Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

API Security Engineer

$116k - $216k

Keybank, National Association

Location: 4910 Tiedeman Road, Brooklyn Ohio

API Security Engineer Role Overview

We are seeking an experienced API & Application Security Engineer with expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling. This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments. The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation.

Key Responsibilities

API Security

Deploy, configure, administer, and optimize enterprise API security platforms and controls. Perform continuous API discovery, inventory, classification, and security posture management. Identify shadow, rogue, zombie, deprecated, and undocumented APIs. Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns. Identify vulnerabilities including BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, security misconfigurations, and business-logic abuse. Assess APIs against the OWASP API Security Top 10 and organizational security standards. Investigate API security alerts and coordinate remediation with engineering and application teams. Integrate API security findings with SIEM, SOAR, vulnerability management, incident response, and ticketing workflows.

eBPF Agent / Sensor Deployment

Design, deploy, configure, and maintain eBPF-based API security agents and sensors across Linux, containerized, Kubernetes, and cloud environments. Deploy traffic-collection components to provide visibility into API communications and application behavior. Validate operating-system, kernel, container runtime, Kubernetes, networking, and infrastructure prerequisites for eBPF deployments. Troubleshoot agent installation, connectivity, permissions, kernel compatibility, traffic visibility, telemetry collection, and performance issues. Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact. Develop standards and automation for repeatable, enterprise-scale agent deployments. Support agent upgrades, configuration changes, health monitoring, troubleshooting, and lifecycle management. Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.

API Gateway & middleware Integrations

Integrate API security platforms with enterprise API gateways, middleware platforms, reverse proxies, ingress controllers, and traffic-management technologies. Work with API proxies, products, policies, routing configurations, authentication mechanisms, and traffic-management controls. Configure and validate API traffic visibility between gateways and API security platforms. Review gateway policies for authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security-control weaknesses. Support integrations with both cloud-native API management platforms and enterprise on-premises gateway appliances. Configure and validate traffic forwarding, mirroring, logging, telemetry, or other supported collection mechanisms. Troubleshoot connectivity, certificate, traffic collection, API discovery, and integration issues. Partner with gateway administrators, middleware engineers, application teams, and platform owners to remediate identified security weaknesses.

Web Application Firewall / WAAP

Deploy, configure, administer, and optimize enterprise WAF/WAAP security controls. Configure and tune WAF policies, custom rules, rate controls, network/IP controls, and application protections. Analyze traffic and security events to identify attacks, anomalous activity, and false positives. Investigate SQL injection, XSS, command injection, path traversal, file inclusion, malicious automation, and other application-layer attacks. Onboard applications and APIs to enterprise web and API protection services. Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic. Support security incident investigations using WAF, API, application, and network telemetry.

Security Architecture & Threat Modeling

Perform security architecture reviews for APIs, web applications, microservices, API gateways, middleware platforms, Kubernetes, containers, and cloud environments. Conduct threat modeling to identify attack surfaces, trust boundaries, abuse cases, authorization risks, sensitive-data exposure, and potential control gaps. Review authentication and authorization architectures involving OAuth 2.0, OIDC, JWT, API keys, mTLS, IAM, RBAC, and other access-control mechanisms. Evaluate end-to-end API traffic flows from clients through edge-security controls, gateways, middleware, microservices, and backend applications. Recommend preventive, detective, and compensating security controls based on identified risks. Participate in application and infrastructure design reviews and promote secure-by-design engineering practices.

Application Security & Automation

Perform application and API security assessments using manual and automated testing techniques. Apply the OWASP Top 10 and OWASP API Security Top 10 to application and API assessments. Perform request and response analysis, vulnerability validation, and remediation verification. Work with intercepting proxies, API clients, command-line testing tools, SAST, DAST, SCA, and API security testing technologies. Integrate application and API security testing into CI/CD and DevSecOps pipelines. Develop automation using Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies. Automate agent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows. Work directly with developers to explain vulnerabilities, recommend practical remediation, and validate fixes.

Education & Experience

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience; or An equivalent combination of college education, technical training, industry certifications, and hands‑on cybersecurity experience. Candidates with an Associate degree, relevant college coursework, technical certifications, or substantial professional experience in lieu of a four-year degree may be considered. Demonstrated professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering. Hands‑on experience deploying and supporting enterprise API security, application security, API gateway, and traffic‑monitoring technologies is strongly preferred.

