The Senior Engineer, External Web Application & API Security is a hands-on technical lead responsible for enterprise API security and web application protection. This role will lead the engineering and operationalization of API discovery, posture management, and runtime protection capabilities across cloud, on-premises, and partner environments. The engineer will design, operate, and tune WAF and edge security controls for high-availability digital services, assess and reduce API risk related to authorization failures, authentication weaknesses, excessive data exposure, business logic abuse, injection, automation, and other OWASP API Security Top 10 risks. Additionally, the role involves designing and tuning WAF, rate-limiting, bot management, DDoS, and edge security controls for applications and APIs, with a strong focus on accuracy, resiliency, and low false-positive rates. A key aspect of this role is to automate repeatable security workflows and embed validation into CI/CD and DevSecOps processes. This role reports into the Senior Manager, Application & API Security (E-WAAP) and will provide coaching and technical direction to Engineers and Analysts as capabilities are in-sourced from a managed services provider.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior