Resume and JobRESUME AND JOB
IBM logo

API Security Analyst

IBM

Software and Technology Jobs

API Security Analyst

full-timePosted: Dec 12, 2025

Job Description

API Security Analyst

📋 Job Overview

The Junior API Security Consultant will join IBM's cybersecurity team to support senior consultants in assessing and improving API security. This role involves hands-on testing, secure design practices, and collaboration with development teams to implement security measures. Ideal candidates should have foundational experience in API development or security and a keen interest in securing modern applications.

📍 Location: Taguig City, PH (Remote/Hybrid)

💼 Career Level: Entry Level

🎯 Key Responsibilities

  • Assist in conducting Vulnerability Assessment and Penetration Testing (VAPT) on APIs using industry-standard tools
  • Support Static Application Security Testing (SAST) efforts to identify insecure coding patterns in API source code
  • Help review API specifications (OpenAPI/Swagger) for potential security gaps
  • Collaborate with development teams to implement secure API design and coding practices
  • Participate in the integration of security controls into CI/CD pipelines
  • Document findings, remediation steps, and best practices for internal and client use
  • Stay updated on API security trends, tools, and vulnerabilities

✅ Required Qualifications

  • 1–3 years of experience in application development, cybersecurity, or API support
  • Basic understanding of RESTful and GraphQL APIs, including authentication methods (OAuth2, JWT)
  • Exposure to VAPT tools such as Burp Suite, OWASP ZAP, Postman, or similar
  • Familiarity with SAST tools like SonarQube, Checkmarx, Fortify or equivalent
  • Awareness of OWASP API Security Top 10 and secure coding principles
  • Basic scripting or programming skills (e.g., Python, JavaScript)
  • Exposure to cloud platforms (AWS, Azure, GCP) and API gateways
  • Understanding of DevSecOps concepts and CI/CD integration
  • Strong analytical and problem-solving abilities with keen attention to detail

⭐ Preferred Qualifications

  • API Security Fundamentals (Cloud Academy, Salt Security, etc.)
  • Familiarity with MITRE ATT&CK for APIs or OWASP API Security

🛠️ Required Skills

  • Vulnerability Assessment and Penetration Testing (VAPT)
  • Static Application Security Testing (SAST)
  • API specifications (OpenAPI/Swagger)
  • Secure API design and coding practices
  • CI/CD pipelines
  • RESTful APIs
  • GraphQL APIs
  • OAuth2
  • JWT
  • Burp Suite
  • OWASP ZAP
  • Postman
  • SonarQube
  • Checkmarx
  • Fortify
  • OWASP API Security Top 10
  • Python
  • JavaScript
  • AWS
  • Azure
  • GCP
  • API gateways
  • DevSecOps
  • Analytical skills
  • Problem-solving
  • Attention to detail

🎁 Benefits & Perks

  • Opportunity to learn and develop career
  • Encouragement to be courageous and experiment daily
  • Continuous trust and support in an inclusive environment
  • Growth-minded culture with emphasis on curiosity and feedback
  • Collaboration with colleagues for exceptional customer outcomes
  • Opportunity to make critical decisions and embrace challenges
  • Being part of a responsible technology innovator and force for good
  • Equal-opportunity employment without discrimination

Locations

  • Taguig City, PH, India (Remote)

Salary

Estimated Salary Rangemedium confidence

600,000 - 1,200,000 INR / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Vulnerability Assessment and Penetration Testing (VAPT)intermediate
  • Static Application Security Testing (SAST)intermediate
  • API specifications (OpenAPI/Swagger)intermediate
  • Secure API design and coding practicesintermediate
  • CI/CD pipelinesintermediate
  • RESTful APIsintermediate
  • GraphQL APIsintermediate
  • OAuth2intermediate
  • JWTintermediate
  • Burp Suiteintermediate
  • OWASP ZAPintermediate
  • Postmanintermediate
  • SonarQubeintermediate
  • Checkmarxintermediate
  • Fortifyintermediate
  • OWASP API Security Top 10intermediate
  • Pythonintermediate
  • JavaScriptintermediate
  • AWSintermediate
  • Azureintermediate
  • GCPintermediate
  • API gatewaysintermediate
  • DevSecOpsintermediate
  • Analytical skillsintermediate
  • Problem-solvingintermediate
  • Attention to detailintermediate