Required Technical Qualifications

Hands‑on experience with enterprise API security technologies. Experience deploying, configuring, and tuning WAF/WAAP security controls. Understanding of eBPF‑based agent/sensor deployment and troubleshooting in Linux, Kubernetes, containerized, and cloud environments. Experience integrating API security platforms with enterprise API gateways and API management technologies. Strong knowledge of DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures. Strong understanding of the OWASP API Security Top 10 and OWASP Top 10. Knowledge of OAuth 2.0, OIDC, JWT, API keys, IAM, RBAC, and modern API authorization models. Experience performing security architecture reviews and threat modeling. Working knowledge of public cloud platforms, Kubernetes, containers, Linux, and microservices. Experience with secure SDLC, DevSecOps, CI/CD, vulnerability management, and incident‑response processes. Ability to troubleshoot complex integrations across applications, gateways, middleware, networks, security controls, and cloud infrastructure. Ability to work directly with developers, architects, API gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams.

Preferred Qualifications

Experience operating enterprise‑scale API security and application security environments. Experience with eBPF‑based API traffic collection and Kubernetes/Linux sensor deployments. Advanced experience integrating security platforms with cloud‑based API management solutions and enterprise gateway appliances. Experience with API gateways, reverse proxies, service meshes, ingress controllers, and load‑balancing technologies. Experience integrating security telemetry with SIEM/SOAR platforms. Experience with penetration testing and adversarial API/application security assessments. Familiarity with STRIDE, attack trees, or comparable threat‑modeling methodologies. Experience developing security tooling and automation at enterprise scale. Relevant industry certifications in information security, application security, penetration testing, cloud security, or DevSecOps are preferred but not required.

Key Technical Skills
  • API Security
  • Application Security
  • WAF/WAAP
  • eBPF
  • Linux
  • Kubernetes
  • API Gateway Security
  • API Management
  • API Discovery
  • API Posture Management
  • REST
  • GraphQL
  • OWASP API Top 10
  • OWASP Top 10
  • OAuth 2.0
  • OIDC
  • JWT
  • TLS/mTLS
  • OpenAPI/Swagger
  • DevSecOps
  • CI/CD
  • Python
  • Security Automation
  • Threat Modeling
  • Security Architecture
  • Cloud Security
  • SIEM/SOAR
  • Vulnerability Management
What Success Looks Like

The successful candidate will serve as a technical subject‑matter expert for enterprise API and application security, with the ability to deploy and troubleshoot eBPF‑based security agents, integrate security capabilities with cloud and on‑premises API gateway technologies, and secure complex enterprise API architectures. The engineer will combine hands‑on security engineering with API security, WAF/WAAP, application security, security architecture, threat modeling, cloud security, DevSecOps, and automation expertise while working directly with engineering teams to implement scalable secure‑by‑design solutions.

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $116,000.00 - $216,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Key has implemented an approach to employee workspaces which prioritizes in‑office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/26/2026

KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law. Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing View email address on click.appcast.io.

#LI-Remote KeyBank is an organization collectively committed to helping you unlock your potential and discover what truly drives you.

Working here means sharing our purpose to help our clients, colleagues, and communities thrive.

For 200 years, Key has opened doors in our communities. Let us open one for you.

#J-18808-Ljbffr
Vacancy posted 17 hours ago
Similar jobs that could be interesting for youBased on the API Security Engineer in Brooklyn, OH vacancy
  •  ..., deploy, integrate, administer, and optimize enterprise API and application security controls across cloud, on-premises, containerized, and hybrid...  .../SRE, cloud, network, SOC, middleware, and platform engineering teams to identify risks and implement protections Perform... 
    Suggested

    Jobtailor

    Brooklyn, OH
    5 days ago
  •  ...Job Description: Pay Rate: $65 - $70/hour on W2 Notes: should be local to OH or KY TECHNICAL SKILLS Must Have API security Software Application Security Testing (SAST) Software Composition Analysis (SCA) Javascript/NodeJS Python Terraform... 
    Suggested
    Local area
    Remote work

