Cloud and Web API Security Engineer
Newark, CA
Full Time Entry-level / Junior USD 145K - 200K
Lucid Motors
Lucid is the future of sustainable mobility, designing electric cars that further reimagines the driving experience.We are seeking a skilled and motivated Security Engineer to join our team. The ideal candidate will have experience in API security assessments and possess a basic understanding of various technologies such as Kubernetes, Docker, Istio, gPRC, REST, MTLS, Web Application Security, Source Code Review, SAST / DAST. This is an excellent opportunity for a junior to mid-level professional looking to develop their expertise in API security and contribute to the security posture of our organization.
Responsibilities:
- Conduct security assessments of APIs to identify potential vulnerabilities, weaknesses, and risks.
- Collaborate with development teams to provide guidance on implementing secure API architectures.
- Perform code reviews and provide recommendations for secure coding practices.
- Assist in the development and maintenance of security testing methodologies, tools, and frameworks for API security assessments.
- Stay updated with the latest security threats, vulnerabilities, and industry best practices related to API security.
- Create and maintain documentation of security assessment findings, recommendations, and mitigation strategies.
- Collaborate with cross-functional teams to remediate identified vulnerabilities and ensure the security of APIs.
- Participate in the design and implementation of secure API authentication and authorization mechanisms.
- Contribute to training and workshops for development teams on API security best practices.
Requirements:
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
- Experience or strong interest in API security assessments and vulnerability management.
- Basic understanding of API security best practices and standards (e.g., OWASP API Security Top 10).
- Knowledge of authentication and authorization protocols (e.g., OAuth, JWT) is a plus.
- Familiarity with security assessment tools such as Burp Suite, OWASP ZAP, or similar is a plus.
- Basic understanding of secure coding practices and common vulnerabilities in web applications and APIs.
- Strong problem-solving and analytical skills.
- Excellent written and verbal communication skills.
- Ability to work independently and collaboratively in a fast-paced environment.
- Relevant certifications such as OffSec Web Assessor (OSWA) or OSCP are a plus.
Join our team and contribute to ensuring the security and integrity of our APIs as we strive to deliver secure and reliable services to our customers. Apply now and be part of our mission to protect sensitive data and maintain the highest standards of API security.
Salary Range: The compensation range for this position is specific to the locations listed below and is the range Lucid reasonably and in good faith expects to pay for the position taking into account the wide variety of factors that are considered in making compensation decisions, including job-related knowledge; skillset; experience, education and training; certifications; and other relevant business and organizational factors. Additional Compensation and Benefits: Lucid offers a wide range of competitive benefits, including medical, dental, vision, life insurance, disability insurance, vacation, and 401k. The successful candidate may also be eligible to participate in Lucid’s equity program and/or a discretionary annual incentive program, subject to the rules governing such programs. (Cash or equity incentive awards, if any, will depend on various factors, including, without limitation, individual and company performance.)Base Pay Range (Annual)$145,600—$200,200 USDBy Submitting your application, you understand and agree that your personal data will be processed in accordance with our Candidate Privacy Notice. If you are a California resident, please refer to our California Candidate Privacy Notice.
To all recruitment agencies: Lucid Motors does not accept agency resumes. Please do not forward resumes to our careers alias or other Lucid Motors employees. Lucid Motors is not responsible for any fees related to unsolicited resumes.Tags: APIs Application security Burp Suite Cloud Computer Science DAST Docker Kubernetes Offensive security OSCP OWASP Privacy SAST Security assessment Vulnerabilities Vulnerability management
Perks/benefits: 401(k) matching Career development Competitive pay Equity / stock options Health care Insurance
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.