Required Qualifications

  • 1–3 years of experience in application development, cybersecurity, or API support (experience)
  • Basic understanding of RESTful and GraphQL APIs, including authentication methods (OAuth2, JWT) (experience)
  • Exposure to VAPT tools such as Burp Suite, OWASP ZAP, Postman, or similar (experience)
  • Familiarity with SAST tools like SonarQube, Checkmarx, Fortify or equivalent (experience)
  • Awareness of OWASP API Security Top 10 and secure coding principles (experience)
  • Basic scripting or programming skills (e.g., Python, JavaScript) (experience)
  • Exposure to cloud platforms (AWS, Azure, GCP) and API gateways (experience)
  • Understanding of DevSecOps concepts and CI/CD integration (experience)
  • Strong analytical and problem-solving abilities with keen attention to detail (experience)

Preferred Qualifications

  • API Security Fundamentals (Cloud Academy, Salt Security, etc.) (experience)
  • Familiarity with MITRE ATT&CK for APIs or OWASP API Security (experience)

Responsibilities

  • Assist in conducting Vulnerability Assessment and Penetration Testing (VAPT) on APIs using industry-standard tools
  • Support Static Application Security Testing (SAST) efforts to identify insecure coding patterns in API source code
  • Help review API specifications (OpenAPI/Swagger) for potential security gaps
  • Collaborate with development teams to implement secure API design and coding practices
  • Participate in the integration of security controls into CI/CD pipelines
  • Document findings, remediation steps, and best practices for internal and client use
  • Stay updated on API security trends, tools, and vulnerabilities

Benefits

  • general: Opportunity to learn and develop career
  • general: Encouragement to be courageous and experiment daily
  • general: Continuous trust and support in an inclusive environment
  • general: Growth-minded culture with emphasis on curiosity and feedback
  • general: Collaboration with colleagues for exceptional customer outcomes
  • general: Opportunity to make critical decisions and embrace challenges
  • general: Being part of a responsible technology innovator and force for good
  • general: Equal-opportunity employment without discrimination

Target Your Resume for "API Security Analyst" , IBM

Get personalized recommendations to optimize your resume specifically for API Security Analyst. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "API Security Analyst" , IBM

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

ConsultingConsulting

Answer 10 quick questions to check your fit for API Security Analyst @ IBM.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.

IBM logo

API Security Analyst

IBM

Software and Technology Jobs

API Security Analyst

full-timePosted: Dec 12, 2025

Job Description

API Security Analyst

📋 Job Overview

The Junior API Security Consultant will join IBM's cybersecurity team to support senior consultants in assessing and improving API security. This role involves hands-on testing, secure design practices, and collaboration with development teams to implement security measures. Ideal candidates should have foundational experience in API development or security and a keen interest in securing modern applications.

📍 Location: Taguig City, PH (Remote/Hybrid)

💼 Career Level: Entry Level

🎯 Key Responsibilities

  • Assist in conducting Vulnerability Assessment and Penetration Testing (VAPT) on APIs using industry-standard tools
  • Support Static Application Security Testing (SAST) efforts to identify insecure coding patterns in API source code
  • Help review API specifications (OpenAPI/Swagger) for potential security gaps
  • Collaborate with development teams to implement secure API design and coding practices
  • Participate in the integration of security controls into CI/CD pipelines
  • Document findings, remediation steps, and best practices for internal and client use
  • Stay updated on API security trends, tools, and vulnerabilities

✅ Required Qualifications

  • 1–3 years of experience in application development, cybersecurity, or API support
  • Basic understanding of RESTful and GraphQL APIs, including authentication methods (OAuth2, JWT)
  • Exposure to VAPT tools such as Burp Suite, OWASP ZAP, Postman, or similar
  • Familiarity with SAST tools like SonarQube, Checkmarx, Fortify or equivalent
  • Awareness of OWASP API Security Top 10 and secure coding principles
  • Basic scripting or programming skills (e.g., Python, JavaScript)
  • Exposure to cloud platforms (AWS, Azure, GCP) and API gateways
  • Understanding of DevSecOps concepts and CI/CD integration
  • Strong analytical and problem-solving abilities with keen attention to detail

⭐ Preferred Qualifications

  • API Security Fundamentals (Cloud Academy, Salt Security, etc.)
  • Familiarity with MITRE ATT&CK for APIs or OWASP API Security

