> Markdown version of [/jobs/ext/2250839-senior-backend-api-security-developer](https://www.wearedevelopers.com/jobs/ext/2250839-senior-backend-api-security-developer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Backend/API Security Developer - **Company:** UST Inc - **Location:** Chicago, IL, United States (Remote available) - **Experience:** Expert - **Salary:** $82,000.0 - $123,000.0 - **Contract:** Temporary contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, User Authentication, Cloud Computing, Static Program Analysis, Continuous Integration, Data Masking, DevOps, Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, PostgreSQL, Node.Js, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Role-Based Access Control, Openid Connect, Tokenization, Data Logging, Delivery Pipeline, Software Security, AWS Lambda, Amazon Virtual Private Cloud (VPC), Backend, Rate Limiting, Graphql, Cloudwatch, Api Gateway, Restful APIs, Ddos, Vulnerability Analysis, Microservices - **Published:** August 26, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88151669/1 ## About the Role * Experience with cloud-native development, OWASP API Security standards, OAuth2/OIDC, and large-scale microservices architectures is required. * Skills: AWS, OAuth 2.0, Node.js, PostgreSQL ## Description UST is searching for a Senior Backend/API Security Developer (B2) with strong expertise in Python, Node.js, or Java and AWS, responsible for designing, developing, and securing enterprise-grade APIs that handle highly sensitive data. The opportunity: * Design Secure Architectures: Build scalable RESTful and GraphQL APIs using AWS services like Amazon API Gateway, AWS Lambda, and Amazon VPC while applying the principle of least privilege. * Enforce Strict Authentication: Implement robust identity and access management using OAuth 2.0, OpenID Connect (OIDC), AWS IAM, and Amazon Cognito. * Ensure Regulatory Compliance: Maintain data protection standards required by regulations like HIPAA, GDPR, or PCI-DSS through proper data masking, tokenization, and auditing. * Manage Encryption Standards: Ensure all data in transit uses TLS 1.3 and data at rest is encrypted using AWS Key Management Service (KMS) with customer-managed keys. * Conduct Security Audits: Perform automated security scans, static code analysis, and vulnerability assessments using tools like Amazon Inspector and AWS Security Hub. * Implement Rate Limiting and WAF: Protect backend systems from distributed denial-of-service (DDoS) attacks and injection flaws using AWS WAF and API Gateway throttling controls. * Establish Comprehensive Logging: Configure centralized monitoring and threat detection using Amazon CloudWatch, AWS CloudTrail, and Amazon GuardDuty for complete audit trails. * Collaborate with DevOps engineers in designing and developing CI/CD pipeline using Codepipeline This position description identifies the responsibilities and tasks typically associated with the performance of the position. Other relevant essential functions may be required. What you need: * The ideal candidate will drive API security standards, implement secure architecture patterns, and serve as a key technical leader in building a world-class API engineering practice. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Lessons learned from observing a billion API requests](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Micro-frontends anti-patterns](https://www.wearedevelopers.com/videos/299-micro-frontends-anti-patterns) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [20 Essential Tools For Backend Development](https://www.wearedevelopers.com/magazine/218-20-essential-tools-for-backend-development) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 7 Most Popular Backend Frameworks for Developers](https://www.wearedevelopers.com/magazine/403-the-7-most-popular-backend-frameworks-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference Between Frontend and Backend Development?](https://www.wearedevelopers.com/magazine/240-what-s-the-difference-between-frontend-and-backend-development)