Job Closed
This listing is no longer active.
Based in Foster City, California, Visa is a global payments technology organization. Visa was founded in 1958, coinciding with Bank of America’s launch of the
Senior Cybersecurity Engineer – API Security, Platform
Location
Brazil
Posted
72 days ago
Salary
0
Seniority
Senior
Job Description
Senior Cybersecurity Engineer – API Security, Platform
Visa
• Designing, implementing, and operating identity and authorization platforms used across internal and external services • Defining and evolving authentication and authorization patterns based on OAuth 2.0, OpenID Connect, and token-based security • Supporting and improving API security using API Gateway technologies, preferably Kong, including authentication flows, rate limiting, and policy enforcement • Collaborating with engineering teams to securely integrate identity solutions into APIs and services • Building and maintaining infrastructure using Infrastructure as Code (Terraform) • Operating and securing Kubernetes-based workloads and identity-related services • Contributing to cloud architecture decisions with a strong focus on security, resilience, and scalability • Partnering with DevOps and SRE teams to improve observability, incident response, and operational excellence • Participating in security reviews, threat modeling, and architecture design discussions • Defining best practices, documentation, and reference architectures for identity and access management • Continuously learning and staying current with modern identity, cloud security, and platform engineering practices
Job Requirements
- 6 or more years of work experience with a Bachelor's Degree or 4 or more years of relevant experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or up to 3 years of relevant experience with a PhD
- Strong experience securing API Gateway platforms, with deep familiarity in architectures based on Kong Gateway (Enterprise or OSS), including ingress and egress traffic patterns in cloud‑native environments
- Proven expertise in Identity and service‑to‑service security, including the design, enforcement, and validation of mTLS‑based communication, certificate lifecycle management, and trust boundaries across distributed systems.
- Hands‑on experience working with Public Key Infrastructure (PKI) concepts and implementations, including certificate issuance, rotation, revocation, and integration with gateways and workloads.
- Deep understanding of API security controls implemented at the gateway layer, such as OAuth2, OpenID Connect, JWT validation, client credentials, rate limiting, traffic filtering, and abuse prevention.
- Strong experience securing Kubernetes‑based platforms, including API Gateway deployments running inside clusters, with knowledge of namespaces, workload isolation, network policies, and integration with service mesh when applicable.
- Solid experience reviewing and influencing Infrastructure as Code (IaC) used to provision API Gateways, identity components, and supporting infrastructure, particularly using Terraform and GitOps‑style workflows.
- Proven ability to perform security assessments, threat modeling, and architectural reviews for gateway and identity platforms, identifying systemic risks, misconfigurations, and scalability concerns.
- Strong understanding of observability and security monitoring for gateways and identity services, including logs, metrics, and traces used to detect anomalies, investigate incidents, and support audits.
- Excellent analytical and problem‑solving skills, with strong attention to detail when operating in high‑traffic, multi‑environment, and multi‑region platforms.
- Ability to clearly communicate security risks, architectural decisions, and remediation strategies to engineering teams, platform owners, and non‑technical stakeholders.
- Demonstrated ability to lead and influence cross‑functional teams, including platform engineering, SRE, and application teams, ensuring consistent security baselines across the API and identity ecosystem.
Benefits
- Remote position
- Opportunity to work with experienced entrepreneurs and engineers
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cloud Network Security Architect, SME – Public Trust/Secret Clearance
TOMORROW HIRETOMORROW HIRE is revolutionizing the staffing industry by integrating advanced AI technology with deep human expertise.
• Architect and manage complex AWS network environments to meet TIC 3.0 and federal security standards. • Deploy and manage Palo Alto VM-Series firewalls in AWS, including configuration of GlobalProtect, Panorama, and security policy orchestration. • Use Terraform or CloudFormation to deploy major networking components via Infrastructure as Code (IaC), ensuring repeatable, documented, and auditable environments. • Configure, troubleshoot, and maintain hybrid connectivity solutions, including AWS Direct Connect, Site-to-Site VPNs, and SD-WAN integrations. • Design and implement Transit Gateway architecture and VPC Peering in multi-account AWS environments. • Apply Zero Trust principles and TIC 3.0 requirements within AWS and Palo Alto ecosystems to enhance application and network security. • Serve as the primary (or sole) Network Architect/Engineer responsible for discovery, documentation, design, and execution of network security solutions with minimal supervision. • Collaborate with stakeholders to ensure secure, compliant network designs that support mission-critical federal applications.
Cloud Network Security Architect
TOMORROW HIRETOMORROW HIRE is revolutionizing the staffing industry by integrating advanced AI technology with deep human expertise.
• Architect and manage complex AWS network environments to meet TIC 3.0 and federal security standards. • Deploy and manage Palo Alto VM-Series firewalls in AWS, including configuration of GlobalProtect, Panorama, and security policy orchestration. • Use Terraform or CloudFormation to deploy major networking components via Infrastructure as Code (IaC), ensuring repeatable, documented, and auditable environments. • Configure, troubleshoot, and maintain hybrid connectivity solutions, including AWS Direct Connect, Site-to-Site VPNs, and SD-WAN integrations. • Design and implement Transit Gateway architecture and VPC Peering in multi-account AWS environments. • Apply Zero Trust principles and TIC 3.0 requirements within AWS and Palo Alto ecosystems to enhance application and network security. • Serve as the primary (or sole) Network Architect/Engineer responsible for discovery, documentation, design, and execution of network security solutions with minimal supervision. • Collaborate with stakeholders to ensure secure, compliant network designs that support mission-critical federal applications.
Sales Specialist – Data & AI Security
Veeam SoftwareYour Single Backup and Data Management Platform for Cloud, Virtual and Physical
• Develop and execute a territory plan to drive repeatable revenue within assigned accounts. • Collaborate with account executives to identify and maximize cross-sell opportunities for Securiti AI solutions. • Lead the entire sales process, serving as a trusted advisor, and presenting compelling business cases to customers. • Manage a pipeline of high-value opportunities, ensuring accurate forecasting and CRM discipline. • Expand relationships with key channel partners and resellers to accelerate deal flow and market reach.
IT Security Engineer
Defense UnicornsWe help mission-focused heroes solve the world’s biggest software challenges.
• Serve as the primary point of contact for Tier 1 and Tier 2 user technical support requests, triaging issues and resolving or escalating as appropriate • Provision user laptops and administer a company-wide Mobile Device Management (MDM) solution • Manage inventory of physical and digital IT assets • Onboard and offboard users by managing access through Google Admin Console and related tools • Collaborate with third-party vendors and internal stakeholders to support rollout, troubleshooting, and updates of SaaS tools • Assist with Third Party Risk Management (TPRM) reviews, including security research and audit report reviews • Support technical implementation of security controls aligned with NIST SP 800-171, such as logging, SIEM, incident response, and configuration management • Assist with triage of security events, log audits, and incident response processes



