← Security Engineering & Assurance

Security Engineering & Assurance

API Security Engineer

Not accepting applications
Remote Remote-friendly 정규직 Access tier: T3
Background screening required Professional credentials required

About Sequester

Sequester is a privacy-first encrypted vault for personal photos and videos. We build software where security, reliability, and user trust are product features???not afterthoughts.

About this role

You will secure Sequester's outward-facing APIs???auth flows, upload endpoints, webhooks???against abuse, injection, and broken access control at scale.

What you will do

  • Review and test API designs for authN/authZ gaps and mass-assignment risks
  • Implement or recommend WAF rules, rate limits, and bot detection for public routes
  • Run regular authenticated and unauthenticated API fuzzing in staging
  • Partner with backend teams on OAuth/session hardening and audit logging
  • Track API security findings to closure with release-blocking policy for criticals

What we are looking for

  • API security specialization with Burp, Postman collections, or custom fuzzers
  • Deep understanding of OWASP API Security Top 10
  • Experience securing high-volume media upload endpoints is a plus
  • Clear communication with backend engineers who own the fixes

Location

Remote-friendly. We hire globally and collaborate async-first across time zones.

Not currently accepting applications

This role page remains available for reference, but we are not accepting new applications right now. Check back later or browse other openings. 채용 공고 보기