API Business Security Analyst

5 - 8 years

7 - 11 Lacs

Posted:-1 days ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

  • Collaborate with product owners, architects, and business stakeholders to define and document business requirements related to secret management, identity, and access control.
  • Conduct interviews and workshops to gather and clarify security-related business requirements for our applications and APIs.
  • Work with technical teams to design and implement API security policies and access models within HashiCorp Vault.
  • Translate business needs into actionable API specifications, including authentication methods (e.g., JWT, OAuth), request-response formats, and policy-based authorization.
  • Create detailed API documentation, security policies, and procedural guides for developers and other internal teams.
  • Develop and deliver training to internal teams on Vault integration and API security best practices. Conduct API security assessments, penetration testing, and remediation planning.
  • Ensure data handling for API interactions.
  • Ensure that HashiCorp Vault configurations and API security measures follow regulatory and compliance standards (e.g., ISO 27001, PCI-DSS).
  • Support internal and external audits by generating reports from Vaults audit logs and providing documentation of security controls.
The Essentials - You Will Have:
  • Bachelors / Masters Degree in computer science, software engineering, management information systems, or related field or equivalent relevant years of experience.
The Preferred - You Might Also Have:
  • Requires minimum 5-8 years of experience in Cyber Security, API Security & Vault Management.
  • Experience with secrets management solutions (e.g., HashiCorp Vault, CyberArk Conjur).
  • Working knowledge of HashiCorp Vault and its components, including secret engines (KV, PKI, Transit), auth methods, and policies.
  • Experience defining security for REST APIs, including knowledge of JSON, API security best practices, and authentication protocols (OAuth, JWT).
  • Experience with API testing tools such as Postman or SoapUI.
  • Familiarity with modern software development methodologies (Agile, Scrum) and DevOps practices.
  • Ability to translate complex business needs into clear, actionable technical requirements.
  • Proficiency with visualisation and documentation tools (e.g., Visio, Confluence, or JIRA).
  • Familiarity with configuration management and automation tools (e.g., SALT, Ansible, or Terraform).
  • Experience with OAuth2, OpenID Connect, JWT, and API gateway security patterns.
  • Good exposure with cloud-native environments (AWS, Azure, or GCP).

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Lektronix logo
Lektronix

Automation Machinery Manufacturing

West Midlands Newry

RecommendedJobs for You

hyderabad, pune, bengaluru