API Security Engineer

LEVY PROFESSIONALS
Amstelveen, Netherlands
about 1 month ago
Apply on nl.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) User Authentication Cloud Computing Security Cyber Security OAuth Open Web Application Security Akamai Security Software Session Management Software Security Mitre Att&ck Cybercrime
+1 more
Api Design

Job description

An experienced API Security Engineer to join a central platform team at one of the Netherlands’ leading banks. In this role, you will help shape and strengthen API security across the organization by implementing security standards, automating controls, and ensuring APIs remain resilient against evolving cyber threats.

Working alongside platform engineers, architects, and security specialists, you’ll play a key role in building secure-by-design API platforms that support both customer-facing and internal services.

Outcomes of the project

As an API Security Engineer, you will strengthen the bank’s API security posture by translating security standards and best practices into scalable platform policies and automated security controls. Your work will enable secure API development, improve compliance with internal security requirements, and reduce risk across the enterprise API landscape., As an API Security Engineer, you are responsible for designing, implementing, and continuously improving API security capabilities across a central platform., * Develop and maintain automated API security policies, business rules, and platform guardrails.

  • Assess API security findings and determine their severity, business impact, and remediation priorities.
  • Collaborate with engineers, architects, and security teams to embed security into API design and delivery.
  • Implement security best practices covering authentication, authorization, and API protection mechanisms.
  • Ensure APIs comply with internal security standards and industry frameworks.
  • Drive continuous improvements to API security governance and platform capabilities.
  • Help strengthen the organization’s resilience against emerging API threats and vulnerabilities.

Requirements

  • Proven experience with API Security platforms such as Akamai Noname, Salt Security, or Cequence.
  • Strong understanding of cybersecurity principles and security architecture.
  • Experience with cloud security and application security architecture.
  • Extensive knowledge of API and application security frameworks including OWASP Top 10, MITRE ATT&CK, and CVE.
  • Advanced knowledge of authentication and authorization technologies, including:
  • OAuth 2.0
  • JWT
  • Mutual TLS (mTLS)
  • Session management
  • Object-Level Authorization
  • Attribute-Level Authorization
  • Experience translating security requirements into practical platform policies and automated controls.
  • Strong analytical skills with the ability to evaluate API security risks and recommend effective improvements.

About the company

Since 2000, Levy Professionals has been connecting highly skilled IT professionals with leading international organizations. With offices in Amsterdam and London, we have built an extensive network of experienced consultants and contractors across Europe. We believe in building lasting relationships and matching the right people with the right projects to create long-term success for both our clients and professionals.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on nl.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil · LIVE

3:15 min

The current state of enterprise APIs and security trends

Pratim Bhosale Pratim Bhosale · World Congress 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:58 min

Application performance and its direct business impact

Jérôme Vieilledent · LIVE

Videos

See all

Related articles

See all