Royal Bank of Canada
Job title:
API Security Specialist Lead (Global Security)
Company
Royal Bank of Canada
Job description
Job SummaryJob DescriptionWhat is the opportunity?The API Security Specialist Lead will play a pivotal role in the assessment and implementation of runtime API security solution(s), coordinating with cross-functional teams, and ensuring seamless integration across cloud and on-prem environments within the bank. Additionally, the specialist will be responsible for enhancing API security practices and contributing to the implementation of the API security roadmap.What will you do?API Security Runtime Platform Deployment:Lead the end-to-end deployment of API security solution(s) within the bank.Collaborate with development, operations, and security teams to ensure smooth integration within the bank’s cloud and on-prem infrastructure.Monitor platform performance and ensure it aligns with the agreed KPIs and SLAs.Optimize platform configurations to detect, block, and prevent API-related threats.API Security Roadmap Implementation:Contribute to the planning, execution, and delivery of API security initiatives as part of the broader security improvement roadmap.Stay ahead of emerging threats and technologies, recommending improvements to the API security framework.Automation & Pipeline Integration:Collaborate with Application Security Engineering and DevOps teams to automate security processes, such as API vulnerability detection, policy enforcement, and compliance checks.Help integrate API security solutions into CI/CD pipelines for continuous testing and monitoring.Develop scripts and tools to streamline processes and conducting data analysis.Stakeholder Engagement & Documentation:Act as a technical lead, liaising with internal teams (including IT, Compliance, and Risk) and vendors to drive the implementation forward.Document processes, configurations, and lessons learned to ensure knowledge transfer across the organization.Provide regular updates to senior leadership on work initiatives, risks, and mitigation strategies.What do you need to succeed?Must-have:5+ years of experience in Application & API security.Strong knowledge of API protocols/frameworks (e.g., REST, SOAP, GraphQL, gRPC), API gateways (e.g., Apigee, Kong), Authentication and Authorization Protocols (OAuth2/OIDC/JWT etc.).Strong Understanding of OWASP API Security Top 10 and secure coding practices.Strong knowledge of Kubernetes, Docker, and CI/CD tools (e.g., Jenkins, GitHub Actions).Experience working in cloud environments such as AWS, Azure, or GCP.Strong scripting skills (e.g., Python, Bash) for automation and monitoring tasks.Familiarity with runtime security, eBPF, and traffic monitoring for API discovery.Familiarity with workflow management tools (e.g., Jira, GitHub Issues) for issue tracking and collaboration.Nice-to-have:Expertise in API Security frameworks and experience with API Security Testing tools (DAST, AST, etc.) and Runtime API protection platformsExperience working within financial institutions or other highly regulated industries.Security certifications such as CISSP, CSSLP, CASP, CEH or Certified DevSecOps Engineer.Knowledge of data residency requirements and compliance frameworks (e.g., GDPR, PCI-DSS, NIST CSF).What’s in it for you?We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicableLeaders who support your development through coaching and managing opportunitiesAbility to make a difference and lasting impactWork in a dynamic, collaborative, progressive, and high-performing teamA world-class training program in financial servicesFlexible work/life balance optionsOpportunities to do challenging work#Ll-Hybrid
#Ll-POST
#TECHPJJob Skills API Gateway, API Specifications, API Testing, Application Programming Interface (API) Security, Atlassian JIRA, CloudBees Jenkins, DevSecOps, Dynamic Application Security Testing (DAST), GitHub Actions, GitHub Issues, IT Security Architecture, IT Systems Integration, Kubernetes, OAuth, OWASP Top 10, Python (Programming Language), Secure Coding Practices, Security Engineering, Security Information and Event Management (SIEM), Web Application Penetration TestingAdditional Job DetailsAddress: 330 FRONT ST W:TORONTOCity: TORONTOCountry: CanadaWork hours/week: 37.5Employment Type: Full timePlatform: TECHNOLOGY AND OPERATIONSJob Type: RegularPay Type: SalariedPosted Date: 2024-11-05Application Deadline: 2025-01-03Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date aboveInclusion and Equal Opportunity EmploymentAt RBC, we embrace diversity and inclusion for innovation and growth. We are committed to building inclusive teams and an equitable workplace for our employees to bring their true selves to work. We are taking actions to tackle issues of inequity and systemic bias to support our diverse talent, clients and communities.We also strive to provide an accessible candidate experience for our prospective employees with different abilities. Please let us know if you need any accommodations during the recruitment process.Join our Talent CommunityStay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at .
Expected salary
Location
Toronto, ON
Job date
Mon, 09 Dec 2024 01:30:03 GMT
To help us track our recruitment effort, please indicate in your email/cover letter where (un-jobs.net) you saw this job posting.