See more Collapse

Security Software Engineer

1 month ago


Cincinnati, United States Marvel Technologies Inc Full time
Job DescriptionJob Description

Security Software Engineer - API Consultant

Cincinnati, OH

6 months

Job Description

Security Engineer focused on API Security and Runtime Defense

TECHNICAL SKILLS- Must Have:

API Development

API Discovery

API Gateway

AWS API Gateway

CI/CD

DevOps

Runtime Defense

Security Engineering

FUNCTION:

Securing APIs is essential to "shifting left" the technology development at the Bank. The Individual will participate in technical conversations to determine API security risks, help establish an API runtime defense and discovery strategy leveraging relevant tooling. They will write and define API patterns while also creating the business and security requirements. They will write requirements with threat modeling in mind to assist engineers with building securely.

They will meet with stakeholders and determine criticality of controls and work with application owners to create patterns. They will collaborate with technical and business stakeholders to address Information Security risks while achieving business objectives, meeting regulatory requirements, and addressing emerging threats.

Responsible for providing expertise and support on decisions and priorities regarding the enterprise's overall Information Security strategy and posture. Responsible and accountable for risk by openly exchanging ideas and opinions, elevating concerns, and personally following policies and procedures as defined.

Accountable for always doing the right thing for customers and colleagues, and ensures that actions and behaviors drive a positive customer experience. While operating within the Bank's risk appetite, achieves results by consistently identifying, assessing, managing, monitoring, and reporting risks of all types.

MINIMUM KNOWLEDGE, SKILLS AND ABILITIES REQUIRED:

  • Bachelor's degree in a relevant technology field or equivalent combination of education and work experience.
  • 8+ years of engineering or other IT/Security work experience relevant to the position.
  • Five or more years of interdisciplinary experience in 4 or more of the following:
  • Access Control Systems, Application Security, Application SDLC, Operating Systems, Cryptographic Controls, API Security, API Scanning, Experience with secure development tooling, and Networking.
  • Excellent communications skills as well as the ability to build effective relationships with business leaders and stakeholders. Ability to manage multiple, diverse tasks simultaneously and effectively prioritize work; strong organizational skills in a results-oriented environment.
  • Willingness to work in a highly-collaborative environment.
  • Ability to effectively communicate with technical and non-technical stakeholders.
  • Solid understanding of IT security best practices.
  • Skilled in designing, implementing, and supporting complex technical solutions. Ability to troubleshoot complex operational issues.
  • Extensive experience designing, developing, and implementing serverless solutions within AWS.
  • Extensive development experience with different API capabilities.
  • Experience with development/engineering of API runtime defense and scanning tools
  • Experience in building and deploying CI/CD pipelines.
  • Familiarity with OWASP
  • Previous experience automating security controls within CI/CD pipelines a plus.
  • Previous microservice development a plus.
  • Previous experience in application vulnerability remediation a plus.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

Provides expert technical insight and industry perspective in the creation, delivery, and integration of complex and comprehensive security solutions for securing APIs.

Acts as an internal consultant, advocate, mentor, and change agent.

Viewed as an Information Security expert and critical technical resources across multiple technical areas and business segments.

Partners with other groups to ensure solid, cross-functional decisions are made as a team.

Maintains and demonstrates a strong understanding of enterprise systems, policies, standards, regulatory requirements, and business drivers.

Represents Information Security at enterprise review meetings (ITAC, NPI Reviews, Production Readiness, etc.).

Adheres to and promotes compliance to Information Security policies, standards and best practices.

Leads process improvement and risk mitigation initiatives.

This position will perform the following functions:

API Security

API runtime engineering (Akamai, Neosec, Noname)

Testing

API Architecture

API Design and Lifecycle management

Work with other dev teams to integrate new security-focused API initatives and provide support to IT Teams through API integrations.

Provide clear and concise documentation on delivered code as well as customer onboarding and support documentation

Work collaboratively in an agile environment

Nice to Have:

API Management


We have other current jobs related to this field that you can find below


  • Cincinnati, United States Apex Systems Full time

    Job#: 2036846 Job Description: FUNCTION: The Individual will participate in technical conversations to determine API security risks, help establish an API scanning strategy specifically around API Security scanning, discovery and tooling. They will write and define API patterns while also creating the business and security requirements. They will write...


  • Cincinnati, United States Compunnel Full time

    Description: The Individual will participate in technical conversations to determine API security risks, help establish an API scanning strategy specifically around API Security scanning, discovery and tooling. They will write and define API patterns while also creating the business and security requirements. They will write requirements with threat modeling...


  • Cincinnati, United States JobRialto Full time

    Description: The Individual will participate in technical conversations to determine API security risks, help establish an API scanning strategy specifically around API Security scanning, discovery and tooling. They will write and define API patterns while also creating the business and security requirements. They will write requirements with threat modeling...

  • Senior Engineer

    3 weeks ago


    Cincinnati, United States SLK Software Services Pvt LTD Full time

    About SLK SLK is a global technology services provider focused on bringing AI, intelligent automation, and analytics together to create leading-edge technology solutions for our customers through a culture of partnership, led by an evolutionary mindset. For over 20 years, we've helped organizations across diverse industries - insurance providers, financial...

  • Software Engineer

    2 weeks ago


    Cincinnati, United States Brooksource Full time

    Software EngineerContract-to-HireHybrid 4 days onsite (Cincinnati, OH) SUMMARY:As a member of an agile squad, responsible for implementing new features and enablingcapabilities using modern software engineering tools and practices. Adheres to practices andstandards, set by communities of practice, and contributes to a culture of continuous improvement....

