Apigee Platform Buildout & Operations Security Architect
Indexed description
Apigee Platform Buildout & Operations Security Architect
Location: Hybrid – 3 days/week onsite. Candidates need to be located in/near San Antonio, TX, Jacksonville, FL, or Alpharetta, GA
First week Expectations: First week onsite Monday-Friday with a team member
Travel: Possibility for limited travel to a Client site (10%)
Role requires: US citizenship or Green Card status
Contract dates: 9/1/26-8/31/27
We are seeking an experienced Apigee Platform Buildout & Operations Security Architect with 10+ years of experience designing, implementing, and operationalizing security for enterprise API management platforms. This role will lead the end-to-end security architecture for the Apigee platform, including API security, IAM, network security, data protection, DevSecOps integration, compliance alignment, security operations, and migration of legacy IBM DataPower security controls into a modern Apigee architecture.
Responsibilities
- Define and implement enterprise API security architecture for Google Apigee, including OAuth 2.0, OpenID Connect, JWT validation, mTLS, API threat protection, policy enforcement, and reusable security patterns.
- Lead security strategy and control mapping for IBM DataPower and API Connect migrations, identifying legacy security controls and designing secure target-state solutions within Apigee.
- Design secure network, connectivity, and traffic protection architectures, including private connectivity, segmentation, TLS/mTLS communications, WAF integration, firewall policies, and zero-trust principles.
- Establish IAM, privileged access, RBAC, service account, and identity federation standards while integrating with enterprise identity providers and automation platforms.
- Partner with DevSecOps, cybersecurity, compliance, and operations teams to embed security controls into CI/CD pipelines, operational monitoring, audit readiness, incident response, and governance processes.
Qualifications
- 10+ years of experience in security architecture with significant expertise in enterprise API management platforms and Google Apigee (Apigee X, Hybrid, or equivalent).
- Deep knowledge of IBM DataPower and API Connect security patterns, including authentication, authorization, TLS/mTLS, certificate management, XML/SOAP security, GatewayScript, and backend security controls.
- Strong expertise in API security standards and technologies including OAuth 2.0, OpenID Connect, JWT, SAML, API keys, identity federation, token validation, and claims-based authorization.
- Experience with cloud security, IAM architecture, DevSecOps, CI/CD security integration, secrets management, SIEM integration, threat modeling, and security monitoring.
- Strong communication and documentation skills with the ability to develop architecture diagrams, threat models, security standards, control matrices, executive presentations, and audit artifacts.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search