Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
API Security Engineer
Berkeley Heights, NJ · On-site
Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
API Security Engineer
Berkeley Heights, NJ · On-site
Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
API Security Engineer
Coral Springs, FL · On-site
Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
API Security Engineer
Coral Springs, FL · On-site
Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
API Security Engineer
Alpharetta, GA · On-site
Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
API Security Engineer
Alpharetta, GA · On-site
Job Title API Security Engineer About your role: You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end ...
Partner with the best Join Akamai's Application & API Security team as an Enterprise Architect. You will work directly with some of the world's largest enterprises. You will design, integrate, and ...
Partner with the best Join Akamai's Application & API Security team as an Enterprise Architect. You will work directly with some of the world's largest enterprises. You will design, integrate, and ...
Senior API Security Engineer
Falls Church, VA · On-site
$122K - $167K/yr
Everforth ECS is seeking a Senior API Security Engineer to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
Senior API Security Engineer
Falls Church, VA · On-site
$122K - $167K/yr
Everforth ECS is seeking a Senior API Security Engineer to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
Partner with the best Join Akamai's Application & API Security team as an Enterprise Architect. You will work directly with some of the world's largest enterprises. You will design, integrate, and ...
Partner with the best Join Akamai's Application & API Security team as an Enterprise Architect. You will work directly with some of the world's largest enterprises. You will design, integrate, and ...
ICONMA is an IT Services and Consultant company seeking a Lead API Security & Vulnerability Management Engineer. The role involves managing the lifecycle of API vulnerabilities, coordinating with ...
ICONMA is an IT Services and Consultant company seeking a Lead API Security & Vulnerability Management Engineer. The role involves managing the lifecycle of API vulnerabilities, coordinating with ...
Everforth ECS is seeking a Senior API Security Engineer to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
Everforth ECS is seeking a Senior API Security Engineer to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
API Architect
Mount Laurel, NJ · On-site
$115K - $130K/yr
... Performance Optimization, API Security (OAuth2, JWT), CI/CD (Jenkins, Azure DevOps), Docker & Kubernetes, Monitoring (Prometheus, ELK), Agile, Technical Leadership & Mentoring Roles ...
API Architect
Mount Laurel, NJ · On-site
$115K - $130K/yr
... Performance Optimization, API Security (OAuth2, JWT), CI/CD (Jenkins, Azure DevOps), Docker & Kubernetes, Monitoring (Prometheus, ELK), Agile, Technical Leadership & Mentoring Roles ...
Cloud Architect API Developer
Burlington, IA · On-site
Implement API security measures like authentication, authorization, and data encryption. * Design and implement API documentation using tool like Swagger or OpenAPI. API Gateway Management
Cloud Architect API Developer
Burlington, IA · On-site
Implement API security measures like authentication, authorization, and data encryption. * Design and implement API documentation using tool like Swagger or OpenAPI. API Gateway Management
Implement API security measures like authentication, authorization, and data encryption. * Design and implement API documentation using tool like Swagger or OpenAPI. API Gateway Management
Implement API security measures like authentication, authorization, and data encryption. * Design and implement API documentation using tool like Swagger or OpenAPI. API Gateway Management
IBM API Developer
Torrance, CA · On-site
Implement API mediation, routing, transformation, and security using IBM DataPower API Gateway * Develop and configure DataPower services such as: * Multi-Protocol Gateway (MPGW) * Web Service Proxy
Quick apply
IBM API Developer
Torrance, CA · On-site
Implement API mediation, routing, transformation, and security using IBM DataPower API Gateway * Develop and configure DataPower services such as: * Multi-Protocol Gateway (MPGW) * Web Service Proxy
API & GCP Architect
Exton, PA · On-site
Establish API security using OAuth 2.0, JWT, OpenID Connect,SSL/TLS, mTLS, and threat protection policies. * Define API governance standards, best practices, and reusableframeworks. * Drive ...
API & GCP Architect
Exton, PA · On-site
Establish API security using OAuth 2.0, JWT, OpenID Connect,SSL/TLS, mTLS, and threat protection policies. * Define API governance standards, best practices, and reusableframeworks. * Drive ...
API & GCP Architect
Exton, PA · Hybrid
Establish API security using OAuth 2.0, JWT, OpenID Connect, SSL/TLS, mTLS, and threat protection policies Define API governance standards, best practices, and reusable frameworks. Drive ...
API & GCP Architect
Exton, PA · Hybrid
Establish API security using OAuth 2.0, JWT, OpenID Connect, SSL/TLS, mTLS, and threat protection policies Define API governance standards, best practices, and reusable frameworks. Drive ...
