API Security Engineer
$121.6k - $194.5kModerna
The Role
As a Cybersecurity Engineer, you will help design, implement, and mature Moderna’s approach to API security across modern applications, platform services, and AI-enabled use cases. This role is primarily focused on securing APIs and the systems that expose and consume them, including improving visibility, control, and risk reduction across a growing set of application and integration patterns, with support for initiatives such as AI Gateway and other shared platforms where needed. The ideal candidate brings strong hands‑on experience with API security concepts and controls, and can work effectively across engineering, architecture, and security teams to improve how APIs are exposed, authenticated, monitored, and governed. This role also calls for someone who is forward thinking about how identity and trust models are evolving, including how to secure service identities, machine-to-machine access, and emerging agentic patterns where software agents interact with APIs, tools, and sensitive data on behalf of users or systems.
Here’s What You’ll Do
Help design, implement, and mature Moderna’s API security capabilities across enterprise applications, shared services, integrations, and AI-related platforms. Support the evaluation, deployment, and operationalization of API security technologies used for API discovery, posture assessment, traffic monitoring, anomaly detection, and policy enforcement. Partner with application, platform, and engineering teams to identify insecure API designs, weak authentication or authorization patterns, excessive data exposure, and other common API security risks. Perform API-focused threat modeling and security assessments for modern services, microservices, integrations, and AI-enabled workflows. Define and promote secure API engineering practices, including strong authentication, authorization, rate limiting, schema validation, secrets handling, and secure service-to-service communication. Help shape security approaches for non-human and agentic identity models, including how services, automation, and software agents authenticate to APIs, obtain scoped access, and interact with sensitive systems safely. Analyze API telemetry and findings to identify abuse paths, misconfigurations, shadow APIs, and control gaps, then work with stakeholders to drive remediation. Collaborate with broader security teams to connect API security findings with cloud, application, identity, and detection engineering workflows. Provide practical engineering guidance that helps teams improve API security while preparing for new trust and identity challenges introduced by automation and AI-enabled systems.
Here’s What You’ll Bring to the Table
5+ years of experience in cybersecurity, application security, platform security, or a related engineering discipline, with meaningful hands‑on experience in API security. Strong understanding of API security risks and controls, including authentication, authorization, token handling, rate limiting, data exposure, input validation, and service-to-service trust models. Experience assessing or securing REST, GraphQL, or other modern API patterns in cloud-native or distributed application environments. Experience working with engineering and platform teams to improve API design, security posture, and operational controls. Familiarity with API gateways, service meshes, reverse proxies, or related control points used to secure and observe API traffic. Ability to perform threat modeling and technical risk assessments for APIs, integrations, backend services, and machine-to‑machine interaction patterns. Working knowledge of identity and access concepts relevant to non-human identities, workload identities, and emerging agentic access patterns is strongly preferred. Working knowledge of cloud and application security fundamentals, including identity, secrets management, logging, and common security design patterns. Familiarity with AI-enabled architectures or gateway patterns is a plus, particularly where APIs are used to broker access to models, tools, or sensitive data flows. Strong analytical and troubleshooting skills, with the ability to turn technical findings into pragmatic remediation guidance. Strong written and verbal communication skills, with the ability to work across technical and non‑technical stakeholder groups.
Pay & Benefits
At Moderna, we believe that when you feel your best, you can do your best work. That’s why our benefits and well‑being resources are designed to support you - at work, at home, and everywhere in between.
- Competitive healthcare, plus voluntary benefit programs to support your unique needs
- A holistic approach to well‑being, with access to fitness, mindfulness, and mental health support
- Family planning benefits, including fertility, adoption, and surrogacy support
- Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown
- Savings and investments to help you plan for the future
- Location-specific perks and extras
The salary range for this role is $121,600.00 - $194,500.00. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of the posting. An individual’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, performance, and business or organizational needs. The successful candidate may be eligible for an annual discretionary bonus, other incentive compensation, or equity award, subject to company plan eligibility criteria and individual performance.
About Moderna
Since our founding in 2010, we have aspired to build the leading mRNA technology platform, the infrastructure to reimagine how medicines are created and delivered, and a world‑class team. We believe in giving our people a platform to change medicine and an opportunity to change the world. By living our mission, values, and mindsets every day, our people are the driving force behind our scientific progress and our culture. Together, we are creating a culture of belonging and building an organization that cares deeply for our patients, our employees, the environment, and our communities. We are proud to have been recognized as a Science Magazine Top Biopharma Employer, a Fast Company Best Workplace for Innovators, and a Great Place to Work in the U.S.
Our Working Model
As we build our company, we have always believed an in‑person culture is critical to our success. Moderna champions the significant benefits of in‑office collaboration by embracing a 70/30 work model. This 70% in‑office structure helps to foster a culture rich in innovation, teamwork, and direct mentorship. Join us in shaping a world where every interaction is an opportunity to learn, contribute, and make a meaningful impact. Moderna is a smoke‑free, alcohol‑free, and drug‑free work environment.
Equal Opportunities
Moderna is committed to equal employment opportunity and non‑discrimination for all employees and qualified applicants without regard to a person’s race, color, sex, gender identity or expression, age, religion, national origin, ancestry or citizenship, ethnicity, disability, military or protected veteran status, genetic information, sexual orientation, marital or familial status, or any other personal characteristic protected under applicable law. We consider qualified applicants regardless of criminal histories, consistent with legal requirements.
Accommodations
We’re focused on attracting, retaining, developing, and advancing our employees. By cultivating a workplace that values diverse experiences, backgrounds, and ideas, we create an environment where every employee can contribute their best. Moderna is committed to offering reasonable accommodations to qualified job applicants with disabilities. Any applicant requiring an accommodation in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should contact the Accommodations team at View email address on click.appcast.io.
Export Control Notice
This position may involve access to technology or data that is subject to U.S. export control laws, including the Export Administration Regulations (EAR). As such, employment is contingent upon the applicant’s ability to access export‑controlled information in accordance with U.S. law. Due to the nature of the work and regulatory requirements, only individuals who qualify as U.S. persons (citizens, permanent residents, asylees, or refugees) are eligible for this position. For this role Moderna is unable to sponsor non‑U.S. persons to apply for an export control license.
Our Mission and Vision
At Moderna we are pioneering the development of a new class of drugs made of messenger RNA (mRNA). This novel drug platform builds on the discovery that modified mRNA can direct the body’s cellular machinery to produce nearly any protein of interest, from native proteins to antibodies and other entirely novel protein constructs that can have therapeutic activity inside and outside of cells. We have a clear mission to propel the field of mRNA science forward and deliver new medicines to patients and a unique vision for how to achieve this mission.
Our Mission: To deliver on the promise of transformative messenger RNA (mRNA) science to bring new medicines to patients.
Our Vision: To unlock the potential of mRNA by establishing an ecosystem of teams and partners that will work together to develop the broadest possible array of drugs, across diverse therapeutic areas and routes of administration, for serious diseases that are not treatable today.
Third Party Staffing Agencies
Moderna does not accept unsolicited resumes from any source other than directly from candidates. For the protection of all parties involved in the recruiting process, resumes will only be accepted from recruiters/agencies if a signed agreement is in place at the inception of the recruiting effort and authorized for a specified position. Unsolicited resumes sent to Moderna from recruiters/agencies do not constitute any type of relationship between the recruiter/agency and Moderna and do not obligate Moderna to pay fees if we hire from those resumes.
Reasonable Accommodation Notice
Moderna will make reasonable accommodations for qualified individuals with known disabilities, in accordance with applicable law. Applicants with disabilities may be entitled to reasonable accommodation under the terms of the Americans with Disabilities Act and certain state or local laws. Please inform the company's personnel representative by calling View phone number on click.appcast.io or emailing View email address on click.appcast.io if you need assistance completing any forms or to otherwise participate in the application process. Examples of reasonable accommodations include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.
#J-18808-Ljbffr$145.9k - $234.2k
The Role: As a Cybersecurity Engineer, you will help design, implement, and mature Moderna’s approach to API security across modern applications, platform services, and AI-enabled use cases. This role is primarily focused on securing APIs and the systems that expose and...SuggestedPermanent employmentFull timeWork at officeWork from home$125k - $205k
...deliver results. Learn more at later.com.Senior Security EngineerAbout this position:We're looking for a Senior Security Engineer to strengthen Later's company-wide security... ...reviews, threat modeling, code review guidance, API security, microservices security patterns, and...SuggestedPermanent employmentLocal areaRemote work$150k - $200k
...organization in Boston, MA that is seeking a hands-on Senior Security Engineer to join a small, high-impact engineering team focused on building... ...scalable security capabilities using Terraform, Python, APIs, and infrastructure-as-code principles* Partner with infrastructure...Suggested$150k - $190k
DescriptionKforce's client in Boston, MA is seeking a Product Security Engineer.Summary:We're partnering with a highly respected global... ...Familiarity with secure development practices across web applications, APIs, and microservices* Experience helping build, mature, or...Suggested- ...Responsibilities The Security Operations Engineer builds and operates security controls, tooling, and automation across DeepHealth's cloud and... ...Integrate security tooling with adjacent platforms through APIs to reduce manual handling and improve data quality. Implement...SuggestedWork at officeLocal areaRemote work
$121k - $226k
...you. As we continue to grow, we're looking for a Sr. AI Security Engineer. Hi Marley is building an AI-native operating model: personal... ...into the internal AI platform: access controls for inference APIs, isolation for cloud-hosted agentic workloads, and endpoint/DLP...Work at officeFlexible hours3 days per week$99k - $120k
...to make them unshakeable, this role is built for you. As a Security Engineer II on our Active Operational Offensive track , you’ll sit at... ...misconfigurations, and privilege escalation paths. Web Application & API Assessment: Perform deep-dive testing on web applications and...Full timeLocal areaImmediate start- ...technical, collaborative environment where engineers build next-generation platforms and... ...significant scale. Job Title - Senior Cloud Security Engineer Location - Hybrid in Boston,... ...leveraging cloud-native services and APIs Provide hands‑on technical leadership...Work at office2 days per week3 days per week
$110k - $315k
...We are seeking a highly skilled and motivated Senior Cloud Security Engineer to join our cybersecurity team, with a focus on guiding cloud... ...adept at building integrations with common AWS services through API frameworks and Platform Automation Development. Responsibilities...Local area$192k - $230k
...Job Summary Snyk is the leader in secure AI software development, helping millions of... ...Security team works consultatively with the engineering teams that build and run our cloud... ...servers, command-line tools, and provider APIs so their fixes are grounded in the real environment...Work at officeWork from homeFlexible hoursEarly shift- ...Identity and Access Management Engineer – Officer (IAM Security Engineer)Location: Boston and Quincy, MA and Austin, TX, Atlanta Georgia, Princeton or Clifton NJ, Berwyn, PA, Stamford CT.MoI: Video with Possible F2FClient is Cyber Identity and Access Management is looking...
$210k - $234k
...exceptional service to seller and buyer clients. Engineering @ Compass Compass has built the... ...that will transform real estate. Security @ Compass We are hands-on security... ...: AWS and/or GCP, Kubernetes, IAM, API security, and DevSecOps practices. ~...Minimum wageFull timeFlexible hours- ...possible. What You Will Do Air Space Intelligence is building mission-critical, secure infrastructure for defense and intelligence applications. We are seeking a Security Engineer to harden and maintain cloud and software environments, ensuring compliance with U.S....Work at office3 days per week
- ...deployment experience, strong troubleshooting skills, CLI proficiency, security mindset, ability to solve complex problems, willingness to... .... Years of experience are less important than demonstrated engineering capability. Candidates transitioning from analyst to engineer...
