API Security Engineer
About the role
API Security Engineer | Long-term Project | Banking
We are looking for…
An experienced API Security Engineer to join a central platform team at one of the Netherlands’ leading banks. In this role, you will help shape and strengthen API security across the organization by implementing security standards, automating controls, and ensuring APIs remain resilient against evolving cyber threats.
Working alongside platform engineers, architects, and security specialists, you’ll play a key role in building secure-by-design API platforms that support both customer-facing and internal services.
Outcomes of the project
As an API Security Engineer, you will strengthen the bank’s API security posture by translating security standards and best practices into scalable platform policies and automated security controls. Your work will enable secure API development, improve compliance with internal security requirements, and reduce risk across the enterprise API landscape.
About the role
As an API Security Engineer, you are responsible for designing, implementing, and continuously improving API security capabilities across a central platform.
You will:
Manage and optimize enterprise API security solutions such as Akamai Noname, Salt Security, or Cequence.
Develop and maintain automated API security policies, business rules, and platform guardrails.
Assess API security findings and determine their severity, business impact, and remediation priorities.
Collaborate with engineers, architects, and security teams to embed security into API design and delivery.
Implement security best practices covering authentication, authorization, and API protection mechanisms.
Ensure APIs comply with internal security standards and industry frameworks.
Drive continuous improvements to API security governance and platform capabilities.
Help strengthen the organization’s resilience against emerging API threats and vulnerabilities.
Experience
Proven experience with API Security platforms such as Akamai Noname, Salt Security, or Cequence.
Strong understanding of cybersecurity principles and security architecture.
Experience with cloud security and application security architecture.
Extensive knowledge of API and application security frameworks including OWASP Top 10, MITRE ATT&CK, and CVE.
Advanced knowledge of authentication and authorization technologies, including:
OAuth 2.0
JWT
Mutual TLS (mTLS)
Session management
Object-Level Authorization
Attribute-Level Authorization
Experience translating security requirements into practical platform policies and automated controls.
Strong analytical skills with the ability to evaluate API security risks and recommend effective improvements.
About Levy Professionals
Since 2000, Levy Professionals has been connecting highly skilled IT professionals with leading international organizations. With offices in Amsterdam and London, we have built an extensive network of experienced consultants and contractors across Europe. We believe in building lasting relationships and matching the right people with the right projects to create long-term success for both our clients and professionals.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.