API Security Engineer
Fiserv - Berkeley Heights, NJ
Hiring: API Security Engineer Company: Fiserv Location: Berkeley Heights, NJ Job Posted Time: 2026-09-16 16:16:02 Employment Type: Contract / On-site Target Skills & Keywords : API Design, CI/CD, CPT, DAST, Git, JWT, OAuth, OAuth2, OIDC, OWASP, PCI DSS, SAST, Service Mesh, WAF About the job Experience: •5+ years related IT and cyber protection experience desired. Required Skills: •Runtime API protection: Implement and tune runtime controls (e.g., behavioral detection, anomaly and abuse prevention, bot defense, schema enforcement, mTLS/OAuth validation, rate limiting, and threat response) across API gateways, service mesh, and edge layers. •Secure API design guidance: Partner with engineering teams to define and promote secure API patterns (authentication/authorization, input validation, error handling, pagination, idempotency, versioning, and least-privilege access). Provide practical guidance aligned to OWASP API Security Top 10 and modern design standards (Open API/JSON Schema). •Automation and integration: Build automation that embeds API security into CI/CD (policy-as-code, automated checks against Open API specs, secrets scanning, SAST/DAST/API testing, and runtime-to-ticket workflows). Reduce friction through reusable tooling and self-service guardrails. •Data analytics and insights: Develop dashboards and analytics using API telemetry and security findings to measure risk, adoption, control effectiveness, and program outcomes. Translate signals into prioritized actions for engineering and leadership. •API security governance: Help define governance for API inventories, ownership, classification, security requirements, exception handling, and control validation. Drive consistent standards across teams while enabling delivery velocity. •DevSecOps lifecycle partnership: Work with product and platform teams to integrate security requirements into backlog planning, threat modeling, design reviews, testing, release readiness, and incident response. •Framework alignment (financial services): Map controls and program outcomes to relevant industry frameworks and expectations (e.g., NIST, ISO 27001, PCI DSS, FAPI, and OWASP guidance). Support audit readiness through clear control documentation and evidence automation. •Continuous improvement and innovation: Evaluate emerging technologies and techniques for API discovery, posture management, and runtime detection. Pilot, measure, and scale what works. Compensation: •$110,000 - $186,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!