API Security Engineer
Moderna
Cybersecurity Engineer
As a Cybersecurity Engineer, you will help design, implement, and mature Moderna's approach to API security across modern applications, platform services, and AI-enabled use cases. This role is primarily focused on securing APIs and the systems that expose and consume them, including improving visibility, control, and risk reduction across a growing set of application and integration patterns, with support for initiatives such as AI Gateway and other shared platforms where needed.
The ideal candidate brings strong hands-on experience with API security concepts and controls, and can work effectively across engineering, architecture, and security teams to improve how APIs are exposed, authenticated, monitored, and governed. This role also calls for someone who is forward thinking about how identity and trust models are evolving, including how to secure service identities, machine-to-machine access, and emerging agentic patterns where software agents interact with APIs, tools, and sensitive data on behalf of users or systems.
Here's What You'll Do:
- Help design, implement, and mature Moderna's API security capabilities across enterprise applications, shared services, integrations, and AI-related platforms.
- Support the evaluation, deployment, and operationalization of API security technologies used for API discovery, posture assessment, traffic monitoring, anomaly detection, and policy enforcement.
- Partner with application, platform, and engineering teams to identify insecure API designs, weak authentication or authorization patterns, excessive data exposure, and other common API security risks.
- Perform API-focused threat modeling and security assessments for modern services, microservices, integrations, and AI-enabled workflows.
- Define and promote secure API engineering practices, including strong authentication, authorization, rate limiting, schema validation, secrets handling, and secure service-to-service communication.
- Help shape security approaches for non-human and agentic identity models, including how services, automation, and software agents authenticate to APIs, obtain scoped access, and interact with sensitive systems safely.
- Analyze API telemetry and findings to identify abuse paths, misconfigurations, shadow APIs, and control gaps, then work with stakeholders to drive remediation.
- Collaborate with broader security teams to connect API security findings with cloud, application, identity, and detection engineering workflows.
- Provide practical engineering guidance that helps teams improve API security while preparing for new trust and identity challenges introduced by automation and AI-enabled systems.
Here's What You'll Bring to the Table:
- 5+ years of experience in cybersecurity, application security, platform security, or a related engineering discipline, with meaningful hands-on experience in API security.
- Strong understanding of API security risks and controls, including authentication, authorization, token handling, rate limiting, data exposure, input validation, and service-to-service trust models.
- Experience assessing or securing REST, GraphQL, or other modern API patterns in cloud-native or distributed application environments.
- Experience working with engineering and platform teams to improve API design, security posture, and operational controls.
- Familiarity with API gateways, service meshes, reverse proxies, or related control points used to secure and observe API traffic.
- Ability to perform threat modeling and technical risk assessments for APIs, integrations, backend services, and machine-to-machine interaction patterns.
- Working knowledge of identity and access concepts relevant to non-human identities, workload identities, and emerging agentic access patterns is strongly preferred.
- Working knowledge of cloud and application security fundamentals, including identity, secrets management, logging, and common security design patterns.
- Familiarity with AI-enabled architectures or gateway patterns is a plus, particularly where APIs are used to broker access to models, tools, or sensitive data flows.
- Strong analytical and troubleshooting skills, with the ability to turn technical findings into pragmatic remediation guidance.
- Strong written and verbal communication skills, with the ability to work across technical and non-technical stakeholder groups.
- ...review the following job description:• This team uses automated API security tools like Akamai, Salt Security and ReadyAPI tools to identify vulnerabilities in running APIs.• This Senior Security Engineer will be experienced with API development and/or API security testing...SuggestedFull timePart timeShift workDay shift
$190k - $210k
...Security Engineer, WAF & API Security You are a software engineer who specializes in security. This role owns Layer 7 defense for a cloud-native fintech environment: WAF, API security, and bot protection for customer-facing applications running across AWS and GCP. You...SuggestedFull timeRemote work$145.9k - $234.2k
The Role: As a Cybersecurity Engineer, you will help design, implement, and mature Moderna’s approach to API security across modern applications, platform services, and AI-enabled use cases. This role is primarily focused on securing APIs and the systems that expose and...SuggestedPermanent employmentFull timeWork at officeWork from home- ...of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay... ...role:You will help build a best-in-class API security program designed for the speed of... ...and analytics, partnering closely with top engineers across product, platform, and security....SuggestedFull timeContract workTemporary workH1bWork at officeMonday to Friday
- ...API Security Engineer Perfict Global is a leading IT consulting services provider focused on providing innovative and successful business workforce solutions to Fortune 500 companies. Our trained and experienced professionals constantly strive to bring together the...SuggestedRemote work
$116k - $216k
...Location: 4910 Tiedeman Road, Brooklyn Ohio API Security Engineer Role Overview We are seeking an experienced API & Application Security Engineer with expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway...Work at officeRemote workFlexible hours$128k - $216k
...of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay... ...difference at Fiserv.About your role:Our API security function is about 18 months in and... ...(Traceable), partnering with the engineers who handle day-to-day tuning, false positives...Full timeTemporary workH1bWork at officeMonday to Friday$103.75k - $174.75k
