KeyBank

API Security Engineer

KeyBank
Apply
1 day ago
Remote, United StatesSenior

Base Salary

$116k - $216k/yr

Responsibilities

  • Deploy, configure, administer, optimize, and troubleshoot enterprise API security, application security, WAF/WAAP, and eBPF-based controls.
  • Perform API discovery, inventory, classification, posture management, traffic analysis, vulnerability identification, and remediation coordination.
  • Deploy and maintain eBPF agents and sensors across Linux, containers, Kubernetes, cloud, and hybrid environments.
  • Integrate API security platforms with API gateways, middleware, reverse proxies, ingress controllers, service meshes, traffic-management systems, SIEM/SOAR, ticketing, and vulnerability-management workflows.
  • Configure and tune WAF policies, custom rules, rate controls, network and IP controls, application protections, and API onboarding.
  • Conduct security architecture reviews and threat modeling for APIs, web applications, microservices, gateways, containers, Kubernetes, and cloud environments.
  • Perform manual and automated API/application security testing, vulnerability validation, remediation verification, and incident investigations.
  • Develop security automation for agent deployment, configuration validation, API onboarding, testing, reporting, alert enrichment, and vulnerability-management workflows.
  • Work directly with developers, architects, gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams to implement secure-by-design solutions.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information technology, information systems, computer engineering, software engineering, or a related technical discipline, with relevant professional experience; equivalent combinations of college education, technical training, certifications, and hands-on cybersecurity experience may be considered.
  • Candidates with an associate degree, relevant college coursework, technical certifications, or substantial professional experience may be considered in lieu of a four-year degree.
  • Professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering.
  • Hands-on experience with enterprise API security technologies, WAF/WAAP controls, API gateways, API management, and traffic-monitoring technologies.
  • Experience deploying and troubleshooting eBPF-based agents or sensors in Linux, Kubernetes, containerized, and cloud environments.
  • Strong knowledge of HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, API gateway architectures, OAuth 2.0, OIDC, JWT, API keys, IAM, and RBAC.
  • Experience with security architecture reviews, threat modeling, OWASP API Security Top 10, OWASP Top 10, secure SDLC, DevSecOps, CI/CD, vulnerability management, and incident response.
  • Working knowledge of public cloud platforms, Kubernetes, containers, Linux, microservices, and complex integrations across applications, gateways, middleware, networks, and security controls.
  • Experience with security tooling and automation using Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies.
  • Preferred qualifications include enterprise-scale API security operations, cloud API management integrations, gateway appliances, reverse proxies, service meshes, ingress controllers, load balancing, SIEM/SOAR integrations, penetration testing, adversarial assessments, STRIDE or attack trees, and relevant information-security certifications.

Benefits

  • Base salary range is $116,000.00–$216,000.00 annually, with eligibility for incentive compensation; compensation figures are excluded from benefit details.
  • Benefits are available according to the company’s eligible-employee benefits list.
  • The company prioritizes in-office presence while providing flexible options when the role can be performed effectively in a mobile environment.
  • The job posting lists the work location as 4910 Tiedeman Road, Brooklyn, Ohio, and includes the tag #LI-Remote.
  • The job posting expires October 26, 2026.

Tech Stack

Categories

KeyBank

About KeyBank

10,000+ employees

KeyBank, the primary banking subsidiary of KeyCorp (NYSE: KEY), provides retail and commercial banking, payments, wealth management, and equipment financing to consumers and businesses across the United States. Headquartered in Cleveland, it operates a branch-based and digital model, earning interest and fee income from deposits, lending, treasury services, and investment products. KeyCorp was formed in 1994 through the merger of Society Corp. and KeyCorp, creating one of the country’s largest regional banks.

Contact me