API Security Engineer

KeyBankBrooklyn, OH
$116,000 - $216,000Hybrid

About The Position

We are seeking an experienced API & Application Security Engineer with expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling. This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments. The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience; or An equivalent combination of college education, technical training, industry certifications, and hands-on cybersecurity experience.
  • Candidates with an Associate degree, relevant college coursework, technical certifications, or substantial professional experience in lieu of a four-year degree may be considered.
  • Demonstrated professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering.
  • Hands-on experience deploying and supporting enterprise API security, application security, API gateway, and traffic-monitoring technologies is strongly preferred.
  • Hands-on experience with enterprise API security technologies.
  • Experience deploying, configuring, and tuning WAF/WAAP security controls.
  • Understanding of eBPF-based agent/sensor deployment and troubleshooting in Linux, Kubernetes, containerized, and cloud environments.
  • Experience integrating API security platforms with enterprise API gateways and API management technologies.
  • Strong knowledge of HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures.
  • Strong understanding of the OWASP API Security Top 10 and OWASP Top 10.
  • Knowledge of OAuth 2.0, OIDC, JWT, API keys, IAM, RBAC, and modern API authorization models.
  • Experience performing security architecture reviews and threat modeling.
  • Working knowledge of public cloud platforms, Kubernetes, containers, Linux, and microservices.
  • Experience with secure SDLC, DevSecOps, CI/CD, vulnerability management, and incident-response processes.
  • Ability to troubleshoot complex integrations across applications, gateways, middleware, networks, security controls, and cloud infrastructure.
  • Ability to work directly with developers, architects, API gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams.

Nice To Haves

  • Experience operating enterprise-scale API security and application security environments.
  • Experience with eBPF-based API traffic collection and Kubernetes/Linux sensor deployments.
  • Advanced experience integrating security platforms with cloud-based API management solutions and enterprise gateway appliances.
  • Experience with API gateways, reverse proxies, service meshes, ingress controllers, and load-balancing technologies.
  • Experience integrating security telemetry with SIEM/SOAR platforms.
  • Experience with penetration testing and adversarial API/application security assessments.
  • Familiarity with STRIDE, attack trees, or comparable threat-modeling methodologies.
  • Experience developing security tooling and automation at enterprise scale.
  • Relevant industry certifications in information security, application security, penetration testing, cloud security, or DevSecOps are preferred but not required.

Responsibilities

  • Deploy, configure, administer, and optimize enterprise API security platforms and controls.
  • Perform continuous API discovery, inventory, classification, and security posture management.
  • Identify shadow, rogue, zombie, deprecated, and undocumented APIs.
  • Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns.
  • Identify vulnerabilities including BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, security misconfigurations, and business-logic abuse.
  • Assess APIs against the OWASP API Security Top 10 and organizational security standards.
  • Investigate API security alerts and coordinate remediation with engineering and application teams.
  • Integrate API security findings with SIEM, SOAR, vulnerability management, incident response, and ticketing workflows.
  • Design, deploy, configure, and maintain eBPF-based API security agents and sensors across Linux, containerized, Kubernetes, and cloud environments.
  • Deploy traffic-collection components to provide visibility into API communications and application behavior.
  • Validate operating-system, kernel, container runtime, Kubernetes, networking, and infrastructure prerequisites for eBPF deployments.
  • Troubleshoot agent installation, connectivity, permissions, kernel compatibility, traffic visibility, telemetry collection, and performance issues.
  • Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact.
  • Develop standards and automation for repeatable, enterprise-scale agent deployments.
  • Support agent upgrades, configuration changes, health monitoring, troubleshooting, and lifecycle management.
  • Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.
  • Integrate API security platforms with enterprise API gateways, middleware platforms, reverse proxies, ingress controllers, and traffic-management technologies.
  • Work with API proxies, products, policies, routing configurations, authentication mechanisms, and traffic-management controls.
  • Configure and validate API traffic visibility between gateways and API security platforms.
  • Review gateway policies for authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security-control weaknesses.
  • Support integrations with both cloud-native API management platforms and enterprise on-premises gateway appliances.
  • Configure and validate traffic forwarding, mirroring, logging, telemetry, or other supported collection mechanisms.
  • Troubleshoot connectivity, certificate, traffic collection, API discovery, and integration issues.
  • Partner with gateway administrators, middleware engineers, application teams, and platform owners to remediate identified security weaknesses.
  • Deploy, configure, administer, and optimize enterprise WAF/WAAP security controls.
  • Configure and tune WAF policies, custom rules, rate controls, network/IP controls, and application protections.
  • Analyze HTTP/HTTPS traffic and security events to identify attacks, anomalous activity, and false positives.
  • Investigate SQL injection, XSS, command injection, path traversal, file inclusion, malicious automation, and other application-layer attacks.
  • Onboard applications and APIs to enterprise web and API protection services.
  • Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic.
  • Support security incident investigations using WAF, API, application, and network telemetry.
  • Perform security architecture reviews for APIs, web applications, microservices, API gateways, middleware platforms, Kubernetes, containers, and cloud environments.
  • Conduct threat modeling to identify attack surfaces, trust boundaries, abuse cases, authorization risks, sensitive-data exposure, and potential control gaps.
  • Review authentication and authorization architectures involving OAuth 2.0, OIDC, JWT, API keys, mTLS, IAM, RBAC, and other access-control mechanisms.
  • Evaluate end-to-end API traffic flows from clients through edge-security controls, gateways, middleware, microservices, and backend applications.
  • Recommend preventive, detective, and compensating security controls based on identified risks.
  • Participate in application and infrastructure design reviews and promote secure-by-design engineering practices.
  • Perform application and API security assessments using manual and automated testing techniques.
  • Apply the OWASP Top 10 and OWASP API Security Top 10 to application and API assessments.
  • Perform HTTP/API request and response analysis, vulnerability validation, and remediation verification.
  • Work with intercepting proxies, API clients, command-line testing tools, SAST, DAST, SCA, and API security testing technologies.
  • Integrate application and API security testing into CI/CD and DevSecOps pipelines.
  • Develop automation using Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies.
  • Automate agent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows.
  • Work directly with developers to explain vulnerabilities, recommend practical remediation, and validate fixes.

Benefits

  • Eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.
  • A list of benefits for which this position is eligible.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service