Security Engineer

3 months ago


Phoenix, United States TEKsystems Full time
Job DescriptionJob Description

Top Skills' Details

Threat modeling experience in relation to API’s
How they are build, common attacks, how to defend API’s
Experience when it comes to testing API’s
Either doing vulnerability testing or pen testing
Familiarity with API Gateways
Understanding of authentication/authorization for API’s

Job Description

Seeking a Senior API Security Engineer with proven strong technical competence and leadership capability to contribute towards the success of enterprise wide API security initiatives.The Senior API Security Engineer serves as a subject matter expert in API security, performs threat modeling of APIs and plays an integral role in managing, monitoring & reporting on API security risk reduction. The Senior API Security Engineer supports the security champion practice by evangelizing API security principles and controls.

Primary Responsibilities

• Conduct and facilitate day-to-day threat modeling of web APIs within the established SLAs.
• Document risk management plans for API threat models to effectively communicate residual risks to the business.
• Perform ongoing governance and follow-through with API owners to ensure implementation of threat based requirements.
• Develop, deliver and keep up-to-date API security standard requirements and design patterns.
• Manage ongoing security exceptions to API security standards.
• Perform API security code reviews and attest to API security standard compliance.
• Validate implementation of API security controls against outputs of vulnerability testing tools to enable auditability and verifiability.

• Serve as an API security technical advisor to application teams.

• Evangelize API security design principles.

• Be recognized as an API security subject matter expert within the organization.

Education
• Bachelor's degree in computer science, information systems, cybersecurity, or a related field.
• At least 5 years experience with threat modeling, secure application design and development practices.

Security and Technical Experience
• Direct hands on experience developing and securing web APIs and web applications: REST, SOAP, gRPC.
• Direct hands on experience with security testing of web services and web APIs.
• Solid hands on experience with leading threat modeling exercises for applications and services.
• Direct hands on experience with threat modeling frameworks, attack vectors an vulnerability analysis: CAPEC, ATT&CK, STRIDE.
• Solid understanding of risk management, security architecture and secure SDLC practices.
• Strong experience and understanding of identity and access management controls: OAuth 2.0, OIDC, JWT
• Strong experience and understanding of familiarity with cryptography controls: Data at rest, in motion and in-use.
• Experience with industry standards and frameworks: NIST 800-53, NIST CSF, OWASP, SANS Top 25.
• Experience with Java, Javascript and mobile application development.
• Familiarity with database architectures: Oracle, SQL and NoSQL Databases.

Preferred Security Certifications

• CISSP, SANS GIAC or similar certifications

Key Behaviors/Competencies
• Self-directed, Confident Team Player
• Strong Technical Thinker
• Strong Planning, Execution and Collaborative skills
• Strong Communication skills — Strong verbal and written communication skills. Ability to document risk and control summary artifacts that translates complex threat models into easy to read reports for the business.
• Openness to Learning: Takes personal responsibility for learning and upskilling. Acquires strategies for gaining new knowledge, behaviors and skills. Builds on and applies existing knowledge. Engages in learning from others, inside and outside the organization.
• Adaptability: Demonstrates flexibility within a variety of changing situations, while working with individuals and groups. Changes his or her own ideas or perceptions in response to changing circumstances.
• Business Acumen: Demonstrates an awareness of internal dynamics.



  • Phoenix, Arizona, United States Direct Protection Security Inc. Full time

    Direct Protection Security Inc. is a rapidly growing ADT provider with offices throughout California and other states. We are seeking a highly skilled Security Solutions Engineer to join our dynamic team.The successful candidate will have previous experience in security system installation, maintenance, or related fields. They will be responsible for...

  • Security Engineer

    3 months ago


    Phoenix, United States TEKsystems Full time

    Job DescriptionJob DescriptionTop Skills' DetailsThreat modeling experience in relation to API’sHow they are build, common attacks, how to defend API’sExperience when it comes to testing API’sEither doing vulnerability testing or pen testingFamiliarity with API GatewaysUnderstanding of authentication/authorization for API’sJob DescriptionPosition...


  • Phoenix, United States TEKsystems Full time

    Job DescriptionJob Description1. Experienced in technical security controls assessment and remediation.2. Threat identification, analysis, and threat modeling3. Technical security experience in 2 of the following:a. Cloudb. Networkc. OSd. Applicatione. Data Storagef. Data & Complianceg. Encryptionh. Infrastructurej. IOTk. Carrier NetworkCybersecurity...

  • Security Engineer

    1 month ago


    Phoenix, United States Diverse Lynx Full time

    Job Tittle: Security EngineerOnsite - Phoenix, AZContract RoleWhat are the top 3 skills required for this role? 1. Threat modelling and endpoint security 2. AWS or Azure cloud experience 3. Application & Cloud Security expertise Job Description/ Responsibilities •Good hands-on app security architect with Cloud security skills •Good knowledge on...

  • Security Engineer

    5 months ago


    Phoenix, United States Diverse Lynx Full time

    Job Tittle: Security EngineerOnsite - Phoenix, AZContract RoleWhat are the top 3 skills required for this role? 1. Threat modelling and endpoint security 2. AWS or Azure cloud experience 3. Application & Cloud Security expertise Job Description/ Responsibilities • Good hands-on app security architect with Cloud security skills • Good knowledge on...


