JOBSEARCHER

Senior Backend/API Security Developer

Ust GlobalEvanston, ILL6 LeadSeptember 15th, 2026
Overview As a Senior Backend/API Security Developer, you design secure, scalable APIs and lead API security practices for enterprise-grade systems on AWS. You will work within a cross-functional team to implement authentication, encryption, and compliance controls, driving secure architecture patterns and threat mitigation. The role combines hands-on engineering with leadership to build a world-class API security program. You will engage with DevOps on CI/CD and collaborate to secure sensitive data and regulatory obligations. Compensation / Benefitsvacation dayspaid sick leavepaid holidays401(k) with employer matchingmedical/dental/vision insuranceHSA and FSA options ResponsibilitiesDesign secure architectures for RESTful and GraphQL APIs using AWS services (API Gateway, Lambda, VPC) with least privilegeImplement robust authentication using OAuth 2.0, OpenID Connect, AWS IAM, and Amazon CognitoMaintain data protection and regulatory compliance (HIPAA, GDPR, PCI-DSS) with masking, tokenization, and auditingEnsure encryption in transit (TLS 1.3) and at rest (AWS KMS with customer-managed keys)Conduct security audits and testing (automated scans, static code analysis, vulnerability assessments) using tools like Amazon Inspector and AWS Security HubApply rate limiting and WAF protections (AWS WAF, API Gateway throttling) to defend against attacksEstablish centralized logging and threat detection (CloudWatch, CloudTrail, GuardDuty) for complete audit trailsCollaborate with DevOps to design and implement a CI/CD pipeline using CodePipeline Key requirementsProficiency in Python, Node.js, or JavaExperience with cloud-native development and large-scale microservicesStrong knowledge of OWASP API Security standardsExperience with OAuth 2.0/OIDCProficiency in AWS (services like API Gateway, Lambda, IAM, Cognito, Inspector, Security Hub, WAF, KMS, CloudWatch, CloudTrail, GuardDuty)PostgreSQLAbility to lead and drive API security standards as a technical leaderleadershipcross-functional collaborationstrong communicationAWSOAuth 2.0/OIDCNode.js