API Risk Management Consultant responsible for managing the API key lifecycle securely and compliantly. Collaborating across teams to ensure seamless integration and access control of API credentials.
Responsibilities
Define and implement the strategy for API key rotation, expiration, and revocation.
Collaborate with product, security, and engineering teams to align API key policies with business and compliance requirements.
Conduct risk assessments and define access scopes for different API consumers.
Proactively monitor applications for non-compliant APIs.
Regularly review API key compliance and rotate keys as needed.
Ensure compliance with data protection regulations (e.g., PCI DSS).
Alert and notify users about upcoming key rotations and compliance requirements.
Create and maintain comprehensive documentation for API key usage, lifecycle policies, and integration guides.
Provide support to internal teams and external partners on API key-related issues.
Requirements
Bachelor's degree in computer science, Information Security, or related field.
3+ years of experience in API management, identity and access management (IAM)
Strong understanding of API lifecycle stages and key management tools (e.g., AWS Secrets Manager, HashiCorp Vault).
Experience with API gateways (e.g., Apigee, AWS API Gateway).
Excellent problem-solving, communication, and documentation skills.
Benefits
Hybrid or remote work options
Cross-functional collaboration with engineering, product, and security teams
Occasional travel for conferences or team meetings
Business Exp Plan & Admin Spec Sr. collaborating with cross - functional teams for PNC's Enterprise Technology & Security Organization. Delivering business planning processes and value - add opportunities while managing projects across physical security.
Cloud Security Engineer focused on protecting Shipt applications and guiding engineering teams in cybersecurity best practices. Designing, developing, and maintaining secure security systems in a hybrid environment.
Construction Site Superintendent overseeing construction projects for Johnson Controls, ensuring timely completion and adherence to project scope, budget, and schedule. Collaborating with teams and managing site activities in the United States.
Senior Security Architect providing security consulting and risk assessment at The Missing Link. Leading initiatives in security architecture and technology risk support within a hybrid work environment.
Apprentice Fire and Security Engineer installing, commissioning, and maintaining electronic protection systems for Johnson Controls. Collaborating in a team - based environment and gaining hands - on experience in fire and security technology.
Teaching and research role in Cybersecurity and AI at De Vinci School. Engaging in course design and research projects in a collaborative academic environment.
Data Protection Security Engineer at Fiserv designing, implementing, and maintaining cybersecurity solutions. Collaborating with teams to safeguard client information and ensure regulatory compliance.
Senior Manager IAM Metric Insights managing metrics and performance in Identity and Access Management. Delivering insights and reporting to enhance security posture for RBC's Global Security team.
HSE Technician I in TechnipFMC's HSE team promoting and supporting an HSE culture. Assisting with investigations, conducting audits, and maintaining safety documentation.
Information Security Officer creating security policies and managing security teams to protect Paytient. Collaborating with internal and external teams to ensure compliance and security posture.