Job Title: Senior API Security Engineer
Location: USA
Duration: Full Time and Contract.
Must-Have:
• Direct hands on experience developing and securing web APIs and web applications: REST, SOAP, gRPC.
• Direct hands-on experience with security testing of web services and web APIs.
• Solid hands-on experience with leading threat modeling exercises for applications and services.
• Solid understanding of risk management, security architecture and secure SDLC practices.
• Strong experience and understanding of API identity and access management controls: OAuth 2.0, OIDC, JWT
• Strong experience and understanding of familiarity with cryptography controls: Data at rest, in motion and in-use.
• Experience with industry standards and frameworks: NIST 800-53, NIST CSF, OWASP, SANS Top 25.
• Experience with Java, JavaScript and mobile application development.
• Familiarity with database architectures: Oracle, SQL and NoSQL Databases.
• Information security professional certifications such as SANS GIAC, CISSP, CISM.
• Experience with service-oriented architectures and web services security.