We're looking for an experienced API Security Consultant to lead and manage the operations of an enterprise-grade API Security Platform. This role will focus on maintaining API security posture leading investigations defining security rules and controls and ensuring seamless integration with client infrastructure.
• Oversee daily administration configuration and tuning of the API Security Platform.
• Oversee the creation of detailed system architecture and design documents for the API Security platform.
• Enhance and refine API Security rules policies and alerts based on threat intelligence and platform findings.
• Manage platform health checks uptime monitoring and integration validations.
• Supervise the integration of the API Security platform with existing systems like F5 LTM and API Gateway.
• Guide the team in setting up effective alerts and notification systems for API security incidents and events.
• Coordinate with SOC DevOps and Infra teams for alert triage issue resolution and response.
• Direct the creation of comprehensive test plans for system and user acceptance testing.
• Lead the process of managing and maintaining remote collectors and other on-site components of the API Security platform.
Qualifications and Skills
Experience:
- 5+ years in cybersecurity or DevSecOps with strong exposure to API security.
- Experience with Cequence API Security is highly preferred. Familiarity with similar API security platforms (e.g. Salt Security or equivalent) will also be considered a strong advantage.
- Strong knowledge of API architectures (REST SOAP GraphQL) OAuth2/OIDC F5 API Gateways and SIEM integration.
- Familiarity with detecting shadow APIs PII-sensitive endpoints and anomalous behavior.
- Deep understanding of platform integrations custom rule writing and correlation logic.
- Experience working with or supporting SOC teams is a plus.
Soft Skills:
- Strong analytical and problem-solving abilities with keen attention to detail.
Preferred Certifications
- API Security Certified Specialist
- CISSP CCSP or GWEB
- AWS/GCP/Azure security certifications
- GIAC Cloud Security Automation (GCSA) or equivalent