
Senior API Security Engineer
Lead API security efforts including detection and exploitation of business-logic vulnerabilities (BOLA/IDOR, mass assignment), design and validation of OAuth2/OIDC/JWT authentication and authorization schemes, scripting automated attacks against API gateways to test rate limiting and fraud rules, and working with platform teams to harden gateways (Kong, Azure API Gateway). Requires strong Python scripting and experience with REST and GraphQL security and tools such as Postman, Burp Suite, and 42Crunch.






