About The Position

We are seeking an experienced Apigee Platform Buildout & Operations Security Architect with 10+ years of experience designing, implementing, and operationalizing security for enterprise API management platforms. This role will lead the end-to-end security architecture for the Apigee platform, including API security, IAM, network security, data protection, DevSecOps integration, compliance alignment, security operations, and migration of legacy IBM DataPower security controls into a modern Apigee architecture.

Requirements

  • 7+ years of experience in security architecture with significant expertise in enterprise API management platforms and Google Apigee (Apigee X, Hybrid, or equivalent).
  • Deep knowledge of IBM DataPower and API Connect security patterns, including authentication, authorization, TLS/mTLS, certificate management, XML/SOAP security, GatewayScript, and backend security controls.
  • Strong expertise in API security standards and technologies including OAuth 2.0, OpenID Connect, JWT, SAML, API keys, identity federation, token validation, and claims-based authorization.
  • Experience with cloud security, IAM architecture, DevSecOps, CI/CD security integration, secrets management, SIEM integration, threat modeling, and security monitoring.
  • Strong communication and documentation skills with the ability to develop architecture diagrams, threat models, security standards, control matrices, executive presentations, and audit artifacts.

Responsibilities

  • Define and implement enterprise API security architecture for Google Apigee, including OAuth 2.0, OpenID Connect, JWT validation, mTLS, API threat protection, policy enforcement, and reusable security patterns.
  • Lead security strategy and control mapping for IBM DataPower and API Connect migrations, identifying legacy security controls and designing secure target-state solutions within Apigee.
  • Design secure network, connectivity, and traffic protection architectures, including private connectivity, segmentation, TLS/mTLS communications, WAF integration, firewall policies, and zero-trust principles.
  • Establish IAM, privileged access, RBAC, service account, and identity federation standards while integrating with enterprise identity providers and automation platforms.
  • Partner with DevSecOps, cybersecurity, compliance, and operations teams to embed security controls into CI/CD pipelines, operational monitoring, audit readiness, incident response, and governance processes.

Benefits

  • Free Healthcare Insurance
  • 401(k) Retirement Plan
  • Free Life Insurance
  • Sick Time Off
  • Mentorship Program
  • Certifications
  • Referrals
  • Family and Wellness benefits
  • Continuous Growth and Career Development
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service