Description Position Summary The API Standards & Compliance Lead is a senior governance and architecture role responsible for defining, implementing, and enforcing enterprise wide API governance frameworks.
This role ensures API consistency, security, scalability, and regulatory compliance across the organization while enabling an API first integration strategy.
This position focuses on policy, standards, operating models, and oversight rather than day to day software development.
The role partners closely with Enterprise Architecture, Platform Engineering, Security, Risk & Compliance, and Developer Experience teams to balance innovation with risk management.
What You'll Do API Governance Frameworks & Standards + Define and maintain enterprise wide API design standards aligned to OpenAPI, REST, and GraphQL best practices + Establish naming conventions, versioning guidelines, backward compatibility rules, and deprecation/retirement policies + Lead the API Governance Board, including reviews, approvals, waivers, and RACI ownership + Author and maintain reference architectures, governance playbooks, and reusable policy templates API Lifecycle Governance & Apigee X + Design and oversee API onboarding workflows through the Developer Portal, ensuring documentation, cataloging, and discoverability + Define governance processes integrated with Apigee X, including runtime policies such as quotas, rate limiting, and analytics + Ensure consistent use of API products, proxies, catalogs, and high quality API definitions to promote reuse Security & Regulatory Compliance + Implement and govern security patterns including OAuth2, JWT, JWKS, and mTLS using Apigee X and Ping Identity + Align APIs with regulatory requirements such as Open Banking, PSD2, HIPAA, and GDPR + Partner with Risk, Compliance, and Security Engineering to define control objectives, evidence, and auditability (NIST, ISO 27001, SOC 2) Developer Experience & Enablement + Collaborate with API Gateway and Developer Experience teams to improve portal usability, discoverability, and adoption + Provide guidance, training, and office hours on governance standards and best practices + Create reusable artifacts such as checklists, cheat sheets, OpenAPI samples, and policy catalogs Analytics, Metrics & Continuous Improvement + Define and track governance KPIs (compliance rates, time to approve, policy adoption, security defect trends) + Use Apigee Analytics and GCP monitoring to identify gaps and continuously refine standards + Conduct maturity assessments and publish governance roadmaps and quarterly updates Risk, Audit & Controls + Establish design time and runtime controls with clear audit evidence + Coordinate remediation plans for non compliant APIs and manage waivers with time bound conditions Tooling & Automation + Partner with platform teams to integrate policy as code, linting, contract validation, and authentication enforcement into CI/CD pipelines + Evaluate governance tooling to automate compliance and improve quality wherever possible Requirements Required Qualifications + 10+ years in IT with strong API development and/or governance experience + 5+ years in API governance, platform, or architecture leadership at enterprise scale + Deep expertise in OpenAPI/Swagger, REST fundamentals, and API lifecycle management + Hands on knowledge of OAuth2, JWT, JWKS, mTLS, and regulatory frameworks (Open Banking, PSD2, HIPAA, GDPR) + Experience with Apigee X (GCP) or comparable platforms (Kong, MuleSoft, AWS API Gateway, Azure APIM) from a governance/architecture perspective + Proven ability to write clear policies, standards, and procedures and to facilitate governance forums + Strong communication, stakeholder management, and change leadership skills Preferred Qualifications + GCP certifications (Professional Cloud Architect, Apigee certifications) + Experience integrating Ping Identity or enterprise IAM platforms + Familiarity with GCP services (Cloud Armor, IAM, VPC networking, security controls) + Background in DevSecOps, CI/CD automation, and policy as code + Experience improving API portals, catalogs, and developer experience using analytics Core Competencies + Strategic policy and standards design + Enterprise architecture alignment + Risk and compliance mindset + Stakeholder facilitation and influence + Data driven continuous improvement + Clear, concise technical writing and storytelling Role Clarity - What This Role Is / Is Not This role is: + A governance, standards, and architecture leadership role + Focused on policy enablement, oversight, and measurable outcomes This role is not: + A day to day software engineering position + A role focused on building Apigee proxies full time + A purely hands on development role (limited configuration may be required to validate controls or demonstrate patterns) Technology Doesn't Change the World, People Do.® Robert Half is the world's first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies.
We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Robert Half works to put you in the best position to succeed.
We provide access to top jobs, competitive compensation and benefits, and free online training.
Stay on top of every opportunity - whenever you choose - even on the go.
Download the Robert Half app ( and get 1-tap apply, notifications of AI-matched jobs, and much more.
All applicants applying for U.S.
job openings must be legally authorized to work in the United States.
Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance.
Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan.
Visit roberthalf.gobenefits.net for more information.
© 2025 Robert Half.
An Equal Opportunity Employer.
M/F/Disability/Veterans.