Job Description

Introduction

We are looking for a passionate and detail-oriented Junior API Security Consultant to join our cybersecurity team. This role is ideal for someone with foundational experience in API development or security and a strong interest in securing modern applications. You will support senior consultants in assessing and improving API security, including hands-on testing and secure design practices.

Your Role And Responsibilities

  • Assist in conducting Vulnerability Assessment and Penetration Testing (VAPT) on APIs using industry-standard tools.
  • Support Static Application Security Testing (SAST) efforts to identify insecure coding patterns in API source code.
  • Help review API specifications (OpenAPI/Swagger) for potential security gaps.
  • Collaborate with development teams to implement secure API design and coding practices.
  • Participate in the integration of security controls into CI/CD pipelines.
  • Document findings, remediation steps, and best practices for internal and client use.
  • Stay updated on API security trends, tools, and vulnerabilities.

Preferred Education

Bachelors Degree

Experience

Required technical and professional expertise

  • 1–3 years of experience in application development, cybersecurity, or API support.
  • Basic understanding of RESTful and GraphQL APIs, including authentication methods (OAuth2, JWT).
  • Exposure to VAPT tools such as Burp Suite, OWASP ZAP, Postman, or similar.
  • Familiarity with SAST tools like SonarQube, Checkmarx, Fortify or equivalent.
  • Awareness of OWASP API Security Top 10 and secure coding principles.
  • Basic scripting or programming skills (e.g., Python, JavaScript).
  • Exposure to cloud platforms (AWS, Azure, GCP) and API gateways.
  • Understanding of DevSecOps concepts and CI/CD integration.

Soft Skills

  • Strong analytical and problem-solving abilities with keen attention to detail.

Preferred Certifications

Preferred technical and professional experience

  • API Security Fundamentals (Cloud Academy, Salt Security, etc.)
  • CompTIA Security+, CySA+, or equivalent
  • Familiarity with MITRE ATT&CK for APIs or OWASP API Security


Job Details

Role Level: Mid-Level Work Type: Full-Time
Country: Philippines City: Taguig National Capital Region
Company Website: http://www.ibm.com Job Function: Cybersecurity
Company Industry/
Sector:
IT Services and IT Consulting

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


Recent Jobs
View More Jobs
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn