Open role
API Security Engineer
IQ Staffing B.V.
About the role
API Security Engineer
An opportunity for an experienced API Security Engineer to join a central security platform team within a leading financial institution in Amsterdam.
In this role, you will play a key part in strengthening the organisation’s digital resilience by securing the APIs that support customer, partner, and internal ecosystems. You will help shape and implement API security standards, platform policies, automated controls, and governance across a complex enterprise environment.
You will work closely with engineers, architects, platform teams, and security specialists to ensure APIs are secure, compliant, and resilient against evolving cyber threats. This is a hands-on position for someone who combines strong technical expertise with a pragmatic and proactive approach.
What you'll do
Translate API security standards, controls, and best practices into practical platform policies and automated guardrails.
Configure, manage, and optimise API security tooling and platform capabilities.
Assess API security findings and determine their severity, criticality, and potential business impact.
Translate identified vulnerabilities and risks into improved security policies, business rules, and remediation actions.
Support the implementation of authentication, authorisation, and access-control mechanisms across API environments.
Collaborate with engineers and architects to embed security throughout the API lifecycle.
Ensure APIs comply with internal security requirements and recognised security frameworks.
Contribute to the further development of API security governance, standards, and strategy.
Proactively identify security improvements and take ownership of their implementation.
What you'll bring
Proven experience managing API security products such as Akamai API Security, Noname Security, Salt Security, Cequence, or similar solutions.
Strong knowledge of cybersecurity principles, security architecture, cloud security, and application security architecture.
Deep expertise in API and application security.
Strong understanding of frameworks and standards such as OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and CVE.
Advanced knowledge of authentication and authorisation mechanisms, including:
OAuth 2.0
OpenID Connect
JWT
mTLS
Session management
Object-level authorisation
Attribute-level authorisation
Experience assessing API security vulnerabilities and translating findings into actionable improvements.
Ability to convert complex security requirements into scalable policies, controls, and automated business rules.
Strong analytical and problem-solving skills.
Excellent communication and stakeholder-management abilities.
A proactive mindset with a strong sense of ownership.
What's on offer
Location: Amsterdam
Salary: Competitive
Contract: 12 months (with extension likely)
Hybrid working model
Approximately 60–80% remote working
Approximately 20–40% office-based working