Lead - API Vulnerability Data Engineer
Avenel, NJ · On-site
$104K - $137K/yr
Akamai or similar API security tooling, vulnerability management, Python and Javascript / Responsibilities : We are seeking a Senior - API Vulnerability Data Engineer with 8+ years of experience to ...
New
Lead - API Vulnerability Data Engineer
Avenel, NJ · On-site
$104K - $137K/yr
Akamai or similar API security tooling, vulnerability management, Python and Javascript / Responsibilities : We are seeking a Senior - API Vulnerability Data Engineer with 8+ years of experience to ...
New
IBM API Developer
Torrance, CA · On-site
Implement API security mechanisms including: * OAuth 2.0 * JWT * API Keys * Mutual TLS * Develop custom logic using: * XSLT * GatewayScript (JavaScript) * Create and manage OpenAPI / Swagger ...
Quick apply
IBM API Developer
Torrance, CA · On-site
Implement API security mechanisms including: * OAuth 2.0 * JWT * API Keys * Mutual TLS * Develop custom logic using: * XSLT * GatewayScript (JavaScript) * Create and manage OpenAPI / Swagger ...
API Architect
Atlanta, TX · On-site
Experience with Designs API security, authentication, and authorization mechanisms. * Extensive experience with leading the design and development of APIs that enable integration between various ...
Quick apply
API Architect
Atlanta, TX · On-site
Experience with Designs API security, authentication, and authorization mechanisms. * Extensive experience with leading the design and development of APIs that enable integration between various ...
Web API Architect
Pennington, NJ · On-site
Tata Consultancy Services is looking for a Web API Architect to design, build, and maintain secure ... services, and establishing security protocols, while also mentoring development teams.
Web API Architect
Pennington, NJ · On-site
Tata Consultancy Services is looking for a Web API Architect to design, build, and maintain secure ... services, and establishing security protocols, while also mentoring development teams.
Lead - API Vulnerability Data Engineer - W2 Only
$100K - $131K/yr
Akamai or similar API security tooling, vulnerability management, Python and Javascript Name Vulnerability Management Python Akamai WebApp Protector Javascript / Responsibilities : We are seeking a ...
Lead - API Vulnerability Data Engineer - W2 Only
$100K - $131K/yr
Akamai or similar API security tooling, vulnerability management, Python and Javascript Name Vulnerability Management Python Akamai WebApp Protector Javascript / Responsibilities : We are seeking a ...
Api Security information
See salary details
$11.54 - $12.76
1% of jobs
$12.76 - $13.99
3% of jobs
$13.99 - $15.21
13% of jobs
$15.65 is the 25th percentile. Wages below this are outliers.
$15.21 - $16.43
22% of jobs
The median wage is $16.97 / hr.
$16.43 - $17.66
24% of jobs
$18.41 is the 75th percentile. Wages above this are outliers.
$17.66 - $18.88
18% of jobs
$18.88 - $20.10
7% of jobs
$20.10 - $21.33
4% of jobs
$21.33 - $22.55
3% of jobs
$22.55 - $23.78
2% of jobs
$23.78 - $25
1% of jobs
$11
$19
$25
How much do api security jobs pay per hour?
What is an API Security job?
An API Security job focuses on protecting application programming interfaces (APIs) from threats such as unauthorized access, data breaches, and cyberattacks. Professionals in this role assess vulnerabilities, implement security controls, and ensure APIs comply with industry standards. Responsibilities may include authentication, encryption, threat monitoring, and incident response to safeguard sensitive data.
What are the typical day-to-day responsibilities of someone working in API Security?
Professionals in API Security regularly review application and API designs for vulnerabilities, conduct security testing and code reviews, and monitor for emerging threats. Their day-to-day work involves collaborating with development teams to provide secure coding guidance, drafting security requirements, and responding quickly to incidents or potential breaches. They also update and implement security policies, stay current on the latest security trends, and often lead training sessions to raise awareness within the organization. This role requires both hands-on technical work and ongoing communication with other teams to ensure secure development practices and compliance with industry standards.
What are the key skills and qualifications needed to thrive in the Api Security position, and why are they important?
To thrive in API Security, you need a strong understanding of web protocols, authentication, encryption, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as OWASP ZAP, Burp Suite, Postman, and certifications like CEH or CISSP is highly valued. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for this role. These capabilities are essential for identifying vulnerabilities, enforcing robust security measures, and clearly conveying risks and solutions to technical and non-technical stakeholders.

Full-time
Posted 17 days ago
Job description
Calling all innovators - find your future at Fiserv.
We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we're involved. If you want to make an impact on a global scale, come make a difference at Fiserv.
