> Markdown version of [/jobs/ext/803102-api-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/803102-api-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # API Application Security Engineer - **Company:** Job Cloud Inc. - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, JavaScript (Programming Language), Application Programming Interfaces (APIs), Application Firewall, Application Layers, Audit Trail, User Authentication, Code Review, Cyber Security, Continuous Delivery, Continuous Integration, Github, JSON, Python (Programming Language), OAuth, Open Web Application Security, Akamai, Secure Coding, Security Information and Event Management, Software Engineering, Scripting, Software Security, Veracode, Github Enterprise, Graphql, Checkmarx, Api Gateway, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 11, 2026 - **Apply:** https://www.dice.com/job-detail/4d9d9c78-d389-45e8-9850-e1651e4dff51 ## About the Role * Minimum of three years of experience in application security, DevSecOps, or API security engineering roles * Hands on experience with GitHub Enterprise administration and GitHub Advanced Security * Experience with API security tools, with preference for Akamai Noname or comparable platforms * Working knowledge of REST and GraphQL architecture, authentication methods such as OAuth, API keys, and JSON web tokens, and common API vulnerabilities * Familiarity with continuous integration pipelines, container security practices, and software supply chain risk management * Proficiency in a scripting language such as Python or JavaScript for automation purposes * Strong communication skills with the ability to engage both engineering and security stakeholders, * GitHub Advanced Security certification or equivalent training * Experience with Akamai App and API Protector or related Akamai security solutions * Background with static application security testing, dynamic application security testing, and software composition analysis tools such as Snyk, Veracode, or Checkmarx * Familiarity with software security maturity frameworks such as OWASP SAMM or BSIMM ## Description API Application Security Engineer with deep expertise in application security and API security. This role supports two key capability areas: securing the enterprise software development lifecycle through GitHub Enterprise and driving API discovery, risk management, and protection through Akamai Noname. This position operates at the intersection of DevSecOps and API security, partnering with development, platform, and security teams to reduce risk across the application layer and strengthen security posture at scale. Core Responsibilities GitHub Enterprise Security * Administer and govern GitHub Enterprise security configurations, including branch protection, secret scanning, code scanning, and Dependabot * Design and enforce security policies across GitHub organizations, repositories, and Actions workflows * Integrate GitHub Advanced Security into continuous integration and continuous delivery pipelines to enable automated vulnerability detection * Partner with development teams to establish secure coding standards and efficient remediation workflow * Monitor and respond to GitHub security alerts, audit logs, and policy violations * Develop automation and tool to strengthen software supply chain security controls API Security with Akamai Deploy and configure Akamai Noname for API discovery, inventory management, and enterprise risk assessment * Identify shadow APIs, misconfigured endpoints, and anomalous API traffic patterns using behavioral analytics * Develop API security policies, alerting rules, and response playbooks in collaboration with application and security operations teams * Integrate Noname with API gateways, web application firewalls, and existing security tooling such as SIEM and SOAR platforms * Conduct API security assessments and deliver remediation guidance to development and platform teams ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)