API Security Engineer

KeyBank - United States

Hiring: API Security Engineer Company: KeyBank Location: United States Job Posted Time: 2026-09-16 23:30:29 Employment Type: Hybrid Target Skills & Keywords : API Gateway, Bash, CI/CD, DAST, DNS, GraphQL, IAM, JWT, JavaScript, Kubernetes, Linux, Microservices, OAuth2, OIDC, OWASP, OpenAPI, Penetration Testing, PowerShell, Python, RBAC, REST, SAST, SCA, SIEM, SOC, SQL, Swagger, TLS, WAF About the job Experience: •Demonstrated professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering. •Hands-on experience deploying and supporting enterprise API security, application security, API gateway, and traffic-monitoring technologies is strongly preferred. Required Skills: •We are seeking an experienced •With expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling •This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments. •The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation. •Deploy, configure, administer, and optimize enterprise API security platforms and controls. •Perform continuous API discovery, inventory, classification, and security posture management. •Identify shadow, rogue, zombie, deprecated, and undocumented APIs. •Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns. Qualifications: •Applied hands-on capability in enterprise API security technologies. •Understanding of eBPF-based agent/sensor deployment and troubleshooting in Linux, Kubernetes, containerized, and cloud environments. •Strong knowledge of HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures. •In-depth knowledge of the OWASP API Security Top 10 and OWASP Top 10. •Knowledge of OAuth 2.0, OIDC, JWT, API keys, IAM, RBAC, and modern API authorization models. •Solid functional working knowledge of public cloud platforms, Kubernetes, containers, Linux, and microservices. •Demonstrated capacity to troubleshoot complex integrations across applications, gateways, middleware, networks, security controls, and cloud infrastructure. •Demonstrated capacity to work directly with developers, architects, API gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams. •Advanced experience integrating security platforms with cloud-based API management solutions and enterprise gateway appliances. •Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience; or An equivalent combination of college education, technical training, industry certifications, and hands-on cybersecurity experience. Compensation: •$116,000 - $216,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!