We're looking for an experienced API Security Consultant to lead and manage the operations of an enterprise-grade API Security Platform. This role will focus on maintaining API security posture, leading investigations, defining security rules and controls, and ensuring seamless integration with client infrastructure.
• Oversee daily administration, configuration, and tuning of the API Security Platform.
• Oversee the creation of detailed system architecture and design documents for the API Security platform.
• Enhance and refine API Security rules, policies, and alerts based on threat intelligence and platform findings.
• Manage platform health checks, uptime monitoring, and integration validations.
• Supervise the integration of the API Security platform with existing systems like F5 LTM and API Gateway.
• Guide the team in setting up effective alerts and notification systems for API security incidents and events.
• Coordinate with SOC, DevOps, and Infra teams for alert triage, issue resolution, and response.
• Direct the creation of comprehensive test plans for system and user acceptance testing.
• Lead the process of managing and maintaining remote collectors and other on-site components of the API Security platform.
Qualifications and Skills
Experience:
- 5+ years in cybersecurity or DevSecOps, with strong exposure to API security.
- Experience with Cequence API Security is highly preferred. Familiarity with similar API security platforms (e.g., Salt Security, or equivalent) will also be considered a strong advantage.
- Strong knowledge of API architectures (REST, SOAP, GraphQL), OAuth2/OIDC, F5, API Gateways, and SIEM integration.
- Familiarity with detecting shadow APIs, PII-sensitive endpoints, and anomalous behavior.
- Deep understanding of platform integrations, custom rule writing, and correlation logic.
- Experience working with or supporting SOC teams is a plus.
Soft Skills:
- Strong analytical and problem-solving abilities with keen attention to detail.
Preferred Certifications
- API Security Certified Specialist,
- CISSP, CCSP, or GWEB
- AWS/GCP/Azure security certifications
- GIAC Cloud Security Automation (GCSA) or equivalent