> Markdown version of [/jobs/ext/1341037-api-security-engineer](https://www.wearedevelopers.com/jobs/ext/1341037-api-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # API Security Engineer - **Company:** LEVY PROFESSIONALS - **Location:** Amstelveen, Netherlands - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), User Authentication, Cloud Computing Security, Cyber Security, OAuth, Open Web Application Security, Akamai, Security Software, Session Management, Software Security, Mitre Att&ck, Cybercrime, Api Design - **Published:** July 19, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=9d7543d87f2f4331 ## About the Role * Proven experience with API Security platforms such as Akamai Noname, Salt Security, or Cequence. * Strong understanding of cybersecurity principles and security architecture. * Experience with cloud security and application security architecture. * Extensive knowledge of API and application security frameworks including OWASP Top 10, MITRE ATT&CK, and CVE. * Advanced knowledge of authentication and authorization technologies, including: + OAuth 2.0 + JWT + Mutual TLS (mTLS) + Session management + Object-Level Authorization + Attribute-Level Authorization * Experience translating security requirements into practical platform policies and automated controls. * Strong analytical skills with the ability to evaluate API security risks and recommend effective improvements. ## Description An experienced API Security Engineer to join a central platform team at one of the Netherlands' leading banks. In this role, you will help shape and strengthen API security across the organization by implementing security standards, automating controls, and ensuring APIs remain resilient against evolving cyber threats. Working alongside platform engineers, architects, and security specialists, you'll play a key role in building secure-by-design API platforms that support both customer-facing and internal services. Outcomes of the project As an API Security Engineer, you will strengthen the bank's API security posture by translating security standards and best practices into scalable platform policies and automated security controls. Your work will enable secure API development, improve compliance with internal security requirements, and reduce risk across the enterprise API landscape., As an API Security Engineer, you are responsible for designing, implementing, and continuously improving API security capabilities across a central platform., * Develop and maintain automated API security policies, business rules, and platform guardrails. * Assess API security findings and determine their severity, business impact, and remediation priorities. * Collaborate with engineers, architects, and security teams to embed security into API design and delivery. * Implement security best practices covering authentication, authorization, and API protection mechanisms. * Ensure APIs comply with internal security standards and industry frameworks. * Drive continuous improvements to API security governance and platform capabilities. * Help strengthen the organization's resilience against emerging API threats and vulnerabilities. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Lessons learned from observing a billion API requests](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)