373,907open jobs
9,676companies
50,719added this week
Browse all
Salary
$128k – $216k per year
Location
In office (United States, Alpharetta, Columbus)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Fiserv is a global financial technology and payments company that provides core banking systems, merchant processing, and electronic payment solutions. Headquartered in Milwaukee, Wisconsin, the firm powers transaction processing and digital banking infrastructure for financial institutions, businesses, and consumers worldwide. It is widely known for operating major financial platforms like the Clover point-of-sale system and the Zelle peer-to-peer network.

Calling all innovators - find your future at Fiserv.

We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we're involved. If you want to make an impact on a global scale, come make a difference at Fiserv.

Job Title

API Security Engineer

What does a successful API Security Engineer do at Fiserv?

Help build a best-in-class API security program designed for the speed of modern financial services. This role is an opportunity to shape how APIs are secured end-to-end, design through runtime, using cutting-edge protection technologies and analytics, partnering closely with top engineers across product, platform, and security. You will help turn API telemetry into actionable intelligence, reduce risk at scale, and raise the bar for secure engineering across the

organization. As an API Security Engineer, you will focus on protecting critical API ecosystems by combining secure-by-design guidance, runtime protections, automation, and data-driven governance. You will be hands-on with modern API security capabilities (discovery, posture, threat detection, abuse prevention, and response) and help integrate them into the DevSecOps lifecycle so teams can move fast without compromising trust. You’ll have the space and support

to help build a program that is measurable, automated, and resilient-one that protects customers and enables teams to deliver with confidence. If you enjoy solving tough security problems, working shoulder-to-shoulder with strong engineers, and turning complex signals into simple, scalable controls, this is the role for you.

What you'll do:

  • Runtime API protection: Implement and tune runtime controls (e.g., behavioral detection anomaly and abuse prevention, bot defense, schema enforcement, mTLS/OAuth validation, rate limiting, and threat response) across API gateways, service mesh, and edge layers.

  • Secure API design guidance: Partner with engineering teams to define and promote secure API patterns (authentication/authorization, input validation, error handling, pagination, idempotency, versioning, and least-privilege access). Provide practical guidance aligned to OWASP API Security Top 10 and modern design standards (OpenAPI/JSON Schema).

  • Automation and integration: Build automation that embeds API security into CI/CD (policy-as[1]code, automated checks against OpenAPI specs, secrets scanning, SAST/DAST/API testing, and runtime-to-ticket workflows). Reduce friction through reusable tooling and self-service guardrails.

  • Data analytics and insights: Develop dashboards and analytics using API telemetry and security findings to measure risk, adoption, control effectiveness, and program outcomes.

  • Translate signals into prioritized actions for engineering and leadership.

  • API security governance: Help define governance for API inventories, ownership,

  • classification, security requirements, exception handling, and control validation. Drive consistent standards across teams while enabling delivery velocity.

  • DevSecOps lifecycle partnership: Work with product and platform teams to integrate security requirements into backlog planning, threat modeling, design reviews, testing, release readiness and incident response.

  • Framework alignment (financial services): Map controls and program outcomes to relevant industry frameworks and expectations (e.g., NIST, ISO 27001, PCI DSS, FAPI, and OWASP guidance).

  • Support audit readiness through clear control documentation and evidence automation.

  • Continuous improvement and innovation: Evaluate emerging technologies and technique for API discovery, posture management, and runtime detection.

  • Pilot, measure, and scale what works.

Experience you'll need to have:

  • 5+ years related IT and cyber protection experience desired.

  • MS preferred or bachelor’s degree with equivalent work experience

  • Strong foundation in API security concepts: authN/authZ (OAuth2/OIDC, JWT), session/token handling, scopes/claims, rate limiting, schema validation, and common API abuse patterns.

  • Practical experience with runtime protection in one or more of: API gateways, WAF/WAAP, service mesh, ingress controllers, or specialized API security platforms.

  • Experience building automation in CI/CD and cloud-native environments (policy-as-code, scripting, pipelines, Git-based workflows).

  • Ability to use data and telemetry (logs, traces, metrics) to detect issues, tell a clear story, and drive priorities.

  • Working knowledge of secure software development and DevSecOps practices, and the ability to influence engineering outcomes through partnerships.

  • Comfort collaborating across security, SRE, platform, and application teams-clear communication, pragmatic decision-making, and strong follow-through.

  • Experience communicating with CISO/CIO/CTO level leadership.

  • CISSP or other professional cyber certification desirable

  • Expert knowledge of and experience with maintaining cyber technologies that can protect operational API systems, such as:

  • o Traceable

  • o Salt Security

  • o NoName

What would be great to have:

  • Experience with OpenAPI tooling, API testing, fuzzing, and contract testing.

  • Familiarity with threat modeling approaches and abuse-case analysis for APIs.

