Associate Software Engineer (Hyderabad)

Associate Software Engineer (Hyderabad)

21 Aug
|
Cbre
|
Hyderabad

21 Aug

Cbre

Hyderabad

Cybersecurity Engineer

API Security

Job Summary

Themission of the individual in this role is to leverage their understanding ofenterprise security practices to help mitigate cybersecurity risk. They willwork with the CBRE business, Digital and Technology, and other partnerorganizations (Compliance, Risk Mgmt., Audit, and Legal) to integrate securityprocesses, tools, and people into the business culture, contributing to aholistic security ecosystem and supporting continuous improvements inprotection and monitoring capabilities globally. Executes on assignedinitiatives and contributes to problem resolution as part of a collaborativesecurity team.

Experiencein all skills listed is not necessary to be qualified for the position. If youhave relevant similar experience, we still want to talk to you.

Essential Duties And Responsibilities

- Implementand maintain security controls for API environments, including REST, GraphQL,gRPC, and event-driven interfaces across cloud and hybrid deployments
- ConductAPI security assessments, threat modeling, and attack surface analysis,covering authentication gaps, injection risk, excessive data exposure, andbroken authorization patterns
- Supportthe implementation of API authentication and authorization standards, includingOAuth 2.0, OIDC, mTLS, and API key lifecycle management
- Configureand maintain API gateway security policies covering rate limiting, inputvalidation, payload inspection, anomaly detection, and traffic routing controls
- Supportsecurity design reviews and operational controls for Model Context Protocol(MCP) server implementations, addressing tool permission scoping, promptinjection risk, Sampling and Elicitation primitive controls, and agenticworkflow safeguards
- IntegrateAPI and MCP security scanning into CI/CD pipelines for shift-left discovery ofsecrets, authentication gaps, and insecure API patterns
- Contributeto API security governance documentation, gate compliance checklists, andsecurity design patterns aligned to enterprise control frameworks
- Collaboratewith development and platform teams to operationalize secure API designpatterns and drive resolution of security findings
- MonitorAPI runtime behavior for anomalies, abuse patterns, unauthorized access, and AIagent tool-use irregularities using SIEM and API observability tooling
- Supportthird-party API and MCP server assessment workflows,



including intakeevaluation, risk classification, and approval routing
- Participatein incident response activities related to API abuse, data exposure via APIendpoints, and agentic AI tool misuse scenarios
- Shareknowledge with engineering teams on API security best practices, OWASP APISecurity Top 10, and secure development patterns for both human-facing andagent-facing interfaces
- Developreporting on operational metrics and product performance
- Participatein on-call rotation for ensuring uptime and functionality of critical internalcustomer services
- Otherduties as assigned

Supervisory Responsibilities Noformal supervisory responsibilities. Contributes to team knowledge sharing andpeer development.

EDUCATION And EXPERIENCE

Bachelor'sdegree (BA/BS) in a related field of work plus a minimum of 2 years relatedwork experience; or equivalent combination of education and experience(equivalent work experience = 2 years of related experience for every year ofhigher level education).

- Intermediateexperience with API security assessment and testing across REST, GraphQL, gRPC,and event-driven API architectures, including familiarity with OWASP APISecurity Top 10
- Intermediateexperience with API gateway platforms; experience with tools like WSO2, Kong,Apigee, AWS API Gateway, or Azure API Management, including policyconfiguration for authentication, rate limiting, and traffic inspection

- Workingknowledge of API security testing and scanning tools; familiarity with BurpSuite, OWASP ZAP, Postman, or 42Crunch for API-specific vulnerability discoveryand spec validation
- Workingknowledge of API discovery and runtime security observability; familiarity withtools like Traceable AI, Salt Security, or Noname Security for continuous APIinventory, risk scoring, and behavioral monitoring
- Workingknowledge of secrets management and credential lifecycle management for API andservice identities; familiarity with tools such as HashiCorp Vault,



CyberArk,or cloud-native secrets managers (AWS Secrets Manager, Azure Key Vault)
- Workingknowledge of SAST, DAST, and software composition analysis integrated intoCI/CD pipelines; familiarity with tools like Checkmarx, Veracode, Semgrep, orSnyk
- Foundationalawareness of the Model Context Protocol (MCP) specification, including itstwo-layer architecture and the security implications of agentic AI tool-usepatterns
- Workingknowledge of cloud provider API and security services across one or more ofAWS, Azure, or GCP
- Foundationalexperience writing and running infrastructure as code; familiarity with toolslike Terraform
- FoundationalLinux systems administration experience or equivalent skills
- Workingknowledge of DevOps and CI/CD pipelines; familiarity with tools like GitHubActions, GitLab CI, or Jenkins
- Workingknowledge of automating security workflows using Python or another scriptinglanguage
- Foundationalunderstanding of source control management and practices using Git and GitHub

OTHER SKILLS And/or ABILITIES

- Experiencewith the Microsoft ecosystem
- Familiaritywith directory services including Active Directory and LDAP, with understandingof OAuth/OIDC integration patterns for API authorization
- Familiaritywith API specification formats including OpenAPI/Swagger and AsyncAPI
- Awarenessof microservice and service mesh architectures and their security implications,including mTLS, service-to-service authentication, and sidecar proxy patterns
- Awarenessof zero trust principles as applied to API and service authentication acrosscloud and hybrid environments
- Familiaritywith NIST SP 800-204 (security guidance for microservices-based applicationsystems) and related frameworks

Communication Skills Strongwritten and verbal communication skills with the ability to explain API andsecurity concepts clearly across technical teams. Able to contribute tostandards documentation, author technical reports, and collaborate effectivelyacross engineering, operations, and compliance teams.

REASONING ABILITY

Analyticalproblem-solving skills with experience addressing API security challengesacross heterogeneous environments. Able to evaluate technical approaches, applyrisk-based reasoning, and contribute to strategies that measurably reduce APIattack surface and improve enterprise security posture.

📌 Associate Software Engineer (Hyderabad)
🏢 Cbre
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: associate software engineer (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: associate software engineer (hyderabad) / hyderabad