Haystack
← Back to Jobs
Other

API Governance Framework SME/Lead

SysMind, LLCAtlanta, GA🇺🇸United StatesPosted 29 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

 


Job Description - API Governance Framework SME/Lead
Location: Atlanta, GA - Hybrid


Competencies: 6-8+ years’ experience required
Digital : DevOps
Cyber Security



Set up Governance Framework

Ø Policy review and alignment with IHG security standards
Ø Identification and documentation of APIs for deprecation or retirement
Ø Definition and implementation of approval workflows for API security governance
decisions
Ø Creation and maintenance of compliance documentation and evidence artifacts
Ø Periodic audits, gap analysis, and roadmap creation
Ø Setup joint governance forums (leverage existing forums if applicable), escalation
paths, and decision-tracking mechanisms
********


Job Summary:
The API Governance Framework Lead is responsible for establishing, implementing, and managing the organization's API Governance Framework to ensure secure, scalable, compliant, and reusable APIs across the enterprise. This role will define governance policies, standards, best practices, and controls covering API lifecycle management, security, compliance, architecture, documentation, monitoring, and operational excellence.
The individual will work closely with Enterprise Architecture, Cyber Security, Application Development, DevOps, Cloud Engineering, Data Management, and Business stakeholders to drive API standardization and enable secure digital transformation initiatives.

Key Responsibilities
API Governance Strategy
• Design and maintain the enterprise-wide API Governance Framework.
• Establish API policies, standards, principles, and operating procedures.
• Define API maturity models and governance KPIs.
• Develop API lifecycle management standards covering design, development, testing, deployment, monitoring, and retirement.
• Drive API-first architecture adoption across business and technology teams.

API Architecture & Design Governance
• Define API design standards and conventions.
• Govern REST, GraphQL, SOAP, and event-driven API architectures.
• Review and approve API specifications and architecture designs.
• Ensure consistency in versioning, naming standards, metadata, and documentation.
• Promote API reuse and discoverability across the organization.

Security & Compliance
• Develop API security standards aligned with industry frameworks.
• Ensure implementation of:
o OAuth 2.0
o OpenID Connect (OIDC)
o JWT
o mTLS
o API Gateway controls
o Rate limiting
o Threat protection mechanisms
• Conduct API security reviews and risk assessments.
• Ensure compliance with regulatory and organizational requirements.
• Collaborate with Cyber Security teams to mitigate API-related risks and vulnerabilities.

API Lifecycle Management
• Implement governance controls throughout the API lifecycle.
• Establish API onboarding and approval workflows.
• Manage API inventory, cataloging, and service registry.
• Oversee API version management and deprecation processes.
• Ensure APIs are adequately documented and maintained.
Stakeholder Management
• Collaborate with business units to understand API consumption needs.
• Partner with Architecture and Engineering teams to enforce governance standards.
• Conduct governance reviews and reporting with leadership.
• Lead API governance forums and review boards.

Required Qualifications
Education
• Bachelor’s degree in computer science, Information Technology, Engineering, or related field.
• Master's degree preferred.

Experience
• 8–15 years of IT experience.
• Minimum 8 years of experience in API Management, Enterprise Architecture, Cloud Architecture, or API Governance.
• Experience implementing API governance programs in large enterprises.
• Experience with API security frameworks and controls.
• Experience working in Agile and DevSecOps environments.

Technical Skills:
API Technologies
• REST APIs
• GraphQL
• SOAP Services
• Event-Driven Architecture
• OpenAPI/Swagger
• AsyncAPI
Security
• OAuth 2.0
• OpenID Connect
• JWT
• mTLS
• API Threat Protection
• OWASP API Security Top 10
• Zero Trust Architecture
API Management Tools
• Azure API Management
• Apigee
• MuleSoft
• Akamai Noname
• AWS API Gateway

Resource should have below exactly:

Set up Governance Framework
Ø Policy review and alignment with IHG security standards
Ø Identification and documentation of APIs for deprecation or retirement
Ø Definition and implementation of approval workflows for API security governance
decisions
Ø Creation and maintenance of compliance documentation and evidence artifacts
Ø Periodic audits, gap analysis, and roadmap creation
Ø Setup joint governance forums (leverage existing forums if applicable), escalation
paths, and decision-tracking mechanisms


 

Thanks, and Regards

Govind Gupta

Sr Technical Acquisition Specialist

Office: EXT: 2208
Direct Number:
Email:


SYSMIND LLC is an Equal Employment Opportunity employer. All qualified applicants will receive consideration for employment without any discrimination. We promote and support a diverse workforce at all levels in the company. All job offers are contingent upon completion of a satisfactory background check and reference checks. Additionally passing the drug test may also be required. All contractors intending to work on SYSMIND's W2 are "at will" employees.

Skills

SOAP
API Gateway
AWS
OAuth
OWASP
Agile
Azure
Compliance
GraphQL
JWT
Onboarding
REST
Stakeholder Management
Zero Trust

Similar jobs