Core Fundamentals: Solid understanding of cryptographic primitives, API security at scale (OAuth 2.0 / OIDC, JWT pitfalls), and SaaS multi-tenancy data exposure risks. * Design Architecture: Review Architectural Decision Records (ADRs), API designs, and data flow diagrams before code gets written. API & Service Security * API Standards: Define and enforce standards for authentication (OAuth 2.0, mTLS), rate limiting, and schema validation across REST, GraphQL, and gRPC. * Gateway Hardening: Partner with the Cloud Security Engineer to harden API gateway configurations, request validations, and JWT validation rules.
more