8 days ago
Base Salary
$109k - $182k/yr
Responsibilities
- Implement and tune runtime API protections across API gateways, service meshes, ingress and edge layers.
- Provide secure API design guidance covering authentication, authorization, validation, error handling, pagination, idempotency, versioning, and least-privilege access.
- Build CI/CD automation for policy-as-code, OpenAPI checks, secrets scanning, SAST, DAST, API testing, and runtime-to-ticket workflows.
- Develop dashboards and analytics from API telemetry and security findings to measure risk, adoption, control effectiveness, and outcomes.
- Define and promote governance for API inventories, ownership, classification, security requirements, exceptions, and control validation.
- Partner with product, platform, SRE, application, and security teams throughout the DevSecOps lifecycle, including planning, threat modeling, design reviews, testing, release readiness, and incident response.
- Map API security controls to NIST, ISO 27001, PCI DSS, FAPI, and OWASP guidance and support audit readiness with control documentation and automated evidence.
- Evaluate, pilot, measure, and scale technologies for API discovery, posture management, runtime detection, and abuse prevention.
Requirements
- 5+ years of related IT and cyber protection experience is desired.
- Master’s degree is preferred, or a bachelor’s degree with equivalent work experience.
- Strong knowledge of API security concepts including OAuth2/OIDC, JWT, session and token handling, scopes and claims, rate limiting, schema validation, and API abuse patterns.
- Practical runtime protection experience with API gateways, WAF/WAAP, service mesh, ingress controllers, or specialized API security platforms.
- Experience building automation in CI/CD and cloud-native environments using policy-as-code, scripting, pipelines, and Git-based workflows.
- Ability to analyze logs, traces, metrics, and other telemetry to detect issues and prioritize actions.
- Working knowledge of secure software development and DevSecOps practices, with the ability to influence engineering outcomes.
- Experience collaborating across security, SRE, platform, and application teams.
- Experience communicating with CISO, CIO, and CTO-level leadership.
- CISSP or another professional cybersecurity certification is desirable.
- Expertise maintaining API protection technologies such as Traceable, Salt Security, or NoName.
- Experience with OpenAPI tooling, API testing, fuzzing, contract testing, threat modeling, abuse-case analysis, financial-industry security controls, and audit evidence is desirable.
Benefits
- Base salary range is $109,000.00–$182,400.00 for employees in New Jersey and New York; ranges may differ in other states.
- Incentive-eligible employees may receive an annual incentive opportunity through cash bonus and/or equity awards.
- Fiserv is an equal opportunity employer and provides reasonable accommodation for applicants with disabilities.
About Fiserv
Fiserv, Inc. (NASDAQ: FISV) is a global technology leader committed to delivering innovative and transformative financial services experiences for clients in more than 100 countries.