- ...Sr. API Engineer To the extent permitted by applicable law, candidates must be fully vaccinated against COVID-19 to be considered for... ...model to avoid duplicate efforts, plan to deprecate unused APIs, security and operational policies across APIs to ensure enterprise...Contract workLocal area
$153k - $171k
...platform that empowers residential real estate agents to deliver exceptional service to seller and buyer clients.Security @ Compass We are hands-on security engineers helping to build secure, resilient, and scalable web apps, mobile apps, and platform for the real estate...Minimum wageFlexible hours- ...in mind every step of the way. As a Senior Application Security Engineer, you'll find the vulnerabilities in Forward Financing's software... .... Perform secure code review across web applications, APIs, and AWS infrastructure. Build tooling and security services...Work at officeRemote workWork from homeFlexible hours
$110k - $315k
...Job Overview We are seeking a hands-on Network Security Engineer with deep experience in NexGen firewalls such as Palo Alto Networks, Checkpoint and Fortinet technologies to help operate, secure, and continuously improve Arrowstreets network security environment....Local areaRemote work$170k - $200k
...Remote employees considered) Contract Full-time, Hybrid / Flexible – 35‑hour week Salary $175,000 base + 15% bonus Title Senior Security Engineer (US) Overview We are seeking a hands‑on, senior security engineer to proactively strengthen our security posture across cloud‑...Full timeContract workWork at officeRemote workFlexible hours$134.5k - $265.1k
...with confidence, and proactively manage to secure success.Work you will do:As Privileged... ...Science, Cyber Security, Information Security, Engineering, Information Technology, Finance,... ...Familiarity with SCIM and knowledge of various API authentication standards.Experience...Local areaVisa sponsorship$117.6k - $176.4k
...As a Senior Security Engineer at EnergySage, you will play a pivotal role in fortifying our application security through both hands-on technical work and strategic initiatives. What You’ll Do: Hands-On Security Enhancements: Implement and refine security measures...Full timeTemporary workFlexible hours$276.96k - $363.51k
...venture arm of NVIDIA). About the role The Lead Corporate Security Engineer will be our domain expert for securing our Corporate IT... ...the outcome ~ Automation fluency: Python or TypeScript, REST APIs, and a habit of building integrations and internal tooling as...Full timeLocal area$176k - $196k
...to deliver exceptional service to seller and buyer clients. Engineering @ Compass Compass is building the first modern end-to-end... ...the operating platform that will transform real estate. Security @ Compass We recognize that the most innovative teams are...Minimum wageFull timeWork at officeRemote workFlexible hours$120k - $202.5k
...Who we are looking for We are seeking a Product Security Engineer / Architect – Email Security reporting into the Defensive Engineering leadership team within Global Cyber Security (GCS). You will lead the strategy, architecture, and engineering of enterprise email...Full timeTemporary workWork at officeFlexible hours- ...AI Security ArchitectNTT DATA strives to hire exceptional, innovative and passionate individuals... ..., enterprise architects, data engineers, security teams, application developers,... ...enterprise applications, cloud platforms, APIs, and data platforms.Architect Retrieval-Augmented...
$198k - $368k
...and others. If you're as passionate about your future as we are, join our team.KPMG is currently seeking a Director, Global Security Engineering Lead to join our Global Digital Group which is part of KPMG International.Responsibilities:Own the engineering architecture,...H1bLocal area- ...customer facilities, on customer networks. Each of those customers has an IT and security team, and they need someone at Tutor who can work with them directly. We're looking for a senior engineer to be that person and to own the systems behind the conversation: the network...Full timeWork at officeShift work
$234k - $300k
...As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll... ...engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews....Full time- ...Test Automation Engineer (API)Location: Remote/ Hybrid (Durham, NC / Merrimack, NH / Boston / Smithfield, RI)Duration: Long term contractMust have:API Testing preferably Cucumber based testing frameworksWriting Database SQL’s -FitNesse - with 5 or more years of hands-on...Remote work
$57 - $64 per hour
DescriptionKforce has a client in Boston, MA that is seeking an Information Security Engineer.Responsibilities:* Evaluate technology and security operations to identify system needs, risks, and improvement opportunities* Gather and translate business requirements into clear...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to API Security Engineer. Be the first to apply!



