Senior API Security Engineer

Kuala Lumpur Until 8/22/2026 First posted June 23, 2026 Last posted June 23, 2026
Job description

Key Responsibilities: 
● API Logic Security: Hunt for Business Logic vulnerabilities (BOLA/IDOR, Mass 
Assignment) that traditional firewalls miss. 
● Authentication & Authorization: Design and validate OAuth2, OIDC, and JWT 
implementations to ensure users can only access their own data. 
● Attack Simulation: Script automated attacks against the API Gateway to test rate limiting 
and fraud detection rules. 
● Gateway Hardening: Work with the Platform team to configure the API Gateway (Kong, 
or Azure API Gateway) for maximum security. 
● Auth & Partner Integration: Deliver new security design patterns and components for 
authentication, authorization, SSO, MFA, and Partner security. Standardize how we 
consume external APIs (Open Banking) and how we secure our own exposed endpoints. 

Technical Requirements: 
● Strong scripting skills (Python) to automate API attacks. 
● Expertise in REST and GraphQL security. 
● Deep knowledge of OAuth 2.0 and OpenID Connect (OIDC) flows. 
● Experience with API Security tools (Postman, Burp Suite, 42Crunch).

About this role

Summary

Design, implement, and test API security solutions, including OAuth, JWT, and attack scripting.

Job title

Senior API Security Engineer

Experience level

senior level

Industry

software

Location requirements

Kuala Lumpur-based, no remote work stated

Salary

Not specified

Management role

No

Skills & keywords

Required skills

Pythonrestgraphqloauth 2.0oidcattack scriptingapi security tools

Preferred skills

None specified

Specializations

API SecurityOAuth 2.0OIDCJWTrestgraphql
Locations

Structured locations inferred from the posting.

Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia

On-site City