API Developer
AI in this role
Job Description: API Developer
Our Team:
The API Developer designs, builds, and maintains the APIs that connect enterprise systems, digital products, and external partners. This is a hands-on engineering role responsible for producing well-designed, robust, scalable, secure, well-documented APIs that other teams can discover and reuse for communication between internal products, third-party platforms and client-facing applications.
The API platform is run both as an internal product and as a managed service. The API Developer works contract-first, publishing APIs to the enterprise catalogue and developer portal, and builds the reusable components, templates, and policies that raise the standard of every API delivered across the organisation.
Kong is the primary gateway, operating alongside Apigee, Azure API Management, and AWS API Gateway across a multi-cloud estate on Microsoft Azure and Amazon Web Services. The role therefore values transferable, gateway-agnostic API skills as highly as any single product.
Main responsibilities:
API Design and Development
- Design and build APIs contract-first using Open API/Swagger, applying enterprise design standards, naming conventions, and versioning policy.
- Develop synchronous and asynchronous APIs across REST, GraphQL, gRPC, and event-driven patterns documented with AsyncAPI.
- Build domain and experience APIs that expose business capabilities cleanly, abstracting the complexity of underlying systems.
- Develop reusable API components, policies, plugins, and templates that other teams consume as a starting point.
Gateway and Runtime Implementation
- Implement and configure API proxies, routes, plugins, and policies on Kong Gateway and Kong Konnect.
- Deploy and operate gateway components on Kubernetes using the Kong Ingress Controller and GitOps workflows.
- Implement traffic management including rate limiting, throttling, caching, retries, and circuit breaking.
Security and Access Control
- Implement robust authentication and authorization mechanisms (OAuth 2.0, OpenID Connect, JWT, mutual TLS, API keys patterns)
- Ensure APIs comply with regulatory and data privacy requirements (GDPR, GxP where applicable)
- Integrate with enterprise identity providers including Entra ID and Okta.
- Manage secrets and certificates through HashiCorp Vault, CyberArk, and cloud-native key services.
Quality, Testing, and Automation
- Build automated contract, functional, integration, security, and performance tests for every API.
- Maintain CI/CD pipelines for API delivery using GitHub Actions or Azure DevOps, including linting and specification validation.
- Integrate static analysis, dependency scanning, and SBOM generation using SonarQube, Snyk, and equivalent tooling.
Operations and Support
- Instrument APIs for observability using OpenTelemetry format.
- Contribute during incident response, root-cause analysis, and problem management for API services.
- Build proactive monitoring services relying on Predictive ML.
- Support consumers through onboarding, troubleshooting, and clear technical guidance.
Technical Craft and Engineering Practices
- Write clean, tested, peer-reviewed code managed in Git using trunk-based practices.
- Use AI-assisted engineering tools such as GitHub Copilot and Claude Code to accelerate development, test generation, and documentation, applying appropriate review and technical judgement.
- Favour reuse and shared components over bespoke, single-purpose implementations.
Collaboration and Ways of Working
- Work within an agile product team with a shared backlog and defined customers.
- Partner with integration engineers, application teams, and data teams to agree interfaces and contracts.
- Engage with Cybersecurity and Architecture teams to keep API patterns aligned with approved standards.
About you
Required
- Demonstrated capability in API or backend software engineering, typically gained across five to eight years of professional experience.
- Proficiency in at least one modern backend language: Python or Node.js and TypeScript are preferred, and Java with Spring Boot is equally welcome.
- Deep understanding of REST architectural principles and GraphQL query language
- Experience with relational and NoSQL databases and the ability to write optimized queries
- Strong contract-first API design experience with Open API, including versioning and backward compatibility.
- Hands-on experience with an API gateway or management platform such as Kong, Apigee, Azure API Management, or AWS API Gateway.
- Practical experience implementing OAuth2, OpenID Connect, and TLS-based API security.
- Working knowledge of containers, Kubernetes, and CI/CD pipelines.
- Sound debugging skills across application, network, and gateway layers.
- Clear written and verbal communication in English, including the ability to document APIs for other engineers.
Preferred
- Experience with GraphQL federation and gRPC or Protocol Buffers.
- Experience with Kafka, Solace, or another event streaming or brokering platform.
- Experience integrating enterprise systems such as SAP, Salesforce, Veeva, Workday, or ServiceNow.
- Experience with developer portals, API catalogues, or API productization for external partners.
- Experience delivering within a regulated environment (GxP or other), including awareness of data-protection obligations such as GDPR.
- Certifications such as Kong, AWS or Azure developer level, or Certified Kubernetes Application Developer.
- A bachelor's degree in computer science, engineering, information technology, or a related discipline.
Core Competencies
- Design-led thinking with strong attention to interface quality
- Consumer focus and empathy for the developers who use your APIs
- Security awareness embedded in everyday engineering decisions
- Bias toward reuse, standardization, and simplification
- Pragmatic problem-solving under production pressure
- Ownership and follow-through
- Continuous learning and adaptability
Measures of Success
- Increased reuse of published APIs and shared components
- Reduced lead time from API design to production availability
- Improved conformance to enterprise API design and security standards
- Complete, accurate, and current API documentation in the catalogue
- Improved API availability, latency, and error rates against service levels
- Faster consumer onboarding and reduced support effort per API
- Reduced number of undocumented, duplicate, or unmanaged endpoints
Pursue progress, discover extraordinary
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!
Pursue progress, discover extraordinary
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, ability or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!
How we score this
API Developer at Sanofi scores 23 out of 100 on AI centrality, which makes it AI Level 1 of 4 (Little AI) on this board. The level measures how much of the work is AI, not seniority.
AI Level 1. The work itself involves no AI, or AI only appears as scenery, such as a company tagline.
- AI Level 480 to 100
- AI Level 360 to 79
- AI Level 240 to 59
- AI Level 10 to 39
Bands come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- What's a project where you used Claude hands-on?
- Walk me through how you've used Copilot in your day-to-day work.
- What are the limits of Claude Code that you've run into, and how did you work around them?
Adapt your resume
- List these exact terms on your resume: Claude, Copilot, and Claude Code. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want your resume actually rewritten for this job?
The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.
Get new AI jobs by email
One email a week with the new AI jobs, each rated AI Level 1 to 4 for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles rated AI Level 1 at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step