1,421,583open jobs
83,066companies
211,600added this week
Browse all
Salary
$116k – $216k per year
Location
Remote (United States)
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 9, 2026. First seen by Alion on Sep 14, 2026.

Overview
Company
Impact
Profile match
KeyBank is the banking subsidiary of KeyCorp, a US regional bank headquartered in Cleveland, Ohio, offering consumer and small business banking, mortgages, commercial lending, wealth management and investment banking through KeyBanc Capital Markets. KeyCorp is listed on the New York Stock Exchange and runs a branch network across states from Maine and New York to Ohio, Indiana, Colorado, Idaho, Washington and Alaska, with a large operations campus in Brooklyn, Ohio. Its job board lists branch managers, relationship managers, mortgage loan officers, credit and compliance risk staff, investment bankers, treasury analysts and GenAI product and technology roles.

Location:

4910 Tiedeman Road, Brooklyn Ohio

API Security Engineer

Role Overview

We are seeking an experienced API & Application Security Engineer with expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations, security architecture, and threat modeling.

This role is responsible for designing, deploying, integrating, administering, and optimizing enterprise API and application security controls across cloud, on-premises, containerized, and hybrid environments.

The engineer will partner directly with application development, security architecture, DevOps/SRE, cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections, investigate threats, automate security processes, and drive remediation.

Key Responsibilities

API Security

  • Deploy, configure, administer, and optimize enterprise API security platforms and controls.
  • Perform continuous API discovery, inventory, classification, and security posture management.
  • Identify shadow, rogue, zombie, deprecated, and undocumented APIs.
  • Analyze API traffic, endpoints, parameters, authentication mechanisms, sensitive-data flows, and behavioral patterns.
  • Identify vulnerabilities including BOLA/IDOR, broken authentication and authorization, injection, SSRF, excessive data exposure, security misconfigurations, and business-logic abuse.
  • Assess APIs against the OWASP API Security Top 10 and organizational security standards.
  • Investigate API security alerts and coordinate remediation with engineering and application teams.
  • Integrate API security findings with SIEM, SOAR, vulnerability management, incident response, and ticketing workflows.

eBPF Agent / Sensor Deployment

  • Design, deploy, configure, and maintain eBPF-based API security agents and sensors across Linux, containerized, Kubernetes, and cloud environments.
  • Deploy traffic-collection components to provide visibility into API communications and application behavior.
  • Validate operating-system, kernel, container runtime, Kubernetes, networking, and infrastructure prerequisites for eBPF deployments.
  • Troubleshoot agent installation, connectivity, permissions, kernel compatibility, traffic visibility, telemetry collection, and performance issues.
  • Validate that deployed sensors provide appropriate API visibility while minimizing application and infrastructure impact.
  • Develop standards and automation for repeatable, enterprise-scale agent deployments.
  • Support agent upgrades, configuration changes, health monitoring, troubleshooting, and lifecycle management.
  • Apply least-privilege and secure deployment practices to agent permissions and runtime configurations.

API Gateway & Middleware Integrations

  • Integrate API security platforms with enterprise API gateways, middleware platforms, reverse proxies, ingress controllers, and traffic-management technologies.
  • Work with API proxies, products, policies, routing configurations, authentication mechanisms, and traffic-management controls.
  • Configure and validate API traffic visibility between gateways and API security platforms.
  • Review gateway policies for authentication, authorization, rate limiting, TLS/mTLS, data exposure, routing, and security-control weaknesses.
  • Support integrations with both cloud-native API management platforms and enterprise on-premises gateway appliances.
  • Configure and validate traffic forwarding, mirroring, logging, telemetry, or other supported collection mechanisms.
  • Troubleshoot connectivity, certificate, traffic collection, API discovery, and integration issues.
  • Partner with gateway administrators, middleware engineers, application teams, and platform owners to remediate identified security weaknesses.

Web Application Firewall / WAAP

  • Deploy, configure, administer, and optimize enterprise WAF/WAAP security controls.
  • Configure and tune WAF policies, custom rules, rate controls, network/IP controls, and application protections.
  • Analyze HTTP/HTTPS traffic and security events to identify attacks, anomalous activity, and false positives.
  • Investigate SQL injection, XSS, command injection, path traversal, file inclusion, malicious automation, and other application-layer attacks.
  • Onboard applications and APIs to enterprise web and API protection services.
  • Tune security policies to maintain effective protection while minimizing impact to legitimate application traffic.
  • Support security incident investigations using WAF, API, application, and network telemetry.

