Confidential mandate

API Abuse Defence Leader — Mobility Super-App

Urgent / Unplanned

API Abuse Defence Leader mandate in Mexico City, Mexico · Mobility Platforms

Following coordinated partner-token abuse, a mobility platform needs executive API defence leadership to restore ecosystem trust, contain automated exploitation and hand over durable controls within seven months.

The mandate

Attackers used leaked partner tokens, device farms and low-rate automation to enumerate accounts and manipulate promotions without triggering volumetric controls. Requests rotated through valid partners, copied mobile journey timing and combined individually low-value actions into material campaign gain. The platform-security director left after containment disabled legitimate integrations across two markets and the business could not explain which defensive rule caused each failure.

The interim starts within two weeks for seven fixed months across Mexico City, Bogotá and Miami. Daily abuse decisions continue through credential rotation and move to weekly platform governance once priority journeys stabilise. Permanent recruitment begins after partner trust is rebuilt and one simulated campaign passes; four weeks of overlap follow, with no extension for delayed integration repair or search.

Handover requires inventoried APIs, rotated partner identity, behaviour-based abuse controls, governed exceptions, restored partner service and a successor-led attack simulation. Critical operations must have resource-value limits and accountable owners, leaked-token drills must trigger containment within threshold, and false-positive effects must remain visible by partner, market and customer journey.

The leader may revoke tokens, throttle endpoints, suspend integrations and reprioritise defence engineering within the approved MXN 45 million recovery envelope. The leader can require a partner to re-attest its application before restoring scope. Market shutdown, customer redress, permanent hiring and partner termination require executive approval, with product owners accountable for documented availability trade-offs.

Consumer pricing, generic application modernisation and payment fraud outside API pathways are excluded. Bot tooling and gateway replacement enter only where necessary to enforce agreed controls, while their broader roadmaps remain with platform engineering. The seat owns automated and partner-mediated abuse containment rather than every fraud or application-security concern.

Why this seat is open

The campaign operated below infrastructure thresholds and across organisational owners. Initial containment caused disproportionate customer and partner disruption. Temporary leadership must restore precise controls and accountable succession.

What you will own

  • Reconstruct token, device, endpoint, account, beneficiary and benefit-abuse journeys across markets, partners and repeated attacker infrastructure.
  • Inventory exposed APIs, callable business operations, data objects, economic value and partner trust dependencies with accountable service owners.
  • Rotate credentials and redesign partner identity with narrow scopes, audience restriction, expiring authority and attributable emergency access.
  • Establish behavioural limits across identity, sequence, velocity, relationship, resource value and cumulative campaign effect without relying on IP reputation.
  • Test controls against distributed low-and-slow automation, partner compromise, device farms and legitimate promotion or transport peaks.
  • Govern partner exceptions through business evidence, targeted monitoring, compensating restriction, sponsor approval and enforced retirement dates.
  • Transfer playbooks, control rationale, partner exceptions, simulation results and risk decisions through two successor-led platform governance cycles.

Candidate qualifications

  • Led API abuse defence for a high-scale consumer platform with material partner, marketplace and customer dependencies.
  • Can evidence containment of low-rate distributed automation that deliberately stayed beneath volumetric and infrastructure thresholds.
  • Governed partner tokens, OAuth grants, service identity, scope reduction, secret custody and emergency credential rotation.
  • Balanced abuse suppression against legitimate ecosystem availability using journey, partner and customer-impact evidence.
  • Connected fraud, security, platform engineering, commercial partner and customer-operations teams during a coordinated campaign.
  • Handed recovered controls, exception debt and simulation ownership to permanent engineering leadership after stable operation.

Non-negotiables

  • Available within two weeks for the regional cadence.
  • Independent of bot-management and API-security vendors engaged.
  • Will measure customer and partner harm alongside attack suppression.
  • Has director-level live platform security authority.
  1. 49 words maximum. State your availability and one low-rate API campaign you contained.
  2. 49 words maximum. Which behaviour exposed abuse when volume thresholds remained normal?
  3. 49 words maximum. Describe a containment action you reversed because partner harm was excessive.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.