🛠️ Required Skills

  • Vulnerability Assessment and Penetration Testing (VAPT)
  • Static Application Security Testing (SAST)
  • API specifications (OpenAPI/Swagger)
  • Secure API design and coding practices
  • CI/CD pipelines
  • RESTful APIs
  • GraphQL APIs
  • OAuth2
  • JWT
  • Burp Suite
  • OWASP ZAP
  • Postman
  • SonarQube
  • Checkmarx
  • Fortify
  • OWASP API Security Top 10
  • Python
  • JavaScript
  • AWS
  • Azure
  • GCP
  • API gateways
  • DevSecOps
  • Analytical skills
  • Problem-solving
  • Attention to detail

🎁 Benefits & Perks

  • Opportunity to learn and develop career
  • Encouragement to be courageous and experiment daily
  • Continuous trust and support in an inclusive environment
  • Growth-minded culture with emphasis on curiosity and feedback
  • Collaboration with colleagues for exceptional customer outcomes
  • Opportunity to make critical decisions and embrace challenges
  • Being part of a responsible technology innovator and force for good
  • Equal-opportunity employment without discrimination

Locations

  • Taguig City, PH, India (Remote)

Salary

Estimated Salary Rangemedium confidence

600,000 - 1,200,000 INR / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Vulnerability Assessment and Penetration Testing (VAPT)intermediate
  • Static Application Security Testing (SAST)intermediate
  • API specifications (OpenAPI/Swagger)intermediate
  • Secure API design and coding practicesintermediate
  • CI/CD pipelinesintermediate
  • RESTful APIsintermediate
  • GraphQL APIsintermediate
  • OAuth2intermediate
  • JWTintermediate
  • Burp Suiteintermediate
  • OWASP ZAPintermediate
  • Postmanintermediate
  • SonarQubeintermediate
  • Checkmarxintermediate
  • Fortifyintermediate
  • OWASP API Security Top 10intermediate
  • Pythonintermediate
  • JavaScriptintermediate
  • AWSintermediate
  • Azureintermediate
  • GCPintermediate
  • API gatewaysintermediate
  • DevSecOpsintermediate
  • Analytical skillsintermediate
  • Problem-solvingintermediate
  • Attention to detailintermediate

Required Qualifications

  • 1–3 years of experience in application development, cybersecurity, or API support (experience)
  • Basic understanding of RESTful and GraphQL APIs, including authentication methods (OAuth2, JWT) (experience)
  • Exposure to VAPT tools such as Burp Suite, OWASP ZAP, Postman, or similar (experience)
  • Familiarity with SAST tools like SonarQube, Checkmarx, Fortify or equivalent (experience)
  • Awareness of OWASP API Security Top 10 and secure coding principles (experience)
  • Basic scripting or programming skills (e.g., Python, JavaScript) (experience)
  • Exposure to cloud platforms (AWS, Azure, GCP) and API gateways (experience)
  • Understanding of DevSecOps concepts and CI/CD integration (experience)
  • Strong analytical and problem-solving abilities with keen attention to detail (experience)

Preferred Qualifications

  • API Security Fundamentals (Cloud Academy, Salt Security, etc.) (experience)
  • Familiarity with MITRE ATT&CK for APIs or OWASP API Security (experience)

Responsibilities

  • Assist in conducting Vulnerability Assessment and Penetration Testing (VAPT) on APIs using industry-standard tools
  • Support Static Application Security Testing (SAST) efforts to identify insecure coding patterns in API source code
  • Help review API specifications (OpenAPI/Swagger) for potential security gaps
  • Collaborate with development teams to implement secure API design and coding practices
  • Participate in the integration of security controls into CI/CD pipelines
  • Document findings, remediation steps, and best practices for internal and client use
  • Stay updated on API security trends, tools, and vulnerabilities

Benefits

  • general: Opportunity to learn and develop career
  • general: Encouragement to be courageous and experiment daily
  • general: Continuous trust and support in an inclusive environment
  • general: Growth-minded culture with emphasis on curiosity and feedback
  • general: Collaboration with colleagues for exceptional customer outcomes
  • general: Opportunity to make critical decisions and embrace challenges
  • general: Being part of a responsible technology innovator and force for good
  • general: Equal-opportunity employment without discrimination

Target Your Resume for "API Security Analyst" , IBM

Get personalized recommendations to optimize your resume specifically for API Security Analyst. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "API Security Analyst" , IBM

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

ConsultingConsulting

Answer 10 quick questions to check your fit for API Security Analyst @ IBM.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.