Lead Information Security Consultant – API Security, Governance

Jobtailor

Illinois

On-site

USD 180,000 - 260,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is recruiting for a senior API Security leader in the United States. The role focuses on directing enterprise API security standards, governance practices, and risk assessments to strengthen the organization’s security posture across API-enabled platforms.

You will guide secure API design, authentication, and threat protection, while collaborating with security, risk, and architecture teams to implement secure-by-design initiatives and regulatory controls.

Qualifications

  • 10+ years of experience in Information Security, Application Security, API Security, or a related field.
  • Deep expertise in API Security principles, frameworks, and best practices.
  • Experience developing, implementing, and enforcing security standards, governance models, controls, and policies.
  • Strong understanding of secure API design, authentication, authorization, and risk management.
  • Experience performing threat modeling, security reviews, architecture assessments, and risk evaluations.
  • Proven ability to assess and improve an organization's API security posture.
  • Experience partnering with security, risk, architecture, business, and engineering stakeholders across large enterprise environments.
  • Certifications such as CISSP, CSSLP, GWAPT, or equivalent.

Responsibilities

  • Lead the development, maintenance, and evolution of enterprise API security standards, controls, and governance practices.
  • Assess and improve the bank's overall API security posture through security reviews, risk assessments, and control evaluations.
  • Provide guidance on secure API architecture, authentication, authorization, encryption, threat protection, monitoring, and lifecycle management.
  • Partner with Information Security, Technology Risk, Enterprise Architecture, and engineering teams to identify and mitigate API security risks.
  • Conduct architecture reviews, threat modeling exercises, and security assessments for API-enabled applications and platforms.
  • Define and promote API security best practices, reusable security patterns, and governance frameworks across the enterprise.
  • Influence technology teams to adopt secure-by-design API development and implementation practices.
  • Support regulatory, compliance, audit, and risk management activities related to API and Application Security.
  • Serve as a trusted advisor and subject matter expert for API Security and Application Security initiatives.
  • Stay current on emerging API threats, vulnerabilities, technologies, and industry best practices.
  • Collaborate with platform teams supporting Apigee, GraphQL, AI APIs, AWS API Gateway, and other API technologies.
  • Drive alignment between business objectives, security requirements, and enterprise technology standards.

Skills

API Security
Security Architecture
Threat Modeling
Regulatory Compliance
OAuth 2.0 / OIDC
Threat Protection
APIs & Microservices
Influencing Decision-Making

Tools

Apigee
AWS API Gateway
GraphQL
Kong
MuleSoft

Job description

  • Lead the development, maintenance, and evolution of enterprise API security standards, controls, and governance practices
  • Assess and improve the bank's overall API security posture through security reviews, risk assessments, and control evaluations
  • Provide guidance on secure API architecture, authentication, authorization, encryption, threat protection, monitoring, and lifecycle management
  • Partner with Information Security, Technology Risk, Enterprise Architecture, and engineering teams to identify and mitigate API security risks
  • Conduct architecture reviews, threat modeling exercises, and security assessments for API-enabled applications and platforms
  • Define and promote API security best practices, reusable security patterns, and governance frameworks across the enterprise
  • Influence technology teams to adopt secure-by-design API development and implementation practices
  • Support regulatory, compliance, audit, and risk management activities related to API and Application Security
  • Serve as a trusted advisor and subject matter expert for API Security and Application Security initiatives
  • Stay current on emerging API threats, vulnerabilities, technologies, and industry best practices
  • Collaborate with platform teams supporting Apigee, GraphQL, AI APIs, AWS API Gateway, and other API technologies
  • Drive alignment between business objectives, security requirements, and enterprise technology standards
Requirements
  • 10+ years of experience in Information Security, Application Security, API Security, Security Architecture, or a related field
  • Deep expertise in API Security and Application Security principles, frameworks, and best practices
  • Experience developing, implementing, and enforcing security standards, governance models, controls, and policies
  • Strong understanding of secure API design, architecture, authentication, authorization, and risk management
  • Experience performing threat modeling, security reviews, architecture assessments, and risk evaluations
  • Proven ability to assess and improve an organization's API security posture
  • Experience partnering with security, risk, architecture, business, and engineering stakeholders across large enterprise environments
  • Strong understanding of security frameworks, regulatory requirements, and compliance considerations
  • Prior hands‑on technical experience with application development, APIs, or API technologies
  • Ability to influence decision‑making and drive security initiatives without direct authority
  • Experience with API gateway technologies such as Apigee, AWS API Gateway, GraphQL gateways, Kong, MuleSoft, or similar platforms
  • Knowledge of the OWASP API Security Top 10 and common API attack vectors
  • Experience with OAuth 2.0, OpenID Connect (OIDC), JWT, mTLS, API threat protection, and modern authentication frameworks
  • Experience supporting API governance programs within financial services or other highly regulated industries
  • Exposure to API penetration testing, security testing methodologies, and vulnerability management practices
  • Knowledge of cloud‑native application architectures, microservices, and distributed systems
  • Experience developing enterprise security reference architectures and reusable security patterns
  • Security certifications such as CISSP, CSSLP, GWAPT, or equivalent
  • Experience securing modern API ecosystems, including AI APIs and emerging API technologies
  • Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies
  • Must satisfy applicable employment eligibility verification requirements
Core Competencies

Demonstrates deep expertise in API Security and Application Security principles, frameworks, and best practices, with a strong focus on secure API design, architecture, and risk management. Proven ability to assess and enhance an organization's API security posture while collaborating with cross‑functional teams in highly regulated environments.

Highest-signal resume keywords
  • API Security
  • Application Security
  • Security Architecture
  • Threat Modeling
  • Regulatory Compliance
ATS Optimization Keywords
Hard Skills
  • API Security Principles
  • Secure API Design
  • Risk Management
  • Security Standards Development
  • Threat Protection
  • Security Assessments
  • Vulnerability Management
  • OAuth 2.0
  • OpenID Connect
  • API Penetration Testing
Soft Skills
  • Influencing Decision-Making
  • Collaboration
  • Advisory Skills
Certifications & Qualifications
  • CISSP
  • CSSLP
  • GWAPT
Industry Keywords
  • Financial Services
  • Compliance
  • Governance Frameworks
  • Security Frameworks
  • API Ecosystems
Tools & Technologies
  • Apigee
  • AWS API Gateway
  • GraphQL
  • Kong
  • MuleSoft
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Information Security Consultant - API Security & Governance
Lead Information Security Consultant - API Security & Governance

U.S. Bank • Atlanta (GA)

On-site
USD 127,000 - 149,000
Healthcare
401(k)
Paid vacation
+1
Director, Digital Product Management – API Gateways, Managed File Transfer, Agentic Platforms – Enterprise Architecture
Director, Digital Product Management – API Gateways, Managed File Transfer, Agentic Platforms – Enterprise Architecture

Jobtailor • Phoenix (AZ)

On-site
USD 150,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Lead Information Security Consultant - API Security & Governance
Lead Information Security Consultant - API Security & Governance

U.S. Bank • Northern (KY)

Hybrid
USD 127,000 - 149,000
Healthcare benefits
401(k) retirement plan
Paid time off
Lead Software Engineer - API, AI, and Agentic Gateway Platform
Lead Software Engineer - API, AI, and Agentic Gateway Platform

U.S. Bank • Chicago (IL)

On-site
USD 140,000 - 210,000
Principal Application Security Architect
Principal Application Security Architect

LPL Financial LLC • San Diego (CA)

On-site
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+2
Principal Enterprise Architect – Tooling
Principal Enterprise Architect – Tooling

Jobtailor • Minnesota

On-site
USD 150,000 - 210,000
Lead Engineer – AI Security
Lead Engineer – AI Security

Jobtailor • Brooklyn Park (MN)

On-site
USD 120,000 - 150,000
API Architect
API Architect

Cloud Security Web • Phoenix (AZ)

On-site
USD 180,000 - 230,000
Senior Cybersecurity Integration Engineer
Senior Cybersecurity Integration Engineer

Basecamp Consulting & Solutions LLC • Reston (VA)

On-site
USD 140,000 - 200,000
401(k) matching
Bonus based on performance
Competitive salary
+6