Security Engineer
2 months ago
Top Skills' Details
- Threat modeling experience in relation to API’s
- How they are build, common attacks, how to defend API’s
- Experience when it comes to testing API’s
- Either doing vulnerability testing or pen testing
- Familiarity with API Gateways
- Understanding of authentication/authorization for API’s
Job Description
Position Summary
Seeking a Senior API Security Engineer with proven strong technical competence and leadership capability to contribute towards the success of enterprise wide API security initiatives.The Senior API Security Engineer serves as a subject matter expert in API security, performs threat modeling of APIs and plays an integral role in managing, monitoring & reporting on API security risk reduction. The Senior API Security Engineer supports the security champion practice by evangelizing API security principles and controls.
Primary Responsibilities
• Conduct and facilitate day-to-day threat modeling of web APIs within the established SLAs.
• Document risk management plans for API threat models to effectively communicate residual risks to the business.
• Perform ongoing governance and follow-through with API owners to ensure implementation of threat based requirements.
• Develop, deliver and keep up-to-date API security standard requirements and design patterns.
• Manage ongoing security exceptions to API security standards.
• Perform API security code reviews and attest to API security standard compliance.
• Validate implementation of API security controls against outputs of vulnerability testing tools to enable auditability and verifiability.
• Serve as an API security technical advisor to application teams.
• Evangelize API security design principles.
• Be recognized as an API security subject matter expert within the organization.
Education
• Bachelor's degree in computer science, information systems, cybersecurity, or a related field.
• Atleast 5 years experience with threat modeling, secure application design and development practices.
Security and Technical Experience
• Direct hands on experience developing and securing web APIs and web applications: REST, SOAP, gRPC.
• Direct hands on experience with security testing of web services and web APIs.
• Solid hands on experience with leading threat modeling exercises for applications and services.
• Direct hands on experience with threat modeling frameworks, attack vectors an vulnerability analysis: CAPEC, ATT&CK, STRIDE.
• Solid understanding of risk management, security architecture and secure SDLC practices.
• Strong experience and understanding of identity and access management controls: OAuth 2.0, OIDC, JWT
• Strong experience and understanding of familiarity with cryptography controls: Data at rest, in motion and in-use.
• Experience with industry standards and frameworks: NIST 800-53, NIST CSF, OWASP, SANS Top 25.
• Experience with Java, Javascript and mobile application development.
• Familiarity with database architectures: Oracle, SQL and NoSQL Databases.
Preferred Security Certifications
• CISSP, SANS GIAC or similar certifications
Key Behaviors/Competencies
• Self-directed, Confident Team Player
• Strong Technical Thinker
• Strong Planning, Execution and Collaborative skills
• Strong Communication skills — Strong verbal and written communication skills. Ability to document risk and control summary artifacts that translates complex threat models into easy to read reports for the business.
• Openness to Learning: Takes personal responsibility for learning and upskilling. Acquires strategies for gaining new knowledge, behaviors and skills. Builds on and applies existing knowledge. Engages in learning from others, inside and outside the organization.
• Adaptability: Demonstrates flexibility within a variety of changing situations, while working with individuals and groups. Changes his or her own ideas or perceptions in response to changing circumstances.
• Business Acumen: Demonstrates an awareness of internal dynamics.
-
Cyber Security Engineer
2 months ago
Phoenix, United States TEKsystems Full timeJob DescriptionJob Description1. Experienced in technical security controls assessment and remediation.2. Threat identification, analysis, and threat modeling3. Technical security experience in 2 of the following:a. Cloudb. Networkc. OSd. Applicatione. Data Storagef. Data & Complianceg. Encryptionh. Infrastructurej. IOTk. Carrier NetworkCybersecurity...
-
Security Engineer
2 months ago
Phoenix, United States TEKsystems Full timeJob DescriptionJob DescriptionTop Skills' DetailsThreat modeling experience in relation to API’sHow they are build, common attacks, how to defend API’sExperience when it comes to testing API’sEither doing vulnerability testing or pen testingFamiliarity with API GatewaysUnderstanding of authentication/authorization for API’sJob DescriptionSeeking...
-
Security Engineer
4 months ago
Phoenix, United States Diverse Lynx Full timeJob Tittle: Security EngineerOnsite - Phoenix, AZContract RoleWhat are the top 3 skills required for this role? 1. Threat modelling and endpoint security 2. AWS or Azure cloud experience 3. Application & Cloud Security expertise Job Description/ Responsibilities • Good hands-on app security architect with Cloud security skills • Good knowledge on...
-
Senior Security Engineer
4 weeks ago
Phoenix, United States Diverse Lynx Full timeJob Summary: What are the top skills required for this role? 1. API 2. Apigee 3. Hands on WebAPI, and web apps: REST, SOAP, gRPC 4. Knowledge of Java, JavaScript or mobile app development 5. Knowledge of project management desirable Job Description/ Responsibilities Client is seeking a Senior API Security Engineer with proven strong technical competence and...
-
Endpoint Security Engineer
3 months ago
PHOENIX, United States Charles Schwab Full timePosition Type: RegularYour opportunityAt Schwab, you are empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.The Endpoint Security Engineer is an individual contributor supporting endpoint security technologies, threat...
-
Jr Security Engineer
2 months ago
Phoenix, United States TEKsystems Full timeJob DescriptionJob Description Job DescriptionParticipate in security consulting on small projects for internal clients to ensure uniformity with corporate information, security policy, and standards. Track or remediate vulnerabilities and security issues. Review and correlate security logs. Assist with the design, documentation, testing, maintenance, and...
-
Cloud Security Engineer
4 weeks ago
Phoenix, Arizona, United States Fruth Group Full timeJob Title: Systems Engineer – MSPLocation: RemoteCompany: Fruth GroupJob DescriptionFruth Group is seeking a skilled Systems Engineer – MSP to join our IT division. As a security-focused managed service provider (MSP), we're looking for a talented individual to ensure secure system implementations. The ideal candidate will be proficient in Entra ID,...
-
LU 62 Security Engineer
4 weeks ago
Phoenix, United States Focused HR Solutions Remote Work Freelance Full timeThis job is hybrid and this will be a mix of remote and on site in Phoenix AZ. Our direct client has an opening for a Security Engineer 1323 Please send us your rate and resume. This position is up to 2 years with the option of extension. The client is in Phoenix, AZ. Please send us your rate and resume Work Location...
-
Network Security Engineer
2 months ago
Phoenix, United States TEKsystems Full timeJob DescriptionJob DescriptionLooking for a Network Infrastructure/Security Engineer with a strong Networking background, firewall and packet capture experience as well as Python scripting. This person must be someone who can learn new things and work on new integrations for one of the biggest financial services companies in the nation. This position can...
-
Staff Security Operations Engineer
2 weeks ago
Phoenix, United States Canonical - Jobs Full timeJob DescriptionJob DescriptionWe have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions - at the high end we are looking for deep experience defending highly contested critical assets and high-value cyber targets against advanced...
-
Network Security Engineer
2 months ago
Phoenix, United States TEKsystems Full timeJob DescriptionJob DescriptionThe Network Security Engineer is responsible for the support and maintenance of a Multi-Tenant environment, both cloud based and on-premises, requiring cooperative support of 24x7x365 NOC/SOC operation.A clear understanding of network security and best practices is highly important. Your primary responsibilities will be to...
-
Information Security Engineer, Senior
5 months ago
Phoenix, United States Arizona Official Website of State of Arizona Full timeJob Summary: This position is an integral part of the Information Security Team which aids in reducing overall organization risk by way of deployment, management, monitoring, and tuning of technical security controls. Additionally, this position reviews security policies and creates associated security standards and procedures in coordination with the...
-
Cybersecurity Architect
1 month ago
Phoenix, United States Kudelski Security Full timeManaged Detection and Response (MDR) Cybersecurity ArchitectCompany BackgroundKudelski Security is a leading cyber security solutions company, providing a combination of consulting, technology, managed services, and innovation to enterprise and public sector clients around the world with a relentless commitment to developing & delivering innovative solutions...
-
Information Security Engineer
2 months ago
Phoenix, United States TEKsystems Full timeJob DescriptionJob DescriptionDirect Placement with a Fortune 500 company Top Skills Details1) Security architecture or engineering experience, understand concepts and understand best practices for monitoring different platforms (Unix, Linux, Cloud, etc.).2) Understand incident response, logging and monitoring within security. Worked in a consultative role,...
-
Sr Manager, Security Development
4 weeks ago
Phoenix, United States Charles Schwab Full timePosition Type: RegularYour opportunity At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together. Consult with development teams, providing application security guidance and recommendations. Perform secure...
-
Senior Security Engineer
1 month ago
PHOENIX, United States Charles Schwab Full timePosition Type: RegularYour opportunityAt Schwab, you are empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together. In Schwab Cybersecurity Services (SCS), Office of CISO, we provide platforms, services, and security operations...
-
Senior Security Engineer
2 weeks ago
Phoenix, United States Motion Recruitment Partners LLC Full timeSenior Security Engineer / HashiCorp Vault SME Phoenix, AZ 100% Remote Contract $75/hr - $90/hr A regional bank based out of Arkansas is a looking for a Senior Security Engineer & HashiCorp Vault SME to add to their growing team. This engineer will own Vault, help to implement new features, and onboard other teams to said features. Right now its deployed for...
-
Senior Security Engineer
1 week ago
Phoenix, United States Motion Recruitment Full timeA regional bank based out of Arkansas is a looking for a Senior Security Engineer & HashiCorp Vault SME to add to their growing team. This engineer will own Vault, help to implement new features, and onboard other teams to said features. Right now its deployed for secrets management but they want to take advantage of what it can do with tokenization,...
-
Information Security Engineer
2 months ago
Phoenix, United States TEKsystems Full timeJob DescriptionJob DescriptionTop skillsLinux and windows experienceLead or participate in computer security incident response activities for moderately complex events.Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies.Provide security consulting on...
-
Sr. Cyber Security Engineer
3 weeks ago
Phoenix, United States Konica Minolta Full timeOverview Senior Cybersecurity Engineer - Endpoint Detection and Response is expected to possess a high level of knowledge and experience in various security domains and technologies with a focus on advanced endpoint protection, detection and response. This resource will work closely with the defensive managed security services team to design, deploy, and...