    CBTS

    Parma, OH
    4 days ago
  •  ...Pay Rate: $65 - $70/hour on W2 \n Notes: should be local to OH or KY \n \n TECHNICAL SKILLS \n Must Have \n \n API security \n Software Application Security Testing (SAST)\n Software Composition Analysis (SCA)\n Javascript/NodeJS \n Python... 
    Suggested
    Remote job
    Local area

    CBTS

    Parma, OH
    11 days ago
  • $96k - $181k

     ...’s broader Cyber Defense function within Corporate Information Security. Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny...  ...threat-centric defense. The Senior Offensive Security Engineer serves as the technical and operational lead for the Cyber Defense... 
    Suggested
    Work at office
    Flexible hours

    KeyCorp

    Brooklyn, OH
    1 day ago
  • OverviewWe are seeking a highly skilled Security Engineer II to join our Information Security team. This role will play a key part in managing, administrating, reporting and identifying enhancements for our security solutions and assisting with implementation across cloud... 
    Suggested
    Full time
    Flexible hours

    AmTrust

    Cleveland, OH
    2 days ago
  •  ...#LI-CR2 #LI-Hybrid Responsibilities The Senior Product Security Engineer is a deeply technical, hands-on engineering and architect-...  ...reference architectures, and secure design patterns for web, mobile, API, microservices, serverless, and AI-enabled applications.... 

    CBIZ

    Independence, OH
    4 days ago
  •  ...Senior Security Engineer At Flynn Group, we believe in the power of collaboration and value in-person interactions. This is why our employees work from the office four days per week, leaving Fridays to work from home. This setup cultivates casual conversations, problem... 
    Temporary work
    Casual work
    Work at office
    Work from home
    Flexible hours

    Flynn Group

    Independence, OH
    5 days ago
  • $82.6k - $162.8k

     ...with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be...  ...asOAuth 2.0, Authentication & Authorization, API Security, API Gateways, System... 
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    1 day ago
  • $105.4k - $207.8k

    Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business...  ..., Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident... 
    Work experience placement
    Local area
    Remote work

    Deloitte

    Cleveland, OH
    3 days ago
  •  ...Senior Security Engineer Medical Mutual employees must submit their applications through MySource. This is a hybrid-remote role based out of the Dublin, OH office, with employees expected to work onsite on designated in-office days each week. Founded in 1934,... 
    Casual work
    Work at office
    Remote work

    Medical Mutual of Ohio

    Cleveland, OH
    4 days ago
  •  ...Interacts with business users and vendors to identify, define requirements, and expectations of new and existing network systems security needs. Participates in design, implementation, and troubleshooting process for complex firewall solutions. Assists in the development... 
    Casual work
    Night shift

    University Hospitals Pain Management

    Cleveland, OH
    2 days ago
  • $122k - $240.5k

    Position Summary As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s Digital...  ...communicate effectively with business, security, privacy, legal, and compliance...  ...applicableBuilding application programming interfaces (APIs), automations, workflows, integrations,... 
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    1 day ago
  • $105.4k - $207.8k

     ...this role, you will support Next-Generation Security Operations Center (SOC) capabilities...  ...technologies and application programming interface (API) integrations, including Cribl, Tines, or...  ...with SOC analysts and threat detection engineers to prioritize, develop, and tune threat-... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    17 hours ago
  • $105.4k - $207.8k

    Position Summary Deloitte is seeking an AI Cloud Security Engineer, Senior Consultant to design, build, and secure next-generation AI...  ...across models, agents, tools, application programming interfaces (APIs), data, cloud workloads, development pipelines, and runtime... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    9 hours ago
  • $198k - $368k

     ...and others. If you're as passionate about your future as we are, join our team.KPMG is currently seeking a Director, Global Security Engineering Lead to join our Global Digital Group which is part of KPMG International.Responsibilities:Own the engineering architecture,... 
    H1b
    Local area

    KPMG

    Cleveland, OH
    1 day ago
  • $82.6k - $162.8k

     ...clients to operate with resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/31/2026. Work you'll do As a Managed Services Engineer II on the Cyber Operate Offering team, you will be responsible for helping... 
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    17 hours ago
  •  ...threat events Conduct threat-to-control gap assessments against security controls, risk treatments, and business dependencies Apply...  ...exercises, and risk decisions Partner with Cyber Defense, Security Engineering, Fraud, Third-Party Risk Management, Third-Party Security,... 

