- Provide integration security expertise across triage, risk assessment, control design and development support.
- Support and guide developers building integrations (e.g. MuleSoft, APIs) to do so securely, embedding security by design throughout.
- Review integration designs, API specifications, interface contracts and data-flow diagrams for security risks.
- Assess API controls such as input validation, schema validation, rate limiting, error handling and protection against misuse.
- Provide practical security guidance on API security including OAuth2, OpenID Connect, mTLS, gateway policies, service identities, REST and SOAP services, messaging, event driven integrations and API governance.
- Assess and secure integration patterns and data flows between systems.
- Review the security of trust boundaries, network connections and data transfers between systems and environments.
- Review the handling of credentials, certificates, tokens, keys and other secrets.
- Work closely with the security architects to translate design intent into secure, practical engineering outcomes.
- Support the secure configuration of integration platforms, deployment pipelines and automated testing.
- Help teams identify and remediate security weaknesses in integration code, configuration and reusable components.