KeyBank

API Security Engineer

KeyBank$116K — $216K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in API security and application security
  • Hands-on expertise with WAF/WAAP technologies
  • Proficiency in deploying and managing security in cloud, on-premises, and hybrid environments
  • Experience in threat modeling and security architecture reviews
  • Familiar with integration of security platforms with API gateways and middleware technologies
  • Strong understanding of OWASP security principles
  • Ability to work collaboratively with cross-functional engineering teams.

Responsibilities

  • Design and deploy enterprise API security controls across various environments
  • Conduct continuous API discovery and maintain an accurate security posture
  • Analyze API traffic and identify security vulnerabilities through proactive measures
  • Integrate API security findings with organizational incident response and threat detection systems
  • Establish eBPF-based security agents for enhanced visibility and monitoring of API communications
  • Perform application security assessments leveraging automated and manual techniques
  • Collaborate with developers to remediate vulnerabilities and enhance security practices.

Benefits

  • Comprehensive health, dental, and vision insurance
  • 401(k) retirement plan with employer matching
  • Professional development opportunities including training and certifications
  • Paid time off including vacation and sick leave
  • Flexible work options with a focus on in-office presence where necessary.
Full Job Description

Location:

4910 Tiedeman Road, Brooklyn Ohio

API Security Engineer

Role Overview

We are seeking an experiencedAPI & Application Security Engineer with expertise inAPI security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling.

This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments.

The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation.

Key Responsibilities

API Security

  • Deploy, configure, administer, and optimize enterpriseAPI security platforms and controls.
  • Perform continuous API discovery, inventory, classification, and security posture management.
  • Identifyshadow, rogue, zombie, deprecated, and undocumented APIs.
  • Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns.
  • Identify vulnerabilities includingBOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, security misconfigurations, and business-logic abuse.
  • Assess APIs against theOWASP API Security Top 10and organizational security standards.
  • Investigate API security alerts and coordinate remediation with engineering and application teams.
  • Integrate API security findings withSIEM, SOAR, vulnerability management, incident response, and ticketing workflows.

eBPF Agent / Sensor Deployment

  • Design, deploy, configure, and maintaineBPF-based API security agents and sensorsacross Linux, containerized, Kubernetes, and cloud environments.
  • Deploy traffic-collection components to provide visibility into API communications and application behavior.
  • Validate operating-system, kernel, container runtime, Kubernetes, networking, and infrastructure prerequisites for eBPF deployments.
  • Troubleshootagent installation, connectivity, permissions, kernel compatibility, traffic visibility, telemetry collection, and performance issues.
  • Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact.
  • Develop standards and automation for repeatable, enterprise-scale agent deployments.
  • Support agent upgrades, configuration changes, health monitoring, troubleshooting, and lifecycle management.
  • Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.

API Gateway & Middleware Integrations

  • Integrate API security platforms withenterprise API gateways, middleware platforms, reverse proxies, ingress controllers, and traffic-management technologies.
  • Work with API proxies, products, policies, routing configurations, authentication mechanisms, and traffic-management controls.
  • Configure and validate API traffic visibility between gateways and API security platforms.
  • Review gateway policies forauthentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security-control weaknesses.
  • Support integrations with bothcloud-native API management platforms and enterprise on-premises gateway appliances.
  • Configure and validate traffic forwarding, mirroring, logging, telemetry, or other supported collection mechanisms.
  • Troubleshoot connectivity, certificate, traffic collection, API discovery, and integration issues.
  • Partner with gateway administrators, middleware engineers, application teams, and platform owners to remediate identified security weaknesses.

Web Application Firewall / WAAP

  • Deploy, configure, administer, and optimize enterpriseWAF/WAAP security controls.
  • Configure and tune WAF policies, custom rules, rate controls, network/IP controls, and application protections.
  • Analyze HTTP/HTTPS traffic and security events to identify attacks, anomalous activity, and false positives.
  • InvestigateSQL injection, XSS, command injection, path traversal, file inclusion, malicious automation, and other application-layer attacks.
  • Onboard applications and APIs to enterprise web and API protection services.
  • Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic.
  • Support security incident investigations using WAF, API, application, and network telemetry.