  • Experience aligning security controls to financial industry expectations and producing evidence that stands up to audit scrutiny

Sponsorship:

  • You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring sponsorship, now or in the future, will not be considered.

Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, gender, gender identity, sexual orientation, age, disability, protected veteran status, or any other category protected by law.

If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process, please contact [email protected]. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiserv’s Disability Accommodation Policy for additional information.

Note to agencies: Fiserv does not accept resume submissions from agencies outside of existing agreements. Please do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.

Warning about fake job posts: Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.

Salary Range

$128,000.00 - $216,000.00

These pay ranges apply to employees in New Jersey and New York. Pay ranges for employees in other states may differ.

It is unlawful to discriminate against a prospective employee due to the individual's status as a veteran.

For incentive eligible associates, the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Company’s sole discretion.

Thank you for considering employment with Fiserv. Please:

  • Apply using your legal name
  • Complete the step-by-step profile and attach your resume (either is acceptable, both are preferable).

Our commitment to Equal Opportunity:

Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, gender, gender identity, sexual orientation, age, disability, protected veteran status, or any other category protected by law.

If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process, please contact [email protected]. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiserv’s Disability Accommodation Policy for additional information.

Note to agencies:

Fiserv does not accept resume submissions from agencies outside of existing agreements. Pleasedo not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.

Warning about fake job posts:

Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
373,907 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Alpharetta
$110k – $185k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Quincy
DevOps
Azure
IAM
Rest API
Cybersecurity
Least Privilege
Microsoft Entra ID
Management
Confluence
ServiceNow
Apply
$29k – $76k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru • Nagpur • Jaipur • Indore • Gurgaon
Python
DevOps
AWS
CI/CD
Apply
$135k – $297k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Dublin
C++
Java
Python
AI/ML
Airflow
Kubeflow
DevOps
CI/CD
Docker
Kubernetes
Apply
$33k – $82k per year (Estimated) • In office • Full-Time • 8+ years exp • Gurgaon
AI/ML
LLM
DevOps
CI/CD
Apply
$29k – $76k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru • Nagpur • Jaipur • Indore • Gurgaon
Python
DevOps
AWS
CI/CD
Apply
$21k – $55k per year (Estimated) • In office • Full-Time • Pune
Java
TypeScript
JavaScript
Java
Gradle
Maven
Quarkus
Spring Boot
Frontend
Angular
DevOps
AWS
Azure
CI/CD
GCP
GitLab
Cybersecurity
Fortify
SonarQube
Management
Confluence
QA
Postman
SoapUI
Apply
$90k per year • In office • Full-Time • Milan
SQL
Cybersecurity
PCI DSS
Analytics
Power BI
Management
Miro
Apply
$83k – $189k per year (Estimated) • In office • Full-Time • Dublin
Apply
Sr. SDET 1 day ago
$109k – $163k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Sunnyvale
Java
Python
SQL
Java
Spring Framework
Mobile
JUnit
DevOps
CI/CD
Kubernetes
QA
Cypress
JMeter
Postman
Apply
$79k – $159k per year (Estimated) • In office • Full-Time • 6+ years exp • Lincoln
C#
C#
.NET
DevOps
AWS
Azure
CI/CD
Docker
Dynatrace
GCP
GitHub
GitHub Actions
Grafana
Jenkins
Kubernetes
Splunk
QA
Cypress
JMeter
k6
Pact
Playwright
Postman
Rest-Assured
Selenium
Supertest
WebDriverIO
Apply
$100k – $215k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Alpharetta • Columbus
JavaScript
Objective-C
Swift
TypeScript
Swift
Carthage
Databases
Cassandra
Frontend
Angular
React.js
Mobile
CocoaPods
SwiftUI
DevOps
Azure
Azure DevOps
CI/CD
Git
Jenkins
VMWare
Apply
$128k – $204k per year • Equity • In office • Full-Time • 8+ years exp • Alpharetta • Columbus • Frisco • Omaha
DevOps
AWS
Azure
GCP
Kubernetes
Cybersecurity
Snort
Suricata
Tcpdump
Wireshark
Zero Trust
Apply
API Security Engineer 3 hours ago
$110k – $186k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Alpharetta
DevOps
CI/CD
Git
Cybersecurity
ISO 27001
PCI DSS
Threat Modeling
Least Privilege
Apply
$72k – $119k per year • In office • Full-Time • Bachelor's Degree • Boca Raton • Alpharetta • Dayton
Java
DevOps
CI/CD
Git
Apply
$59k – $99k per year • In office • Full-Time • Bachelor's Degree • Alpharetta
C++
JavaScript
Python
SQL
C#
C#
.NET
DevOps
AWS
Azure
Apply
See all jobs
This is one of many
373,907 more open roles from verified company boards, updated every day.