Security Architecture & Threat Modeling

  • Perform security architecture reviews for APIs, web applications, microservices, API gateways, middleware platforms, Kubernetes, containers, and cloud environments.
  • Conduct threat modeling to identify attack surfaces, trust boundaries, abuse cases, authorization risks, sensitive-data exposure, and potential control gaps.
  • Review authentication and authorization architectures involving OAuth 2.0, OIDC, JWT, API keys, mTLS, IAM, RBAC, and other access-control mechanisms.
  • Evaluate end-to-end API traffic flows from clients through edge-security controls, gateways, middleware, microservices, and backend applications.
  • Recommend preventive, detective, and compensating security controls based on identified risks.
  • Participate in application and infrastructure design reviews and promote secure-by-design engineering practices.

Application Security & Automation

  • Perform application and API security assessments using manual and automated testing techniques.
  • Apply the OWASP Top 10 and OWASP API Security Top 10 to application and API assessments.
  • Perform HTTP/API request and response analysis, vulnerability validation, and remediation verification.
  • Work with intercepting proxies, API clients, command-line testing tools, SAST, DAST, SCA, and API security testing technologies.
  • Integrate application and API security testing into CI/CD and DevSecOps pipelines.
  • Develop automation using Python, Bash, PowerShell, Go, JavaScript, APIs, or similar technologies.
  • Automate agent deployment, configuration validation, API onboarding, security testing, reporting, alert enrichment, and vulnerability-management workflows.
  • Work directly with developers to explain vulnerabilities, recommend practical remediation, and validate fixes.

Education & Experience

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, Software Engineering, or a related technical discipline and relevant professional experience; or
  • An equivalent combination of college education, technical training, industry certifications, and hands-on cybersecurity experience.
  • Candidates with an Associate degree, relevant college coursework, technical certifications, or substantial professional experience in lieu of a four-year degree may be considered.
  • Demonstrated professional experience in API security, application security, WAF/WAAP engineering, security architecture, DevSecOps, cloud security, vulnerability management, or security engineering.
  • Hands-on experience deploying and supporting enterprise API security, application security, API gateway, and traffic-monitoring technologies is strongly preferred.

Required Technical Qualifications

  • Hands-on experience with enterprise API security technologies.
  • Experience deploying, configuring, and tuning WAF/WAAP security controls.
  • Understanding of eBPF-based agent/sensor deployment and troubleshooting in Linux, Kubernetes, containerized, and cloud environments.
  • Experience integrating API security platforms with enterprise API gateways and API management technologies.
  • Strong knowledge of HTTP/HTTPS, DNS, TLS/mTLS, REST, GraphQL, JSON, OpenAPI/Swagger, web services, and API gateway architectures.
  • Strong understanding of the OWASP API Security Top 10 and OWASP Top 10.
  • Knowledge of OAuth 2.0, OIDC, JWT, API keys, IAM, RBAC, and modern API authorization models.
  • Experience performing security architecture reviews and threat modeling.
  • Working knowledge of public cloud platforms, Kubernetes, containers, Linux, and microservices.
  • Experience with secure SDLC, DevSecOps, CI/CD, vulnerability management, and incident-response processes.
  • Ability to troubleshoot complex integrations across applications, gateways, middleware, networks, security controls, and cloud infrastructure.
  • Ability to work directly with developers, architects, API gateway teams, middleware engineers, DevOps/SRE, cloud, network, SOC, and infrastructure teams.

Preferred Qualifications

  • Experience operating enterprise-scale API security and application security environments.
  • Experience with eBPF-based API traffic collection and Kubernetes/Linux sensor deployments.
  • Advanced experience integrating security platforms with cloud-based API management solutions and enterprise gateway appliances.
  • Experience with API gateways, reverse proxies, service meshes, ingress controllers, and load-balancing technologies.
  • Experience integrating security telemetry with SIEM/SOAR platforms.
  • Experience with penetration testing and adversarial API/application security assessments.
  • Familiarity with STRIDE, attack trees, or comparable threat-modeling methodologies.
  • Experience developing security tooling and automation at enterprise scale.
  • Relevant industry certifications in information security, application security, penetration testing, cloud security, or DevSecOps are preferred but not required.

Key Technical Skills

API Security | Application Security | WAF/WAAP | eBPF | Linux | Kubernetes | API Gateway Security | API Management | API Discovery | API Posture Management | REST | GraphQL | OWASP API Top 10 | OWASP Top 10 | OAuth 2.0 | OIDC | JWT | TLS/mTLS | OpenAPI/Swagger | DevSecOps | CI/CD | Python | Security Automation | Threat Modeling | Security Architecture | Cloud Security | SIEM/SOAR | Vulnerability Management

What Success Looks Like

The successful candidate will serve as a technical subject-matter expert for enterprise API and application security, with the ability to deploy and troubleshoot eBPF-based security agents, integrate security capabilities with cloud and on-premises API gateway technologies, and secure complex enterprise API architectures.

