API Application Security Engineer

Job Cloud Inc.
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security JavaScript (Programming Language) Application Programming Interfaces (APIs) Application Firewall Application Layers Audit Trail User Authentication Code Review Cyber Security Continuous Delivery Continuous Integration Github
+19 more
JSON Python (Programming Language) OAuth Open Web Application Security Akamai Secure Coding Security Information and Event Management Software Engineering Scripting Software Security Veracode Github Enterprise Graphql Checkmarx Api Gateway Devsecops Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

API Application Security Engineer with deep expertise in application security and API security. This role supports two key capability areas: securing the enterprise software development lifecycle through GitHub Enterprise and driving API discovery, risk management, and protection through Akamai Noname.

This position operates at the intersection of DevSecOps and API security, partnering with development, platform, and security teams to reduce risk across the application layer and strengthen security posture at scale.

Core Responsibilities

GitHub Enterprise Security

  • Administer and govern GitHub Enterprise security configurations, including branch protection, secret scanning, code scanning, and Dependabot
  • Design and enforce security policies across GitHub organizations, repositories, and Actions workflows
  • Integrate GitHub Advanced Security into continuous integration and continuous delivery pipelines to enable automated vulnerability detection
  • Partner with development teams to establish secure coding standards and efficient remediation workflow
  • Monitor and respond to GitHub security alerts, audit logs, and policy violations
  • Develop automation and tool to strengthen software supply chain security controls API Security with Akamai

Deploy and configure Akamai Noname for API discovery, inventory management, and enterprise risk assessment

  • Identify shadow APIs, misconfigured endpoints, and anomalous API traffic patterns using behavioral analytics
  • Develop API security policies, alerting rules, and response playbooks in collaboration with application and security operations teams
  • Integrate Noname with API gateways, web application firewalls, and existing security tooling such as SIEM and SOAR platforms
  • Conduct API security assessments and deliver remediation guidance to development and platform teams

Requirements

  • Minimum of three years of experience in application security, DevSecOps, or API security engineering roles
  • Hands on experience with GitHub Enterprise administration and GitHub Advanced Security
  • Experience with API security tools, with preference for Akamai Noname or comparable platforms
  • Working knowledge of REST and GraphQL architecture, authentication methods such as OAuth, API keys, and JSON web tokens, and common API vulnerabilities
  • Familiarity with continuous integration pipelines, container security practices, and software supply chain risk management
  • Proficiency in a scripting language such as Python or JavaScript for automation purposes
  • Strong communication skills with the ability to engage both engineering and security stakeholders, * GitHub Advanced Security certification or equivalent training
  • Experience with Akamai App and API Protector or related Akamai security solutions
  • Background with static application security testing, dynamic application security testing, and software composition analysis tools such as Snyk, Veracode, or Checkmarx
  • Familiarity with software security maturity frameworks such as OWASP SAMM or BSIMM

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:58 min

Application performance and its direct business impact

Jérôme Vieilledent · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all