API Security Engineer
Key · Ohio
📍 Brooklyn, OHvia workdayFirst listed here 2026-09-24
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Key.
Location:
4910 Tiedeman Road, Brooklyn Ohio
API Security Engineer
Role Overview
We are seeking an experienced API & Application Security Engineer with expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling .
This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments.
The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation.
Key Responsibilities
API Security
Deploy, configure, administer, and optimize enterprise API security platforms and controls .
Perform continuous API discovery, inventory, classification, and security posture management.
Identify shadow, rogue, zombie, deprecated, and undocumented APIs .
Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns.
Identify vulnerabilities including BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, security misconfigurations, and business-logic abuse .
Assess APIs against the OWASP API Security Top 10 and organizational security standards.
Investigate API security alerts and coordinate remediation with engineering and application teams.
Integrate API security findings with SIEM, SOAR, vulnerability management, incident response, and ticketing workflows .
eBPF Agent / Sensor Deployment
Design, deploy, configure, and maintain eBPF-based API security agents and sensors across Linux, containerized, Kubernetes, and cloud environments.
Deploy traffic-collection components to provide visibility into API communications and application behavior.
Validate operating-system, kernel, container runtime, Kubernetes, networking, and infrastructure prerequisites for eBPF deployments.
Troubleshoot agent installation, connectivity, permissions, kernel compatibility, traffic visibility, telemetry collection, and performance issues .
Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact.
Develop standards and automation for repeatable, enterprise-scale agent deployments.
Support agent upgrades, configuration changes, health monitoring, troubleshooting, and lifecycle management.
Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.
API Gateway & Middleware Integrations
Integrate API security platforms with enterprise API gateways, middleware platforms, reverse proxies, ingress controllers, and traffic-management technologies .
Work with API proxies, products, policies, routing configurations, authentication mechanisms, and traffic-management controls.
Configure and validate API traffic visibility between gateways and API security platforms.
Review gateway policies for authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security-control weaknesses .
Support integrations with both cloud-native API management platforms and enterprise on-premises gateway appliances .
Configure and validate traffic forwarding, mirroring, logging, telemetry, or other supported collection mechanisms.
Troubleshoot connectivity, certificate, traffic collection, API discovery, and integration issues.
Partner with gateway administrators, middleware engineers, application teams, and platform owners to remediate identified security weaknesses.
Web Application Firewall / WAAP
Deploy, configure, administer, and optimize enterprise WAF/WAAP security controls .
Configure and tune WAF policies, custom rules, rate controls, network/IP controls, and application protections.
Analyze HTTP/HTTPS traffic and security events to identify attacks, anomalous activity, and false positives.
Investigate SQL injection, XSS, command injection, path traversal, file inclusion, malicious automation, and other application-layer attacks .
Onboard applications and APIs to enterprise web and API protection services.
Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic.
Support security incident investigations using WAF, API, application, and network telemetry.
Security Architecture & Threat Modeling
Perform security architecture reviews for APIs, web applications, microservices, API gateways, middleware platforms, Kubernetes, containers, and cloud environments .
Conduct threat modeling to identify attack surfaces, trust boundaries, abuse cases, authorization risks, sensitive-data exposure, and potential control gaps .
Review authentication and authorization architectures involving OAuth 2.0, OIDC, JWT, API keys, mTLS, IAM, RBAC, and other access-control mechanisms .
Evaluate end-to-end API traffic flows from clients through edge-security controls, gateways, middleware, microservices, and backend applications.
Recommend preventive, detective, and compensating security controls based on identified risks.
Participate in application and infrastructure design reviews and promote secure-by-design engineering practices.
Application Security & Automation
Perform application and API security assessments using manual and automated testing techniques.
Apply the OWASP Top 10 and OWASP API Security Top 10 to application and API assessments.
Perform HTTP/API request and response analysis, vulnerability validation, and remediation verification.
Work with intercepting proxies, API clients, command-line testing tools, SAST, DAST, SCA, and API security testing technologies .
Integrate application and API security testing into CI/CD and DevSecOps pipelines .
Develop
More Ohio jobs
Ohio jobs · Browse all locations