Job Title
API Security EngineerAbout your role:
You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end, design through runtime, using cutting-edge protection technologies and analytics, partnering closely with top engineers across product, platform, and security. You will help turn API telemetry into actionable intelligence, reduce risk at scale, and raise the bar for secure engineering across the organization. As an API Security Engineer, you will focus on protecting critical API ecosystems by combining secure-by-design guidance, runtime protections, automation, and data-driven governance. You will be hands-on with modern API security capabilities (discovery, posture, threat detection, abuse prevention, and response) and help integrate them into the DevSecOps lifecycle so teams can move fast without compromising trust.
What you will do:
- Runtime API protection:Implement and tune runtime controls (e.g., behavioral detection, anomaly and abuse prevention, bot defense, schema enforcement, mTLS/OAuth validation, rate limiting, and threat response) across API gateways, service mesh, and edge layers.
- Secure API design guidance:Partner with engineering teams to define and promote secure API patterns (authentication/authorization, input validation, error handling, pagination, idempotency, versioning, and least-privilege access). Provide practical guidance aligned to OWASP API Security Top 10 and modern design standards (Open API/JSON Schema).
- Automation and integration:Build automation that embeds API security into CI/CD (policy-as-code, automated checks against Open API specs, secrets scanning, SAST/DAST/API testing, and runtime-to-ticket workflows). Reduce friction through reusable tooling and self-service guardrails.
- Data analytics and insights:Develop dashboards and analytics using API telemetry and security findings to measure risk, adoption, control effectiveness, and program outcomes. Translate signals into prioritized actions for engineering and leadership.
- API security governance:Help define governance for API inventories, ownership, classification, security requirements, exception handling, and control validation. Drive consistent standards across teams while enabling delivery velocity.
- DevSecOps lifecycle partnership:Work with product and platform teams to integrate security requirements into backlog planning, threat modeling, design reviews, testing, release readiness, and incident response.
- Framework alignment (financial services):Map controls and program outcomes to relevant industry frameworks and expectations (e.g., NIST, ISO 27001, PCI DSS, FAPI, and OWASP guidance). Support audit readiness through clear control documentation and evidence automation.
- Continuous improvement and innovation:Evaluate emerging technologies and techniques for API discovery, posture management, and runtime detection. Pilot, measure, and scale what works.
What you will need to have:
- 5+ years related IT and cyber protection experience desired.
- Strong foundation in API security concepts: authN/authZ (OAuth2/OIDC, JWT), session/token handling, scopes/claims, rate limiting, schema validation, and common API abuse patterns.
- Practical experience with runtime protection in one or more of API gateways, WAF/WAAP, service mesh, ingress controllers, or specialized API security platforms.
- Experience building automation in CI/CD and cloud-native environments (policy-as-code, scripting, pipelines, Git-based workflows).
- Ability to use data and telemetry (logs, traces, metrics) to detect issues, tell a clear story, and drive priorities and working knowledge of secure software development and DevSecOps practices, and the ability to influence engineering outcomes through partnerships.
- Comfort collaborating across security, SRE, platform, and application teams with clear communication, pragmatic decision-making, and strong follow-through.
- Expert knowledge of and experience with maintaining cyber technologies that can protect operational API systems, such as:
- Traceable
- Salt Security
- NoName
- Bachelor's degree in computer science, or a relevant field, or an equivalent combination of education, work, and/or military experience
What would be great to have:
- Experience with Open API tooling, API testing, fuzzing, and contract testing.
- Familiarity with threat modeling approaches and abuse-case analysis for APIs.
- Experience aligning security controls to financial industry expectations and. producing evidence that stands up to audit scrutiny.
- CISSP or other professional cyber certification desirable.
How you'll work
- This role is on-site Monday through Friday. Fiserv considers in-person collaboration to be an essential part of this role as in-person office experiences help you with your overall onboarding experience and leads to stronger productivity.
Travel
- Approximately 10% travel off-site or to other office locations is expected.
Sponsorship
- You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring sponsorship, now or in the future, will not be considered.
#LI-RM1
Salary Range
$110,000.00 - $186,000.00These pay ranges apply to employees in New Jersey and New York. Pay ranges for employees in other states may differ.
It is unlawful to discriminate against a prospective employee due to the individual's status as a veteran.
For incentive eligible associates, the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Company's sole discretion.Thank you for considering employment with Fiserv. Please:
- Apply using your legal name
- Complete the step-by-step profile and attach your resume (either is acceptable, both are preferable).
Our commitment to Equal Opportunity:
Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, gender, gender identity, sexual orientation, age, disability, protected veteran status, or any other category protected by law.
If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process, please contactAskHR.US@fiserv.com. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiserv's Disability Accommodation Policy for additional information.
Note to agencies:
Fiserv does not accept resume submissions from agencies outside of existing agreements.Please do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.
Warning about fake job posts:
Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.