Senior API Security Engineer
Role description
- Hybrid set-up, 60 - 80% working from home, 20 - 40% working from office.
- ZZP is allowed
- The relocation is not possible for this role
As an API Security Engineer on a central platform you will play a key role in strengthening our digital resilience by securing the APIs that power our customer and partner ecosystems.
Dien uw cv en eventuele aanvullende vereiste informatie in nadat u deze omschrijving heeft gelezen, door op de sollicitatieknop te klikken.
You will join our API Security team. The team drives the API security strategy, standards, and governance across the bank, ensuring that APIs are secure and comply with internal security requirements.
As an API Security Engineer, it’s your job to safeguard the security of our API landscape by translating security standards, controls, and best practices into platform policies and automation of business logic. You will work closely with engineers, architects, and security specialists to ensure APIs are secure, compliant with security requirements, and resilient against evolving threats.
RequirementsYour profileYou are a security specialist who combines technical expertise with a pragmatic mindset. You bring:
- Strong understanding of cybersecurity principles and architectures included cloud security, and application security architecture
- Deep expertise in API and application security with a strong understanding of frameworks such as OWASP top10, Mitre and CVE
- Advanced knowledge of authentication and authorization mechanisms such as Oauth, JWT, session management, mTLS, Object-level authorization and attribute-level authorization
- An analytical mindset to accurately assess the xgiwjmb severity and criticality of API Security findings, translate these findings into improvements for policies and business rules
- The ability to translate complex security requirements into practical and actionable platform policies and automated guardrails
- Exceptional communication skills, combined with a highly proactive mindset and a proven ability to take ownership
- Proven experience with managing API Security products such as Akamai Noname, Salt or Cequence