    Jobtailor

    Brooklyn, OH
    1 day ago
  • $96k - $181k

     ...s broader Cyber Defense function within Corporate Information Security. Cyber Defense's mission is simple: We aim to Deter, Detect, Deny...  ...relevant to KeyBank. Partner with Cyber Defense, Security Engineering, Fraud, Third-Party Risk Management, Third-Party Security,... 
    Work at office
    Remote work
    Flexible hours

    Key Bank

    Brooklyn, OH
    4 days ago
  • About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure...  ...the position We are seeking an experienced Information Security Engineer with a strong background in implementing and managing general... 
    Remote work

    Keyfactor

    Cleveland, OH
    3 days ago
  • $134.5k - $265.1k

     ...Summary As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection...  ...Experience building and integrating REST APIs, microservices, and serverless...  ...cybersecurity concepts (e.g., application security, cloud security, identity, detection engineering... 
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    4 days ago
  • $155.6k - $306.8k

     ...confidence, and proactively manage their security posture.Recruiting for this role ends on...  ...you will do:As a Cyber Forward Deployed Engineer (FDE) Manager, you will lead delivery of...  ...Experience building and integrating REST APIs, microservices, and serverless architectures... 
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    9 hours ago
  •  ...Processing CenterJob DescriptionThe Lead Software Engineer provides technical leadership for the...  ...partners with business, architecture, security, and product teams to deliver scalable,...  ...enterprise architecture standards.• Develop APIs, integrations, databases, and user-facing... 
    Full time
    Work experience placement
    Work at office

    Northwest Bank

    Independence, OH
    4 days ago
  •  ...Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities...  ...through automation, and deliver secure, scalable, and future-ready networking solutions...  ...automation technologies such as Python, APIs, and automation frameworks.Minimum 3... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Cleveland, OH
    17 hours ago
  • $69.4k - $158k

    Cyber Security AnalystThe Opportunity:As a security operations center analyst, you’re in the middle of the action, responding to and...  ...clearanceBachelor's degree in an Information Systems, Cybersecurity, or Engineering fieldClearance:Applicants selected will be subject to a... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Shift work

    Booz Allen Hamilton

    Cleveland, OH
    3 days ago
  • $198k - $368k

     ...passionate about your future as we are, join our team.KPMG is currently seeking a Director, Cyber Architecture & Engineering to join our Enterprise Security Services organization.Responsibilities:Serve as a senior security architect and trusted advisor, leading the development... 
    H1b
    Local area

    KPMG

    Cleveland, OH
    1 day ago
  • $130k - $160k

     ...performance team.This is a role for someone who wants to do serious engineering in a startup environment: move quickly, think deeply, work with...  ...knowledge of relevant codes and standards such as ASME and API Experience reviewing or developing piping layouts, supports,... 
    Remote work
    Flexible hours

    GrabJobs

    Lakewood, OH
    1 day ago
  • $134.5k - $265.1k

    Position Summary Deloitte is seeking an AI Cloud Security Engineer, Manager to lead the design, implementation, and security of artificial...  ...models, agents, tools, application programming interfaces (APIs), data, cloud workloads, development pipelines, and runtime... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Cleveland, OH
    9 hours ago
  •  ...Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities...  ...through automation, and deliver secure, scalable, and future-ready networking solutions...  ...automation technologies such as Python, APIs, and automation frameworks.Minimum 3... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Cleveland, OH
    2 days ago
  •  ...leading capabilities in digital, cloud and security. Combining unmatched experience and...  ...communities. Visit us at . A successful Network Engineer Architect combines deep technical...  ...automation technologies such as Python, APIs, and automation frameworks.Minimum 8 years... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Cleveland, OH
    4 days ago
  •  ...Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities...  ...through automation, and deliver secure, scalable, and future-ready networking solutions...  ...automation technologies such as Python, APIs, and automation frameworks.Minimum 8... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Cleveland, OH
    17 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to API Security Engineer. Be the first to apply!