Senior Backend/API Security Developer

UST

$82K — $123K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in backend/API security development
  • Proficient in Python, Node.js, or Java
  • Experience with AWS services for API development
  • Knowledge of OWASP API Security standards
  • Familiarity with OAuth2/OIDC and microservices architectures
  • Strong understanding of regulatory compliance (HIPAA, GDPR, PCI-DSS)
  • Experience with encryption and data protection standards

Responsibilities

  • Design and develop secure enterprise-grade APIs
  • Implement strong authentication mechanisms and access controls
  • Ensure compliance with data protection regulations
  • Manage data encryption standards in transit and at rest
  • Conduct security audits and vulnerability assessments
  • Implement rate limiting and WAF for backend protection
  • Collaborate with DevOps on CI/CD pipeline development

Benefits

  • 10 days of paid vacation per year
  • 6 days of paid sick leave annually
  • 401(k) Retirement Plan with employer matching
  • Medical, dental, and vision insurance for employees and dependents
  • Basic life insurance and disability benefits
  • Health Savings Account (HSA) and Flexible Spending Account (FSA) options
Full Job Description
Role description

Senior Backend/API Security Developer

Lead II - Software Engineering

UST is searching for a Senior Backend/API Security Developer (B2) with strong expertise in Python, Node.js, or Java and AWS, responsible for designing, developing, and securing enterprise-grade APIs that handle highly sensitive data.

The opportunity:
• Design Secure Architectures: Build scalable RESTful and GraphQL APIs using AWS services like Amazon API Gateway, AWS Lambda, and Amazon VPC while applying the principle of least privilege.
• Enforce Strict Authentication: Implement robust identity and access management using OAuth 2.0, OpenID Connect (OIDC), AWS IAM, and Amazon Cognito.
• Ensure Regulatory Compliance: Maintain data protection standards required by regulations like HIPAA, GDPR, or PCI-DSS through proper data masking, tokenization, and auditing.
• Manage Encryption Standards: Ensure all data in transit uses TLS 1.3 and data at rest is encrypted using AWS Key Management Service (KMS) with customer-managed keys.
• Conduct Security Audits: Perform automated security scans, static code analysis, and vulnerability assessments using tools like Amazon Inspector and AWS Security Hub.
• Implement Rate Limiting and WAF: Protect backend systems from distributed denial-of-service (DDoS) attacks and injection flaws using AWS WAF and API Gateway throttling controls.
• Establish Comprehensive Logging: Configure centralized monitoring and threat detection using Amazon CloudWatch, AWS CloudTrail, and Amazon GuardDuty for complete audit trails.
• Collaborate with DevOps engineers in designing and developing CI/CD pipeline using Codepipeline

This position description identifies the responsibilities and tasks typically associated with the performance of the position. Other relevant essential functions may be required.

What you need:
• The ideal candidate will drive API security standards, implement secure architecture patterns, and serve as a key technical leader in building a world-class API engineering practice.
• Experience with cloud-native development, OWASP API Security standards, OAuth2/OIDC, and large-scale microservices architectures is required.
• Skills: AWS, OAuth 2.0, Node.js, PostgreSQL

Compensation can differ depending on factors including but not limited to the specific office location, role, skill set, education, and level of experience. UST provides a reasonable range of compensation for roles that may be hired in various U.S. markets as set forth below.

Role Location: Remote-US

Compensation Range: $82,000-$123,000

Benefits

Full-time, regular employees accrue a minimum of 10 days of paid vacation per year, receive 6 days of paid sick leave each year (pro-rated for new hires throughout the year), 10 paid holidays, and are eligible for paid bereavement leave and jury duty. They are eligible to participate in the Company's 401(k) Retirement Plan with employer matching. They and their dependents residing in the US are eligible for medical, dental, and vision insurance, as well as the following Company-paid Employee Only benefits: basic life insurance, accidental death and disability insurance, and short- and long-term disability benefits. Regular employees may purchase additional voluntary short-term disability benefits, and participate in a Health Savings Account (HSA) as well as a Flexible Spending Account (FSA) for healthcare, dependent child care, and/or commuting expenses as allowable under IRS guidelines. Benefits offerings vary in Puerto Rico.

Part-time employees receive 6 days of paid sick leave each year (pro-rated for new hires throughout the year) and are eligible to participate in the Company's 401(k) Retirement Plan with employer matching.

Full-time temporary employees receive 6 days of paid sick leave each year (pro-rated for new hires throughout the year) and are eligible to participate in the Company's 401(k) program with employer matching. They and their dependents residing in the US are eligible for medical, dental, and vision insurance.

Part-time temporary employees receive 6 days of paid sick leave each year (pro-rated for new hires throughout the year).

All US employees who work in a state or locality with more generous paid sick leave benefits than specified here will receive the benefit of those sick leave laws.

#UST

#CB

#LI-AP6

#LI-Remote

Similar Jobs

More Jobs at UST

More Information Technology Jobs

Find similar Senior Backend/API Security Developer jobs: