication. This includes ensuring that communication between services is secure and encrypted.
Experience with API Security Configurations: The role requires extensive experience with API security configurations. This includes knowledge of best practices and standards for securing APIs.
Technical Skills:
Expertise in API security mechanisms such as OAuth 2.0, OpenID Connect, API keys, JWT, rate limiting, and IP whitelisting.
Security Tools & Frameworks: Experience with API security tools (e.g., Postman, Burp Suite, OWASP ZAP), WAFs, API Gateways, and SIEM tools for monitoring and detecting API threats.
Authentication & Authorization: Deep knowledge of authentication protocols, including OAuth, OpenID Connect, SAML, and API token management.
Knowledge of Vulnerabilities: Familiarity with the OWASP API Security Top 10, and experience in identifying and mitigating common API vulnerabilities such as injection attacks, improper authentication, and excessive data exposure.
Compliance Knowledge: Understanding of relevant security and compliance standards, such as GDPR, PCI DSS, and SOC 2, and their impact on API security.
Scripting & Automation: Familiarity with scripting languages (e.g., Python, Bash) to automate security tasks and API security testing.