Senior Cybersecurity Engineer (api Security & Platform)

Visa Visa · Fintech · Brazil · Remote

Senior Cybersecurity Engineer focused on Identity Engineering, designing, building, and operating secure identity and authorization foundations for financial workloads. The role involves securing API Gateway platforms (Kong), implementing authentication/authorization patterns (OAuth 2.0, OpenID Connect), securing Kubernetes, and using Infrastructure as Code (Terraform).

What you'd actually do

  1. Designing, implementing, and operating identity and authorization platforms used across internal and external services
  2. Defining and evolving authentication and authorization patterns based on OAuth 2.0, OpenID Connect, and token-based security
  3. Supporting and improving API security using API Gateway technologies, preferably Kong, including authentication flows, rate limiting, and policy enforcement
  4. Collaborating with engineering teams to securely integrate identity solutions into APIs and services
  5. Building and maintaining infrastructure using Infrastructure as Code (Terraform)

Skills

Required

  • 5 or more years of relevant work experience with a Bachelor's Degree or at least 2 years of work experience with an Advanced degree
  • Securing API Gateway platforms
  • Kong Gateway
  • Identity and service-to-service security
  • mTLS-based communication
  • Certificate lifecycle management
  • Public Key Infrastructure (PKI)
  • API security controls (OAuth2, OpenID Connect, JWT validation, client credentials, rate limiting, traffic filtering, abuse prevention)
  • Securing Kubernetes-based platforms
  • Infrastructure as Code (IaC)
  • Terraform
  • Security assessments, threat modeling, and architectural reviews
  • Observability and security monitoring for gateways and identity services
  • Communication skills

Nice to have

  • Programming experience

What the JD emphasized

  • API Gateway platforms
  • Kong Gateway
  • Identity and service‑to‑service security
  • mTLS‑based communication
  • Public Key Infrastructure (PKI)
  • API security controls
  • Kubernetes‑based platforms
  • Infrastructure as Code (IaC)
  • Terraform
  • security assessments, threat modeling, and architectural reviews
  • observability and security monitoring
  • high‑traffic, multi‑environment, and multi‑region platforms
  • clearly communicate security risks
  • lead and influence cross‑functional teams