Security Architecture & Threat Modeling

  • Perform security architecture reviews forAPIs, web applications, microservices, API gateways, middleware platforms, Kubernetes, containers, and cloud environments.
  • Conduct threat modeling to identifyattack surfaces, trust boundaries, abuse cases, authorization risks, sensitive-data exposure, and potential control gaps.
  • Review authentication and authorization architectures involvingOAuth 2.0, OIDC, JWT, API keys, mTLS, IAM, RBAC, and other access-control mechanisms.
  • Evaluate end-to-end API traffic flows from clients through edge-security controls, gateways, middleware, microservices, and backend applications.
  • Recommend preventive, detective, and compensating security controls based on identified risks.
  • Participate in application and infrastructure design reviews and promotesecure-by-designengineering practices.

Application Security & Automation

  • Perform application and API security assessments using manual and automated testing techniques.
  • Apply theOWASP Top 10 and OWASP API Security Top 10to application and API assessments.
  • Perform HTTP/API request and response analysis, vulnerability validation, and remediation verification.
  • Work withintercepting proxies, API clients, command-line testing tools, SAST, DAST, SCA, and API security testing technologies.
  • Integrate application and API security testing intoCI/CD and DevSecOps pipelines.
  • Develop automation usingPython, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies.
  • Automateagent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows.
  • Work directly with developers to explain vulnerabilities, recommend practical remediation, and validate fixes.

Education & Experience

  • Bachelors degreein Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience;or
  • An equivalent combination ofcollege education, technical training, industry certifications, and hands-on cybersecurity experience.
  • Candidates with anAssociate degree, relevant college coursework, technical certifications, or substantial professional experiencein lieu of a four-year degree may be considered.
  • Demonstrated professional experience inAPI security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering.
  • Hands-on experience deploying and supportingenterprise API security, application security, API gateway, and traffic-monitoring technologiesis strongly preferred.

Required Technical Qualifications

  • Hands-on experience withenterprise API security technologies.
  • Experience deploying, configuring, and tuningWAF/WAAP security controls.
  • Understanding ofeBPF-based agent/sensor deployment and troubleshootingin Linux, Kubernetes, containerized, and cloud environments.
  • Experience integrating API security platforms withenterprise API gateways and API management technologies.
  • Strong knowledge ofHTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures.
  • Strong understanding of theOWASP API Security Top 10 and OWASP Top 10.
  • Knowledge ofOAuth 2.0, OIDC, JWT, API keys, IAM, RBAC, and modern API authorization models.
  • Experience performingsecurity architecture reviews and threat modeling.
  • Working knowledge of public cloud platforms, Kubernetes, containers, Linux, and microservices.
  • Experience withsecure SDLC, DevSecOps, CI/CD, vulnerability management, and incident-response processes.
  • Ability to troubleshoot complex integrations across applications, gateways, middleware, networks, security controls, and cloud infrastructure.
  • Ability to work directly withdevelopers, architects, API gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams.

Preferred Qualifications

  • Experience operating enterprise-scaleAPI security and application security environments.
  • Experience witheBPF-based API traffic collection and Kubernetes/Linux sensor deployments.
  • Advanced experience integrating security platforms withcloud-based API management solutions and enterprise gateway appliances.
  • Experience with API gateways, reverse proxies, service meshes, ingress controllers, and load-balancing technologies.
  • Experience integrating security telemetry withSIEM/SOAR platforms.
  • Experience with penetration testing and adversarial API/application security assessments.
  • Familiarity withSTRIDE, attack trees, or comparable threat-modeling methodologies.
  • Experience developing security tooling and automation at enterprise scale.
  • Relevant industry certifications ininformation security, application security, penetration testing, cloud security, or DevSecOpsare preferred but not required.

Key Technical Skills

API Security | Application Security | WAF/WAAP | eBPF | Linux | Kubernetes | API Gateway Security | API Management | API Discovery | API Posture Management | REST | GraphQL | OWASP API Top 10 | OWASP Top 10 | OAuth 2.0 | OIDC | JWT | TLS/mTLS | OpenAPI/Swagger | DevSecOps | CI/CD | Python | Security Automation | Threat Modeling | Security Architecture | Cloud Security | SIEM/SOAR | Vulnerability Management

What Success Looks Like

The successful candidate will serve as a technical subject-matter expert forenterprise API and application security, with the ability to deploy and troubleshooteBPF-based security agents, integrate security capabilities withcloud and on-premises API gateway technologies, and secure complex enterprise API architectures.

The engineer will combine hands-on security engineering with API security, WAF/WAAP, application security, security architecture, threat modeling, cloud security, DevSecOps, and automation expertise while working directly with engineering teams to implement scalablesecure-by-design solutions.

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $116,000.00 - $216,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/26/2026

About KeyBank

Shockingly, nearly 9-in-10 people who get their real estate license in America fail. We're solving that problem; And doing it while increasing profitability for the brokerage. Through technology, business automation, and a team approach we have created a system where agents focus solely on working with clients and closing deals.

KeyBank Careers

Joining KeyBank means stepping into a world of professional growth and innovation, where job opportunities abound in an environment that values leadership, diversity, and forward-thinking. As a member of our team, you will be part of a company that's committed to empowering your career journey while contributing to the financial wellness of our communities.

Work You'll Do

At KeyBank, we're not just in the business of banking; we're in the business of helping individuals and communities thrive. By joining our team, you will have the chance to be part of a culture that celebrates diversity and fosters leadership and professional development. Whether you're looking for a position in customer service, IT, finance, or management, KeyBank offers a variety of roles suited to your skills and career aspirations.

Innovate and Lead

KeyBank stands at the intersection of finance and innovation. Our employees are encouraged to lead with creativity and integrity, driving solutions that make a real difference. With a focus on digital transformation and sustainable growth, your work at KeyBank will challenge the status quo and encourage you to explore new ideas.

Grow Your Career

Career growth at KeyBank is not just a possibility—it's a priority. We are dedicated to your professional development through comprehensive training programs, leadership workshops, and continuous learning opportunities. Our commitment to your growth is matched by our dedication to inclusion, ensuring all voices are heard and valued.

Be Part of a Great Team

Our team at KeyBank is our strongest asset. We believe in using our collective skills to foster an environment of innovation and collaboration. Join us and connect with colleagues who are just as passionate and driven as you are. Through teamwork, we achieve exceptional results and push the boundaries of what's possible in the banking sector.

Internship and Employment Opportunities

For those starting their careers, KeyBank offers robust internship and employment opportunities that provide a solid foundation in the financial industry. Interns at KeyBank gain hands-on experience, beneficial networking connections, and insights into our day-to-day operations, setting the stage for a successful career.

Benefits and Culture

KeyBank is committed to offering benefits that enhance your life and well-being. From healthcare to retirement plans, and flexible working conditions, we ensure our employees are well taken care of. More than just benefits, our company culture is built on respect, integrity, and accountability—values that guide us in making a positive impact on our clients and communities.

Join Our Team

Explore the job opportunities at KeyBank and find the right fit for your skills and interests. We are continuously hiring and looking for individuals who are curious, innovative, and ready to make a difference. Prepare your resume, ace your interview, and join a team that's dedicated to your success and to transforming the landscape of banking.

Stay Connected

Keep up to date with the latest career tips, industry insights, and company news by following our careers blog. Personalize your experience by subscribing to job alert emails tailored to your preferences, and discover the exciting and rewarding career opportunities that await at KeyBank.

Search KeyBank Jobs

Ready to take the next step in your career? Search open positions at KeyBank that match your skills and interests. We look for passionate, creative, and solution-driven team players who are ready to grow and succeed in a dynamic and supportive environment.

SEARCH KEYBANK JOBS

Join KeyBank and be part of a company where your career is as important to us as it is to you. Together, let's unlock opportunities for growth, innovation, and meaningful impact in the financial world.
Learn more about KeyBank
Size
17,110 employees
Market Cap
$16 billion
Industry
Net Income
$1.3 billion
Founded
1825
5 Year Trend
+5.6%
NASDAQ

Similar Jobs

More Jobs at KeyBank

More Information Technology Jobs

Find similar API Security Engineer jobs: