Fiserv logo
FiservPosted 2 weeks ago

API Security Engineer

$110,000–$186,000 year

On-siteAlpharetta, Georgia, United States or Coral Springs, Florida, United States

Full TimeSenior LevelLarge

Job Summary

Implement runtime API controls across gateways and service meshes to prevent abuse, enforce schema validation, and manage threat response. Partner with engineering teams to define secure design patterns, integrate security checks into CI/CD pipelines, and build automation for policy-as-code and secrets scanning. Develop dashboards from telemetry data to measure risk and control effectiveness, while establishing governance for API inventories and exception handling. Map program outcomes to industry frameworks like PCI DSS and NIST to support audit readiness. Work within the DevSecOps lifecycle to embed security into backlog planning, threat modeling, and incident response.

Required Qualifications

  • 5+ years related IT and cyber protection experience
  • Strong foundation in API security concepts: authN/authZ (OAuth2/OIDC, JWT), session/token handling, scopes/claims, rate limiting, schema validation, and common API abuse patterns
  • Practical experience with runtime protection in one or more of API gateways, WAF/WAAP, service mesh, ingress controllers, or specialized API security platforms
  • Experience building automation in CI/CD and cloud-native environments (policy-as-code, scripting, pipelines, Git-based workflows)
  • Ability to use data and telemetry (logs, traces, metrics) to detect issues, tell a clear story, and drive priorities
  • Working knowledge of secure software development and DevSecOps practices
  • Ability to influence engineering outcomes through partnerships
  • Comfort collaborating across security, SRE, platform, and application teams with clear communication, pragmatic decision-making, and strong follow-through
  • Expert knowledge of and experience with maintaining cyber technologies that can protect operational API systems
  • Bachelor's degree in computer science, or a relevant field, or an equivalent combination of education, work, and/or military experience
  • Valid and unrestricted U.S. work authorization
  • Must currently possess valid and unrestricted U.S. work authorization to be considered for this role
  • Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring sponsorship, now or in the future, will not be considered

Desired Qualifications

  • Experience with Open API tooling, API testing, fuzzing, and contract testing
  • Familiarity with threat modeling approaches and abuse-case analysis for APIs
  • Experience aligning security controls to financial industry expectations and producing evidence that stands up to audit scrutiny
  • CISSP or other professional cyber certification

Additional Requirements

  • Requires U.S. work authorization; sponsorship not provided
  • On-site role; travel ~10% to multiple US locations (NJ/GA/FL)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce