Position Overview
Seeking an experienced Kong External API Gateway (KEG) engineer to support Mythos-related security fixes, patching, and platform optimization. KEG serves as Client's enterprise boundary enabling APIs to communicate with external vendors and partners. This role requires deep expertise in API Gateways, containerized environments, and comprehensive testing practices including performance validation. (Previous Kong experience very helpful)
A Good Fit for Team Norms
- A "if I don't know it, I know I can learn it" attitude.
- Knowledge of agile development principles.
- Excellent client communication skills.
- Hands on experience being part of a "you build it, you run it" team.
Core Expectations
- Ability to rapidly evaluate changes for impact and risk before implementation.
- robust debugging and troubleshooting skills with ability to trace issues across the stack.
- Collaborative approach to working with clients and internal teams during incident response.
- Self-directed in testing and validation - thorough and comprehensive approach.
- Comfortable with net new development when needed, not just maintenance work.
- Empathy for API creators and consumers.
Key Focus Areas for This Engagement
- Rapid Change Implementation: Evaluate changes for impact, implement safely, validate thoroughly
- Comprehensive Stack Testing: Build and execute test suites for Kong configurations, plugins, and integrations
- Security Patching: Apply and validate security patches for Kong Gateway and related components
- Issue Tracing & Debugging: Work with clients to trace issues through gateway upstream services
- Performance Testing: Conduct load testing and performance validation for Kong configurations
- Production Support: Troubleshoot and resolve production issues in Kong Gateway environments
- Net New Development: Implement new Kong plugins, configurations, and integrations as needed
- Documentation: Maintain clear documentation for configurations, troubleshooting, and procedures
Core Skill Layers
The ideal candidate will have coverage across these four stacked skill layers:
- Network layer Routing, TLS, connectivity, DNS, load balancing
- Policy layer Authentication, authorization, rate limiting, security controls
- Gateway layer Kong services, routes, plugins, configuration management
- Delivery layer CI/CD, config management, governance, standardization
Required Domain Knowledge
API Gateway Fundamentals
- Deep understanding of API gateway patterns - Ingress, egress, routing at the enterprise boundary
- Request/response lifecycle through a gateway
- Understanding upstream vs downstream services
- Traffic shaping, routing rules, and service abstraction
- Knowledge of how gateways function as entry/exit points for external vendor communication
Testing & Quality Assurance
- Experience with performance testing tools
- Experience with load testing
- Proficiency in TDD and BDD methodologies
- (Nive to have) Experience testing Kong plugins and custom configurations
- Knowledge of API contract testing (PACT or similar)
- Experience with chaos engineering and resiliency testing
Configuration Management & Delivery
- Declarative config vs imperative config approaches - robust understanding of tradeoffs
- Experience managing large-scale gateway configurations across multiple instances
- CI/CD pipelines for gateway changes - Automated testing and deployment
- Environment promotion patterns (dev test prod)
- Versioning and rollback strategies for gateway configs
- Experience reducing configuration complexity and improving deployment velocity
- Understanding of standardized patterns vs flexible configurations
Cloud & Platform Engineering
- robust experience with Docker
- (Required) AWS ECS
- (Nice to have) Running Kong in containerized environments
- Experience deploying containerized environments (Docker, ECS)
- Infrastructure provisioning (ECS patterns)
- Horizontal scaling and stateless patterns - Gateway scaling strategies
- Networking fundamentals (DNS, load balancing, TLS termination)
- Secrets and credential management for gateway configurations
- Knowledge of container orchestration, scaling, and health checking
API & Development
Primary Languages:
- Experience developing in one or more additional languages (Java, Python, Node.js, TypeScript)
- robust familiarity with API response codes
- (Nice to have) Lua - Helpful for Kong plugin development and customization
- (Nice to have) ReST API creator & consumer experience.
Development Experience:
- robust understanding of API best practices (RESTful design, API spec-driven development, OpenAPI/Swagger)
- Knowledge of API Gateway patterns and microservices architecture
- Experience with API versioning, deprecation strategies, and backward compatibility
- Experience with YAML for declarative Kong configuration
Observability & Operations
- Request tracing through gateway upstream service - Full-path visibility required
- Debugging gateway vs backend issues - Gateway sits in the middle of every request path
- robust experience with observability and telemetry tools:
- Splunk - Log aggregation and investigation (required for Vanguard environment)
- Honeycomb - Distributed tracing and observability
- Experience with OpenTelemetry instrumentation
- Logging expertise (access logs, audit logs)
- Metrics analysis (latency, error rates, throttling behavior)
- Alerting and incident response for gateway issues
- Log tracing across distributed systems
- Performance profiling and debugging using telemetry data
Kong Platform & Plugin Engineering
- Deep hands-on experience with Kong Gateway (Kong Konnect)
- Proficiency in Lua - Kong's core language for plugin development
- Experience with OpenResty/Nginx - Kong's underlying runtime platform
- Kong architecture mastery - Services, routes, consumers, plugins
- Plugin configuration and lifecycle management
- Custom plugin development
- Understanding plugin execution order and chaining
- Experience managing plugin sprawl and driving standardization
- Experience with Kong configuration management (declarative config with decK, DB-less mode)
- Knowledge of Kong Admin API, Control Plane, and Data Plane architecture
Security & Traffic Control
- Proven experience applying security patches and updates to production environments
- Authentication patterns - External auth flows, internal auth flows, consumer-level controls
- Authorization enforcement - Consumer-level, route-level authorization
- mTLS and secure communication patterns - Certificate management, mutual TLS
- Rate limiting, throttling, quota enforcement - Protecting backend services
- Threat protection - WAF-style controls, bot protection, DDoS mitigation
- robust understanding of API security patterns (OAuth 2.0, OpenID Connect, JWT)
- Experience implementing security plugins
- Knowledge of vulnerability scanning and remediation for Kong and its dependencies
- Familiarity with Client's OAuth mechanisms (CA Gateway, CredaaS) - or ability to learn quickly
- Understanding of trust boundaries at the enterprise edge
- A robust understanding of DevSecOps concepts
Helpful Skill Sets
API Lifecycle & Governance
- Understanding of API onboarding processes
- Working knowledge of standardized gateway patterns (golden paths, templates)
- Familiarity with governance requirements for external API exposure
- Understanding of policy enforcement (security, compliance, audit requirements)
- Experience working with API consumers (partners, vendors, internal applications)
Integration & External Connectivity
- External partner integration patterns - API Gateway s unique role at enterprise boundary
- Vendor connectivity patterns (security, routing, trust boundaries)
- Hybrid cloud / external routing considerations
- Managing contracts at the API boundary
Developer Experience & Enablement
- Ability to work with development teams during KEG onboarding
- Experience using templates and patterns for gateway configuration
- robust documentation skills for configurations and troubleshooting procedures
- Supporting diverse tech stacks
Delivery & Infrastructure
- Familiarity with CI/CD pipelines, especially for deploying Kong using IaC (Infrastructure as Code)
- Experience with AWS services and deploying Kong on AWS infrastructure
- Infrastructure-as-code tools (CloudFormation)
- Understanding of Multi Region / Out of Region strategy
- Working understanding of High Availability concepts and failover patterns
- Understanding of Resiliency concepts (circuit breakers, retry policies, timeouts)