The engineer will combine hands-on security engineering with API security, WAF/WAAP, application security, security architecture, threat modeling, cloud security, DevSecOps, and automation expertise while working directly with engineering teams to implement scalable secure-by-design solutions.

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $116,000.00 - $216,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/26/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing [email protected].

#LI-Remote
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,421,583 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
United States
≈ $19k – $53k per year (Estimated) • Remote (Chile) • Las Condes
Cybersecurity
ISO 27001
DLP
Management
Jira
ServiceNow
Apply
$131k per year • Remote (United States) • TS/SCI • Full-Time • United States
Apply
≈ $40k – $96k per year (Estimated) • Remote (Spain) • Full-Time • 3+ years exp • Spain
Python
PowerShell
Cybersecurity
Elastic SIEM
MITRE ATT&CK
IBM QRadar
Cortex XSOAR
SIEM
Apply
$100k – $150k per year • Remote (United States) • 6+ years exp • PhD
Python
Java
C++
Databases
KDB+
Apply
$90k – $120k per year • In office • Contractor • 5+ years exp • Fort Worth
Python
JavaScript
TypeScript
Python
FastAPI
Databases
PostgreSQL
Frontend
React.js
DevOps
Terraform
Azure
AWS
GitHub
Linux
Windows
Cybersecurity
HashiCorp Vault
Cryptography
Vault
Apply
≈ $34k – $82k per year (Estimated) • In office • 7+ years exp • Bengaluru
Python
Go
JavaScript
TypeScript
AI/ML
Fine-tuning
Function Calling
AI Agents
Langfuse
LangSmith
LLM
RAG
Structured Outputs
LLM Guardrails
Tool Use
Frontend
Next.js
React.js
DevOps
Datadog
AWS
Cloudflare
Apply
≈ $65k – $156k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Singapore
Python
SQL
PowerShell
Databases
PostgreSQL
Redis
Snowflake
Oracle
MS SQL
Amazon Aurora
Azure SQL Database
DevOps
Rest API
Terraform
Ansible
GCP
Azure
CI/CD
AWS
Kubernetes
Management
Agile
Apply
$20k per year • In office • Yekaterinburg
Go
SQL
1C
Databases
PostgreSQL
DevOps
Rest API
CI/CD
Apply
≈ $9k – $25k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Master's Degree • Mumbai
SQL
Analytics
Power BI
Apply
≈ $21k – $52k per year (Estimated) • In office • 3+ years exp • Bengaluru
Python
AI/ML
LangChain
LlamaIndex
Embeddings
Prompt Engineering
AI Agents
Gemini
LLM
RAG
Semantic Search
OpenAI
Anthropic
Semantic Search
Apply
$96k – $181k per year • Remote (United States) • Full-Time • Bachelor's Degree • United States
Web3
DAO
Apply
$80k – $150k per year • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • New York
Analytics
Microsoft Excel
Apply
$96k – $181k per year • Remote (United States) • Full-Time • 12+ years exp • Bachelor's Degree • United States
Python
Go
JavaScript
PowerShell
Bash
AI/ML
AI Agents
Red Teaming
Machine Learning
DevOps
GCP
Kali Linux
Azure
AWS
Linux
Windows
Cybersecurity
MITRE ATT&CK
SIEM
Apply
$96k – $181k per year • Remote (United States) • Full-Time • Bachelor's Degree • United States
Cybersecurity
MITRE ATT&CK
MITRE D3FEND
Cyber Kill Chain
Diamond Model
SIEM
Apply
$96k – $181k per year • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Chicago • Albany • Cincinnati • Charlotte • Denver
Management
Outlook
SharePoint
Agile
Microsoft Office
Apply
≈ $60k – $111k per year (Estimated) • In office • 2+ years exp • High School Diploma • United States
Apply
$46k – $52k per year • In office • Full-Time • United States
Apply
Valet Driver 1 hour ago
≈ $33k – $73k per year (Estimated) • In office • PhD • United States
AI/ML
Computer Vision
Apply
IT Project Manager 1 hour ago
$89k – $148k per year • Remote (United States) • Secret • 5+ years exp • Bachelor's Degree • United States
DevOps
AWS
Management
Microsoft Project
Microsoft Office
Apply
up to $46k per year • In office • Full-Time • United States
Apply
See all jobs
This is one of many
1,421,583 more open roles from verified company boards, updated every day.