Senior API Security Engineer
at Encora10
- Seniority
- Senior
- Location
- Kuala Lumpur
- Posted
- 5d ago
at Encora10
<p>Key Responsibilities: <br>● API Logic Security: Hunt for Business Logic vulnerabilities (BOLA/IDOR, Mass <br>Assignment) that traditional firewalls miss. <br>● Authentication & Authorization: Design and validate OAuth2, OIDC, and JWT <br>implementations to ensure users can only access their own data. <br>● Attack Simulation: Script automated attacks against the API Gateway to test rate limiting <br>and fraud detection rules. <br>● Gateway Hardening: Work with the Platform team to configure the API Gateway (Kong, <br>or Azure API Gateway) for maximum security. <br>● Auth & Partner Integration: Deliver new security design patterns and components for <br>authentication, authorization, SSO, MFA, and Partner security. Standardize how we <br>consume external APIs (Open Banking) and how we secure our own exposed endpoints. </p> <p>Technical Requirements: <br>● Strong scripting skills (Python) to automate API attacks. <br>● Expertise in REST and GraphQL security. <br>● Deep knowledge of OAuth 2.0 and OpenID Connect (OIDC) flows. <br>● Experience with API Security tools (Postman, Burp Suite, 42Crunch).</p>