What does a successful API Security Engineer do at Fiserv?
You will work with the “Operational Application Protection Team” where you will focus on reducing the potential impact of threats to internet facing APIs. You will have frequent interaction with Security Assessment, Security Operations and Cyber Security Incident Response teams working together to find ongoing threats to APIs. You will take the work a step past ‘identify’ and join us in developing protections for APIs using modern cyber technologies and protecting operational APIs in real-time.
What you will do:
- Maintain and run API security configurations
- Perform false positive analysis on API security events
- Design and create alerting and monitoring to ensure platform health and stability
- Be comfortable driving work efforts outside business-hours, when necessary, as part of on-call rotation schedule
- Act as a front-line and escalation interface to the business, reviewing trouble tickets and executing the required actions
What you will need to have:
- 10+ years of IT and cyber protection experience
- 5+ years of experience working on cyber threats as related to API security
- 5+ years of experience utilizing NIST CVE data relating to API vulnerabilities to develop threat response actions utilizing OSI Layer 4 through 7 deep inspections
- 5+ years of experience supporting cyber technologies that can protect operational API systems such as Traceable, Salt Security or NoName
- 3+ years of experience with threat analysis of web application network traffic protocols and patterns
- 2+ years of experience using scripting or automation to reduce team’s workload
- Bachelor’s degree in computer science, or a relevant field, or an equivalent combination of education, work, and/or military experience
What would be great to have:
- Advanced degree in computer science or a related field
- 2+ years of experience resolving network infrastructure issues
- 1+ years of experience in Scripting tools like Python and Bash
- 1+ years of experience in HTTP protocol
- CISSP or other professional cyber certification desirable
#LI-RM1
R-10353544