Description
The role focuses on securing APIs by hunting business logic vulnerabilities, validating OAuth2, OIDC, and JWT implementations, automating API-gateway attacks, hardening Kong or Azure API Gateway, and designing authentication, authorization, SSO, MFA, and partner-integration security patterns. It requires Python scripting, REST and GraphQL security knowledge, OAuth 2.0 and OpenID Connect expertise, and experience with Postman, Burp Suite, and 42Crunch.