  • Software Engineer

    2 weeks ago


    Cincinnati, United States Brooksource Full time

    Software EngineerContract-to-HireHybrid 4 days onsite (Cincinnati, OH) SUMMARY:As a member of an agile squad, responsible for implementing new features and enablingcapabilities using modern software engineering tools and practices. Adheres to practices andstandards, set by communities of practice, and contributes to a culture of continuous improvement....


  • Cincinnati, United States Fifth Third Bank, N.A. Full time

    Make banking a Fifth Third better® We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank. GENERAL FUNCTION: Designs and implements software solutions as a member of an agile squad. Being assigned to an agile squad means this role also participates in all agile ceremonies...


  • Cincinnati, United States Smartwork IT Services Full time

    Job DescriptionJob DescriptionTitle: Java Software EngineerLocation: Cincinnati, OH (Local only)Hybrid OnsiteJob Type: Contract - W2JOB DESCRIPTION: Full lifecycle application developmentDesigning, coding and debugging applications in various software languages.Software analysis, code analysis, requirements analysis, software review, identification of code...

  • Lead Software Engineer

    2 months ago


    Cincinnati, Ohio, United States Fifth Third Bank Full time

    Make banking a Fifth Third betterWe connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.GENERAL FUNCTION:Designs and implements software solutions as a member of an agile squad. Being assigned to an agile squad means this role also participates in all agile ceremonies driving...


  • Cincinnati, United States Technology Consulting, Inc. Full time

    TCI has an immediate need for a Senior Java Software Engineer in Cincinnati, OH. Onsite 4-5 days SEEKING LOCAL OR REGIONAL CANDIDATES ONLY. This is not a C2C opportunity. This is a long-term contract opportunity with the possibility of extensions. NOTE: THIS POSITION REQUIRES US CITIZENSHIP OR PERMANENT RESIDENCE (GREEN CARD). SUMMARY The Senior Java...


  • Cincinnati, United States JobRialto Full time

    Description Full lifecycle application development Designing, coding and debugging applications in various software languages. Software analysis, code analysis, requirements analysis, software review, identification of code metrics, system risk analysis, software reliability analysis Object-oriented Design and Analysis (OOA and OOD) Software modeling and...


  • Cincinnati, United States TCI Technology Consulting Inc Full time

    TCI has an immediate need for a Senior Java Software Engineer in Cincinnati, OH. Onsite 4-5 days SEEKING LOCAL OR REGIONAL CANDIDATES ONLY. This is not a C2C opportunity. This is a long-term contract opportunity with the possibility of extensions.NOTE: THIS POSITION REQUIRES US CITIZENSHIP OR PERMANENT RESIDENCE (GREEN CARD).SUMMARYThe Senior Java Software...


  • Cincinnati, United States TCI Technology Consulting Inc Full time

    TCI has an immediate need for a Senior Java Software Engineer in Cincinnati, OH. Onsite 4-5 days SEEKING LOCAL OR REGIONAL CANDIDATES ONLY. This is not a C2C opportunity. This is a long-term contract opportunity with the possibility of extensions.NOTE: THIS POSITION REQUIRES US CITIZENSHIP OR PERMANENT RESIDENCE (GREEN CARD).SUMMARYThe Senior Java Software...


  • Cincinnati, United States CBTS Full time

    W-2 Only /Onsite 5 days in Cincinnati, OH 45227/ Pay $70 -$80 per hour W-2/Contract 12+Mon CBTS is searching for software engineer with DevOps and Platform engineering skills that will be responsible for building outstanding software solutions to drive the success of a business. Build various aspects of the company's infrastructure to power innumerable...


  • Cincinnati, United States CBTS Full time

    W-2 Only /Onsite 5 days in Cincinnati, OH 45227/ Pay $70 -$80 per hour W-2/Contract 12+Mon CBTS is searching for software engineer with DevOps and Platform engineering skills that will be responsible for building outstanding software solutions to drive the success of a business. Build various aspects of the company's infrastructure to power innumerable...


  • Cincinnati, United States Compunnel Full time

    Must have: JAVA SQL Agile experience Git/Jenkins Angular/REACT Nice to have: Spring Boot Spring Framework RESTful web services Python Power Description Strong in API Management – 10+ years’ experience REQUIRED Designs and implements software solutions as a member of an agile squad. Being assigned to an agile squad means this role also...


  • Cincinnati, United States Compunnel Full time

    Must have: JAVA SQL Agile experience Git/Jenkins Angular/REACT Nice to have: Spring Boot Spring Framework RESTful web services Python Power Description Strong in API Management – 10+ years’ experience REQUIRED Designs and implements software solutions as a member of an agile squad. Being assigned to an agile squad means this role also...


  • Cincinnati, United States CBTS Full time

    Responsibilities: Full lifecycle application development Designing, coding and debugging applications in various software languages.Software analysis, code analysis, requirements analysis, software review, identification of code metrics, system risk analysis, software reliability analysis Object-oriented Design and Analysis (OOA and OOD)Software modeling and...


  • Cincinnati, United States CBTS Full time

    Responsibilities: Full lifecycle application development Designing, coding and debugging applications in various software languages.Software analysis, code analysis, requirements analysis, software review, identification of code metrics, system risk analysis, software reliability analysis Object-oriented Design and Analysis (OOA and OOD)Software modeling and...


  • Cincinnati, United States FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor of Computer Engineering Travel Percentage : 0% Job Description At Worldpay you’ll have the opportunity to work on some of the most challenging and relevant issues in financial services and technology. Our talented people empower us, and...