Sobre esta vaga de API Developer na Sanofi
Job Description: API Developer
Our Team:
The API Developer designs, builds, and maintains the APIs that connect enterprise systems, digital products, and external partners. This is a hands-on engineering role responsible for producing well-designed, robust, scalable, secure, well-documented APIs that other teams can discover and reuse for communication between internal products, third-party platforms and client-facing applications.
The API platform is run both as an internal product and as a managed service. The API Developer works contract-first, publishing APIs to the enterprise catalogue and developer portal, and builds the reusable components, templates, and policies that raise the standard of every API delivered across the organisation.
Kong is the primary gateway, operating alongside Apigee, Azure API Management, and AWS API Gateway across a multi-cloud estate on Microsoft Azure and Amazon Web Services. The role therefore values transferable, gateway-agnostic API skills as highly as any single product.
Main responsibilities:
API Design and Development
- Design and build APIs contract-first using Open API/Swagger, applying enterprise design standards, naming conventions, and versioning policy.
- Develop synchronous and asynchronous APIs across REST, GraphQL, gRPC, and event-driven patterns documented with AsyncAPI.
- Build domain and experience APIs that expose business capabilities cleanly, abstracting the complexity of underlying systems.
- Develop reusable API components, policies, plugins, and templates that other teams consume as a starting point.
Gateway and Runtime Implementation
- Implement and configure API proxies, routes, plugins, and policies on Kong Gateway and Kong Konnect.
- Deploy and operate gateway components on Kubernetes using the Kong Ingress Controller and GitOps workflows.
- Implement traffic management including rate limiting, throttling, caching, retries, and circuit breaking.
Security and Access Control
- Implement robust authentication and authorization mechanisms (OAuth 2.0, OpenID Connect, JWT, mutual TLS, API keys patterns)
- Ensure APIs comply with regulatory and data privacy requirements (GDPR, GxP where applicable)
- Integrate with enterprise identity providers including Entra ID and Okta.
- Manage secrets and certificates through HashiCorp Vault, CyberArk, and cloud-native key services.
Quality, Testing, and Automation
- Build automated contract, functional, integration, security, and performance tests for every API.
- Maintain CI/CD pipelines for API delivery using GitHub Actions or Azure DevOps, including linting and specification validation.
- Integrate static analysis, dependency scanning, and SBOM generation using SonarQube, Snyk, and equivalent tooling.
Operations and Support
- Instrument APIs for observability using OpenTelemetry format.
- Contribute during incident response, root-cause analysis, and problem management for API services.
- Build proactive monitoring services relying on Predictive ML.
- Support consumers through onboarding, troubleshooting, and clear technical guidance.
Technical Craft and Engineering Practices
- Write clean, tested, peer-reviewed code managed in Git using trunk-based practices.
- Use AI-assisted engineering tools such as GitHub Copilot and Claude Code to accelerate development, test generation, and documentation, applying appropriate review and technical judgement.
- Favour reuse and shared components over bespoke, single-purpose implementations.
Collaboration and Ways of Working
- Work within an agile product team with a shared backlog and defined customers.
- Partner with integration engineers, application teams, and data teams to agree interfaces and contracts.
- Engage with Cybersecurity and Architecture teams to keep API patterns aligned with approved standards.
About you
Required
- Demonstrated capability in API or backend software engineering, typically gained across five to eight years of professional experience.
- Proficiency in at least one modern backend language: Python or Node.js and TypeScript are preferred, and Java with Spring Boot is equally welcome.
- Deep understanding of REST architectural principles and GraphQL query language
- Experience with relational and NoSQL databases and the ability to write optimized queries
- Strong contract-first API design experience with Open API, including versioning and backward compatibility.
- Hands-on experience with an API gateway or management platform such as Kong, Apigee, Azure API Management, or AWS API Gateway.
- Practical experience implementing OAuth2, OpenID Connect, and TLS-based API security.
- Working knowledge of containers, Kubernetes, and CI/CD pipelines.
- Sound debugging skills across application, network, and gateway layers.
- Clear written and verbal communication in English, including the ability to document APIs for other engineers.
Preferred
- Experience with GraphQL federation and gRPC or Protocol Buffers.
- Experience with Kafka, Solace, or another event streaming or brokering platform.
- Experience integrating enterprise systems such as SAP, Salesforce, Veeva, Workday, or ServiceNow.
- Experience with developer portals, API catalogues, or API productization for external partners.
- Experience delivering within a regulated environment (GxP or other), including awareness of data-protection obligations such as GDPR.
- Certifications such as Kong, AWS or Azure developer level, or Certified Kubernetes Application Developer.
- A bachelor's degree in computer science, engineering, information technology, or a related discipline.
Core Competencies
- Design-led thinking with strong attention to interface quality
- Consumer focus and empathy for the developers who use your APIs
- Security awareness embedded in everyday engineering decisions
- Bias toward reuse, standardization, and simplification
- Pragmatic problem-solving under production pressure
- Ownership and follow-through
- Continuous learning and adaptability
Measures of Success
- Increased reuse of published APIs and shared components
- Reduced lead time from API design to production availability
- Improved conformance to enterprise API design and security standards
- Complete, accurate, and current API documentation in the catalogue
- Improved API availability, latency, and error rates against service levels
- Faster consumer onboarding and reduced support effort per API
- Reduced number of undocumented, duplicate, or unmanaged endpoints
Pursue progress, discover extraordinary
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!
Pursue progress, discover extraordinary
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, ability or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!