  • Phoenix, Arizona, United States Motion Recruitment Full time

    Job Title: Senior Security EngineerA regional bank based in Arkansas seeks a seasoned Senior Security Engineer and HashiCorp Vault SME to join their growing team. This engineer will be responsible for owning Vault, implementing new features, and onboarding other teams to utilize its capabilities.The ideal candidate will have 10+ years of experience in...


  • Phoenix, Arizona, United States Saxon Global Full time

    Cloud Security Engineer WantedSaxon Global is seeking a highly skilled Cloud Security Engineer to join our team. As a Cloud Security Engineer, you will be responsible for managing and administering application access in the cloud.About the Role:We are looking for an individual with 3-5 years of experience in Application Access Management, with expertise in...


  • Phoenix, Arizona, United States TEKsystems Full time

    About the RoleTEKsystems is seeking an experienced Endpoint Security Engineer to join our team. As a key member of our Security Incident Response Engineering (SIRE) team, you will be responsible for managing multiple critical security tools and applications that protect against security threats.Job ResponsibilitiesPrimary focus on operational management,...


  • Phoenix, United States Diverse Lynx Full time

    Job Summary: What are the top skills required for this role? 1. API 2. Apigee 3. Hands on WebAPI, and web apps: REST, SOAP, gRPC 4. Knowledge of Java, JavaScript or mobile app development 5. Knowledge of project management desirable Job Description/ Responsibilities Client is seeking a Senior API Security Engineer with proven strong technical competence and...


  • Phoenix, United States Diverse Lynx Full time

    Job Summary: What are the top skills required for this role? 1. API 2. Apigee 3. Hands on WebAPI, and web apps: REST, SOAP, gRPC 4. Knowledge of Java, JavaScript or mobile app development 5. Knowledge of project management desirable Job Description/ Responsibilities Client is seeking a Senior API Security Engineer with proven strong technical competence and...


  • Phoenix, Arizona, United States Mindlance Full time

    About the PositionWe are looking for a highly skilled Security Operations Engineer to join our team at Mindlance. As a key member of our Cloud Security Operations Team, you will be responsible for maintaining the security and integrity of our cloud-based infrastructure.Estimated salary: $180,000 - $250,000 per year.About the RoleThis is a challenging and...


  • Phoenix, United States The Charles Schwab Corporation Full time

    The Senior Endpoint Security Engineer is an individual contributor supporting endpoint security technologies, threat monitoring and management in Schwab Cybersecurity Services. This role leads the security and infrastructure teams on the design, engi Security Engineer, Security, Engineer, Senior, Technology

  • Jr Security Engineer

    3 months ago


    Phoenix, United States TEKsystems Full time

    Job DescriptionJob Description Job DescriptionParticipate in security consulting on small projects for internal clients to ensure uniformity with corporate information, security policy, and standards. Track or remediate vulnerabilities and security issues. Review and correlate security logs. Assist with the design, documentation, testing, maintenance, and...


  • Phoenix, United States AAA NCNU Full time

    Job DescriptionJob DescriptionWhy Work For Us?Great Pay - opportunity to participate in AAA discretionary annual incentive plan or other incentive plans depending upon position401k Matching – $1 for $1 company match up to 6% of eligible earnings per pay periodBenefits – Medical, Dental, Vision, wellness program and more!Paid HolidaysPaid Time Off –...


  • Phoenix, Arizona, United States Cambridge Investment Research (USA) Full time

    Cambridge Investment Research (USA) is a top independent financial solutions firm committed to fostering an inclusive and dynamic work environment. We are seeking a skilled CLOUD SECURITY ENGINEER to join our IT Security Team.About the RoleThe ideal candidate will bring expertise in Azure security tools and architecture, working closely with IT and IS teams...


  • Phoenix, United States HireRising Full time

    Cyber Security EngineerJob Summary: The Cybersecurity Engineer is a senior-level position responsible for meeting a variety of technical, security, and compliance needs for our clients. This position also safeguards information system assets and networks by identifying and solving potential and actual security problems and identifying and resolving...


  • Phoenix, United States HireRising Full time

    Cyber Security EngineerJob Summary: The Cybersecurity Engineer is a senior-level position responsible for meeting a variety of technical, security, and compliance needs for our clients. This position also safeguards information system assets and networks by identifying and solving potential and actual security problems and identifying and resolving...


  • Phoenix, United States Resource Informatics Group Full time

    Network / Cyber Security Engineer - Senior (6-10 Yrs) Phoenix, AZ - locals ContractDescription: Network Security Engineer is an individual contributor supporting various network security technologies. This role works with various Client's technology and security teams on the engineering and implementation of technology solutions and methodologies to ensure...


  • Phoenix, United States Focused HR Solutions Remote Work Freelance Full time

    This job is hybrid and this will be a mix of remote and  on site in Phoenix AZ.   Our direct client has an opening for a   Security Engineer  1323     Please send us your rate and resume.    This position is up to  2 years with the option of extension. The client is in   Phoenix, AZ.    Please send us your rate and resume  Work Location...


  • Phoenix, United States ServicePoint IT Full time

    PLEASE READ BEFORE APPLYING. This position is NOT available for 3rd party vendors. Do not apply if you can work on a W2 basis. Service Point has a customer seeking a Network Security Engineer for a 6 month+ remote opportunity working 8AM-5PM Monday Friday.Individuals must be located in either Columbus OH or Phoenix Arizona since they will be asked to go into...