- Company Name
- ADP
- Job Title
- Director - API Security
- Job Description
-
Job title: Director – API Security
Role Summary:
Lead the design, implementation, and continuous improvement of an enterprise API security program. Spearhead cross‑functional collaboration with engineering, DevOps, and product teams to embed secure API design, development, and deployment practices across all platforms. Manage a team of analysts/engineers or coordinate cross‑functional initiatives, ensuring that security testing, vulnerability triage, and policy enforcement are integrated into CI/CD pipelines.
Expectations:
* Minimum 10 years of cybersecurity experience, with a proven record of leading teams and managing complex security initiatives.
* Deep expertise in API security risks, mitigation strategies, and emerging threat landscapes.
* Hands‑on experience with API security testing tools (e.g., Burp Suite, OWASP ZAP, Postman, SoapUI) and integrating these tools into CI/CD workflows.
* Strong knowledge of RESTful and GraphQL APIs, authentication protocols (OAuth 2.0, JWT), encryption standards, and API gateway architectures.
Key Responsibilities:
* Develop and maintain a comprehensive API security strategy aligned with business and compliance goals.
* Lead or coordinate secure API design and development practices with software engineering, DevOps, and product groups.
* Evaluate and implement AI‑based tools and automation frameworks to enhance API testing effectiveness.
* Oversee the triage, prioritization, and resolution of API vulnerabilities, ensuring rapid risk mitigation.
* Integrate security testing into CI/CD pipelines using automated tools.
* Draft, update, and enforce security policies, standards, and procedures related to APIs.
* Monitor industry trends, emerging threats, tools, and technologies in API and application security.
Required Skills:
* Leadership and team management in a security context.
* API security expertise (OWASP Top 10 for APIs, threat modeling).
* Proficiency with API security testing tools (Burp Suite, OWASP ZAP, Postman, SoapUI).
* Experience integrating security testing into CI/CD pipelines (GitLab CI, Jenkins, GitHub Actions).
* Knowledge of REST, GraphQL, OAuth 2.0, JWT, TLS/SSL, encryption, and API gateway architectures.
* Strong analytical, problem‑solving, and communication skills.
Required Education & Certifications:
* Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
* Relevant security certifications are preferred (e.g., CISSP, CISM, CSX‑API).