Epicareer Might not Working Properly
Learn More
I

API Security Architect

Salary undisclosed

Apply on


Original
Simplified

Role Summary:
As an API Security Architect, you will be responsible for designing, implementing, and maintaining robust security measures to protect Freddie Mac's APIs throughout their lifecycle. You will collaborate with various teams to ensure the secure migration and operation of APIs in the cloud environment.

Key Responsibilities:
Security Architecture: Develop and maintain a comprehensive API security architecture aligned with industry best practices and regulatory requirements.
Risk Assessment: Conduct regular risk assessments to identify potential vulnerabilities and threats to APIs.
Threat Modeling: Employ threat modeling techniques to analyze and mitigate security risks.
Cloud Security: Ensure the secure migration and operation of APIs in the cloud environment, leveraging cloud-native security features.
API Gateway Security: Implement and manage API gateways with advanced security features, such as authentication, authorization, rate limiting, and threat protection.
Data Protection: Protect sensitive data transmitted through APIs using encryption, tokenization, and other appropriate measures.
Vulnerability Management: Conduct regular vulnerability assessments and penetration testing to identify and address security weaknesses.
Security Standards: Ensure compliance with industry standards and regulations, such as OWASP API Security Top 10.
Security Awareness: Educate and train development teams on secure API design and coding practices.
Incident Response: Develop and implement incident response plans to effectively handle security breaches and data leaks.

Required Skills and Experience:
Strong understanding of API security principles and best practices.
Experience with cloud platforms (e.g., AWS, Azure, Google Cloud Platform) and their security features.
Proficiency in encryption and decryption algorithms.
Experience with security tools and technologies (e.g., firewalls, intrusion detection systems, web application firewalls).
Excellent communication and interpersonal skills.
Ability to work independently and as part of a team.
Strong problem-solving and analytical skills.
Experience with vulnerability assessment and penetration testing methodologies.
Preferred Qualifications:
Certification in cybersecurity or information security (e.g., CISSP, CISM, CISA).
Experience with specific API security frameworks or standards (e.g., OAuth, OpenID Connect).
Knowledge of scripting languages (e.g., Python, Bash).

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job