Senior API Security Engineer - W2 only

Overview

Remote
Hybrid
Depends on Experience
Contract - W2
No Travel Required

Skills

Cloudflare
cryptography
API-management
collaboration
documentation
Python
multitasking

Job Details

Location: Hybrid - Onsite in McLean or Plano, TX Tuesday through Thursday; Open to Remote - prefers local candidates
Duration: 3-6 months contract with a possibility to convert to full-time

Job Summary:
We are seeking an experienced Senior API Security Engineer to join our Endpoint Security team. The ideal candidate will have a strong background in IT security, with specific skills in API security implementation using Cloudflare. This role involves close collaboration with API teams to ensure the design and implementation of secure API patterns and contributes directly to our overall security posture.

Key Responsibilities:

  • Configure and evaluate API security using Cloudflare's API gateway and API shield.
  • Work closely with API owners and architectural teams to understand and secure the company's API ecosystem.
  • Design and document secure API design patterns in collaboration with API teams.
  • Provide support to the Cyber Security Operations Center and assist with the management of security policies.
  • Coordinate with other teams to ensure efficient deployment of new security policies and troubleshoot issues impacting systems.
  • Participate in an on-call rotation for security emergencies.
  • Ensure compliance with IT security standards, policies, and procedures.

Required Qualifications:

  • 5-7 years of relevant experience in IT Security.
  • Hands-on experience with Cloudflare, focusing on API security implementation.
  • Deep understanding of cryptography, including hashing, signing, and symmetric/asymmetric encryption and decryption.
  • Proven experience in the decryption of API traffic for security inspection, such as mTLS and TLS 1.3.
  • Proficiency in API management platforms like MuleSoft and Apigee.
  • Demonstrated ability to assess and secure APIs in alignment with OWASP and other security standards.
  • Familiarity with industry security regulations and frameworks such as MITRE Attack Framework, NIST, and CIS CSC.
  • Strong documentation skills and ability to work independently as well as part of a team.

Preferred Skills:

  • Python scripting and automation experience.
  • Strong organizational skills and the ability to multitask.
  • Excellent communication skills and the ability to work with diverse teams.

Keys to Success in this Role:

  • Ability to perform independently and as part of a cross-functional team.
  • Strong analytical skills and a problem-solving attitude.
    • Passion for staying up to date with the latest security practices and standards.