Security Engineer (API Integrations)
Role details
Job location
Tech stack
Job description
We are seeking a dynamic and detail-oriented Security Engineer specializing in API integrations to join our cybersecurity team. In this role, you will be at the forefront of safeguarding our digital infrastructure by designing, implementing, and maintaining robust security solutions that integrate seamlessly with various APIs. Your expertise will help ensure the integrity, confidentiality, and availability of our systems while supporting compliance with industry standards such as ISO 27001, ISO 27000 series, NIST, and FIPS. This position offers an exciting opportunity to work on cutting-edge security projects within a fast-paced environment dedicated to advancing cybersecurity resilience across cloud and on-premises infrastructures., * Develop and implement secure API integration strategies to enhance system interoperability while maintaining high security standards.
- Conduct comprehensive security risk assessments and vulnerability management for API endpoints, ensuring adherence to best practices aligned with NIST standards and ISO frameworks.
- Collaborate with cross-functional teams to design secure network architectures utilizing WAN, LAN, VPNs, and cloud infrastructure such as AWS and Google Cloud Platform.
- Monitor security event management systems like SIEM tools (e.g., Splunk, New Relic) to detect, analyze, and respond to potential threats related to network protocols, IDS/IPS systems, and cybersecurity tools.
- Perform regular security assessments including vulnerability research, penetration testing, system hardening (e.g., SELinux), and incident response planning for IT infrastructure components like Cisco ASA firewalls, Cisco ISE for identity management, and network routing protocols (OSPF, BGP).
- Maintain comprehensive documentation of system security plans (SSPs), incident management procedures, and compliance reports aligned with standards such as PCI DSS, FedRAMP, FISMA, and COBIT.
- Support incident recovery efforts by investigating security breaches involving encryption failures or unauthorized access via VPNs or open-source operating systems like Debian or CentOS.
Requirements
- Proven experience in security engineering with a focus on API integrations within complex IT environments.
- Strong knowledge of computer networking concepts including TCP/IP, DNS, DHCP, IPsec VPNs, load balancing, and network architecture design.
- Hands-on expertise with cybersecurity tools such as SIEM platforms (Splunk), IDS/IPS systems, endpoint detection and response (EDR), and threat detection & response methodologies.
- Familiarity with cloud security engineering principles across AWS, Azure, or Google Cloud Platform environments.
- Working knowledge of security standards including ISO 27001/27000 series, FIPS compliance requirements, NIST frameworks (RMF), and ITIL best practices.
- Experience managing firewalls (Cisco ASA), network support tools (SolarWinds), configuration management (Ansible), scripting languages (Python, Bash), and system administration tasks on Linux/Unix-based OS like Ubuntu or openSUSE.
- Strong analytical skills for vulnerability assessment investigations and security risk analysis; ability to communicate complex technical issues clearly.
Join us if you're passionate about protecting digital assets through innovative security solutions-where your expertise directly impacts our organization's resilience against evolving cyber threats!
Benefits & conditions
Pay: $90,000.00 - $125,000.00 per year