...technologies, and a commitment to back the broader engineering community through open source, our... ...of this mission is our Information Security organization, enabling exceptional experiences... ...and backend application components, APIs, integrations, and supporting services....Internship- ...and Green Cards candidates only. Help Secure How AI Connects Into the Enterprise We are looking for a Senior Security Engineer with strong AppSec foundations and... ...who can work across complex applications, APIs, identity, cloud, and emerging AI systems....Contract work
- Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services... ...controls for web-based SaaS applications such as API Security, WAF, etc.In-depth knowledge of AI/LLM and machine...Temporary workWork at officeRemote workWork from homeFlexible hours
$146k - $169k
...GoodLeap’s security team safeguards the organization’s information assets while enabling the... ...governance. As a Senior Product Security Engineer, you’ll partner with product and... ...Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces...Full time$152k - $261k
...ideal candidate will be passionate around security and will love to dive deep in order to... ...penetration testing activities on web, mobile, API and network. Provide remediation... ...framework Computer Science, Computer Engineering, or related technical Degree Holder...Full timeTemporary workWork experience placementWork at officeFlexible hours$159.3k - $202.4k
Amazon Healthcare Security's (HealthSec) Detections & Monitoring team is hiring a Security Engineer II to design, build, and operate detection and monitoring capabilities that... ...agent orchestration systems, and AI service APIs Build automated investigation and response...Work experience placementFlexible hours$152k - $261k
...ideal candidate will be passionate around security and will love to dive deep in order to... ...penetration testing activities on web, mobile, API and network.Provide remediation... ...&CK frameworkComputer Science, Computer Engineering, or related technical DegreeHolder of well...Temporary workWork experience placementWork at office$126.82k - $149.2k
...more days per week.US Bank is seeking a Lead Information Security Consultant - API Security & Governance to help strengthen and mature API security... ...Security, Technology Risk, Enterprise Architecture, and engineering teams to identify and mitigate API security risks.Conduct...Full timeLocal area3 days per week- ...experience in microservices architecture, REST APIs, cloud platforms (AWS), and CI/CD... ...REST, SOAP/XML when required)• Implement secure, high-performance backend systems with proper... ...to-Have Skills• Experience with workflow engines (e.g., Camunda)• Knowledge of messaging...
- ...Offensive Security Software Engineer - Attack Engineer Top Secret Clearance Required 90% Remote. On site work required in DMV/NCR occasionally... ...into platform capabilities • Enhance platform architecture, APIs, and data models to support evolving offensive security...Remote work
- ...Security Engineer Location: Seattle, WA – Preferred / Sunnyvale, CA – Local Candidates Preferred Client: Indium Technologies Employment... ...and privacy design reviews of services, applications, APIs, engineering proposals, and AI integrations. Evaluate architecture...Local area
- ...Our federal IT client is looking for a senior engineer to own the security and compliance posture of a Microsoft 365 GCC environment supporting a... ...Okta connectors, Copilot audit logging, and Microsoft Graph API operations macOS security hardening and mSCP baseline engineering...Full time
$55 - $60 per hour
...Job Title: IAM Security Engineer Location: Seattle, WA, 98101 Duration: 3 Months Work Type: Onsite Job Type: Temporary Assignment... ...automation scripts and simple applications that interact with REST APIs to extend IAM platform capabilities. Example Projects or...Temporary work- Engineer II Premium (Cloud Security Consultant) Focus: Security assessment of GCP-based conversational AI, telephony, API, and backend integration architecture.
- ...Security Engineer Department: Engineering Location: Remote (US) Type: Contract-to-hire Intro: Onramp is hiring a Security Engineer... ...custody and delivered through products people love and APIs institutions build on. We are a FinCEN-registered Money Services...Full timeContract workRemote work
- ...endpoint standardization, aligning with industry standards and security best practices. Designed and implemented enterprise-wide software... ...vectors. Developed automated workflows through Tanium’s Rest API to increase efficiency in platform delivery and reporting....Full time
- ..., NY or Alpharetta, GA – onsite 3 days a week WAF / Akamai Security Engineer 1. WAF Onboarding & Application Migration · Lead onboarding... ...narrowly scoped exceptions when justified. 3. AI, LLM & API Security Support · Troubleshoot AI- and LLM-related traffic...Full time3 days per week
- ...IDR is seeking a Senior Access Management Engineer with deep, hands-on experience in Cisco Duo and enterprise MFA/access management.... ...infrastructure, VPN/remote access, and cloud platforms Build/consume Duo APIs (Admin API/Auth API) and support automation/scripting Lead...Remote work
$130k - $200k
...–$200K JOB DESCRIPTION Our client is seeking a Cloud Security Engineer III – AI/ML Platforms to help design, implement, and mature security... ...or security concepts, including securing data flows, APIs, model access, pipelines, or deployment environments. • Experience...Full time- ...Position: Security Engineer Location: New York, NY DESCRIPTION As a member of the Information Security te am, the Security Engineer... ...areas: Web Applications, Mobile Applications, Databases, APIs, Containers and other domains. • Support and maintain application...Full time
- ...Job title: - Security IDaaS Engineer Duration: - 12 Months (Possible for Extension) FULLY REMOTE JOB Job Description: Experience - Must... ...have Security, NIST, FedRAMP CSF, RBAC, Entra, Rest API Networks /infrastructure, Python, Saviynt Responsibilities...Work experience placementRemote work
- ...Hybrid in Cary, NC, Tues-Thursday Our client seeks an Identity Security Engineer to strengthen identity security and reduce privileged access... ...privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations....Permanent employmentFull time
- ...Identity Security Engineer - We are seeking an Identity Security Engineer for a 6-month contract to hire hybrid role on site in Cary,... ...privileged access processes using PowerShell, Python, REST APIs, and workflow integrations . Troubleshoot IAM/PAM issues,...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to API Security Engineer. Be the first to apply!
- application security engineer United States
- principal security engineer United States
- senior cloud security engineer United States
- security operations engineer United States
- security engineer intern United States
- security support engineer United States
- associate security engineer United States
- hardware security engineer United States
- azure security engineer United States
- junior security engineer United States



