API Security Engineer

Moderna Therapeutics

United States

Hybrid

USD 146,000 - 234,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive healthcare
Well-being programs
Family planning benefits
Generous paid time off
Equity incentives

Job summary

Moderna Therapeutics is seeking a Cybersecurity Engineer focused on API security to design, implement, and mature security practices across APIs, services, and AI-enabled platforms. You will partner with engineering teams to strengthen authentication, authorization, and data protection while advancing threat modeling and secure API patterns.

The role emphasizes securing non-human identities, service-to-service communication, and scalable governance, with a hybrid work model in the United States.

Qualifications

  • 5+ years of experience in cybersecurity, application security, platform security, or a related engineering discipline, with meaningful hands-on experience in API security.
  • Strong understanding of API security risks and controls, including authentication, authorization, token handling, rate limiting, data exposure, input validation, and service-to-service trust models.

Responsibilities

  • Design, implement, and mature Moderna’s API security across enterprise apps, services, integrations, and AI platforms.
  • Evaluate, deploy, and operationalize API security tech for discovery, posture, traffic monitoring, anomaly detection, and policy enforcement.
  • Collaborate with engineering teams to identify insecure API designs, weak authentication/authorization patterns, and data exposure risks.
  • Perform API threat modeling and security assessments for microservices, integrations, and AI-enabled workflows.
  • Promote secure API engineering practices: strong authentication, authorization, rate limiting, schema validation, secrets handling, and secure service-to-service communication.
  • Shape security approaches for non-human and agentic identities, including service authentication and machine-to-machine access.
  • Analyze API telemetry to identify abuse paths, misconfigurations, shadow APIs, and drive remediation.
  • Coordinate with cloud, identity, and detection engineering teams to close API security gaps.
  • Provide pragmatic remediation guidance to improve API security amid automation and AI-enabled systems.

Skills

API security
Threat modeling
Cloud security
Identity concepts
Security engineering
API design

Tools

API gateways
Service meshes
REST/GraphQL

Job description

The Role:

As a Cybersecurity Engineer, you will help design, implement, and mature Moderna’s approach to API security across modern applications, platform services, and AI-enabled use cases. This role is primarily focused on securing APIs and the systems that expose and consume them, including improving visibility, control, and risk reduction across a growing set of application and integration patterns, with support for initiatives such as AI Gateway and other shared platforms where needed. The ideal candidate brings strong hands‑on experience with API security concepts and controls, and can work effectively across engineering, architecture, and security teams to improve how APIs are exposed, authenticated, monitored, and governed. This role also calls for someone who is forward thinking about how identity and trust models are evolving, including how to secure service identities, machine‑to‑machine access, and emerging agentic patterns where software agents interact with APIs, tools, and sensitive data on behalf of users or systems.

Here’s What You’ll Do:
  • Help design, implement, and mature Moderna’s API security capabilities across enterprise applications, shared services, integrations, and AI-related platforms.
  • Support the evaluation, deployment, and operationalization of API security technologies used for API discovery, posture assessment, traffic monitoring, anomaly detection, and policy enforcement.
  • Partner with application, platform, and engineering teams to identify insecure API designs, weak authentication or authorization patterns, excessive data exposure, and other common API security risks.
  • Perform API‑focused threat modeling and security assessments for modern services, microservices, integrations, and AI‑enabled workflows.
  • Define and promote secure API engineering practices, including strong authentication, authorization, rate limiting, schema validation, secrets handling, and secure service‑to‑service communication.
  • Help shape security approaches for non‑human and agentic identity models, including how services, automation, and software agents authenticate to APIs, obtain scoped access, and interact with sensitive systems safely.
  • Analyze API telemetry and findings to identify abuse paths, misconfigurations, shadow APIs, and control gaps, then work with stakeholders to drive remediation.
  • Collaborate with broader security teams to connect API security findings with cloud, application, identity, and detection engineering workflows.
  • Provide practical engineering guidance that helps teams improve API security while preparing for new trust and identity challenges introduced by automation and AI‑enabled systems.
Here’s What You’ll Bring to the Table:
  • 5+ years of experience in cybersecurity, application security, platform security, or a related engineering discipline, with meaningful hands‑on experience in API security.
  • Strong understanding of API security risks and controls, including authentication, authorization, token handling, rate limiting, data exposure, input validation, and service‑to‑service trust models.
  • Experience assessing or securing REST, GraphQL, or other modern API patterns in cloud‑native or distributed application environments.
  • Experience working with engineering and platform teams to improve API design, security posture, and operational controls.
  • Familiarity with API gateways, service meshes, reverse proxies, or related control points used to secure and observe API traffic.
  • Ability to perform threat modeling and technical risk assessments for APIs, integrations, backend services, and machine‑to‑machine interaction patterns.
  • Working knowledge of identity and access concepts relevant to non‑human identities, workload identities, and emerging agentic access patterns is strongly preferred.
  • Working knowledge of cloud and application security fundamentals, including identity, secrets management, logging, and common security design patterns.
  • Familiarity with AI‑enabled architectures or gateway patterns is a plus, particularly where APIs are used to broker access to models, tools, or sensitive data flows.
  • Strong analytical and troubleshooting skills, with the ability to turn technical findings into pragmatic remediation guidance.
  • Strong written and verbal communication skills, with the ability to work across technical and non‑technical stakeholder groups.
Pay & Benefits
  • Competitive healthcare, plus voluntary benefit programs to support your unique needs
  • A holistic approach to well‑being, with access to fitness, mindfulness, and mental health support
  • Family planning benefits, including fertility, adoption, and surrogacy support
  • Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year‑end shutdown
  • Savings and investments to help you plan for the future

Location‑specific perks and extras

The salary range for this role is $145,900.00 - $234,200.00. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An individual’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, performance, and business or organizational needs. The successful candidate may be eligible for an annual discretionary bonus, other incentive compensation, or equity award, subject to company plan eligibility criteria and individual performance.

About Moderna

Since our founding in 2010, we have aspired to build the leading mRNA technology platform, the infrastructure to reimagine how medicines are created and delivered, and a world‑class team. We believe in giving our people a platform to change medicine and an opportunity to change the world. By living our mission, values, and mindsets every day, our people are the driving force behind our scientific progress and our culture. Together, we are creating a culture of belonging and building an organization that cares deeply for our patients, our employees, the environment, and our communities. We are proud to have been recognized as a Science Magazine Top Biopharma Employer, a Fast Company Best Workplace for Innovators, and a Great Place to Work in the U.S.

Our Working Model

As we build our company, we have always believed an in‑person culture is critical to our success. Moderna champions the significant benefits of in‑office collaboration by embracing a 70/30 work model. This 70% in‑office structure helps to foster a culture rich in innovation, teamwork, and direct mentorship. Join us in shaping a world where every interaction is an opportunity to learn, contribute, and make a meaningful impact. Moderna is a smoke‑free, alcohol‑free, and drug‑free work environment.

Equal Opportunities

Moderna is committed to equal employment opportunity and non‑discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry or citizenship, ethnicity, disability, military or protected veteran status, genetic information, sexual orientation, marital or familial status, or any other personal characteristic protected under applicable law. Moderna is a place where everyone can grow. Moderna is an E‑Verify Employer in the United States. We consider qualified applicants regardless of criminal histories, consistent with legal requirements.

Accommodations

We’re focused on attracting, retaining, developing, and advancing our employees. By cultivating a workplace that values diverse experiences, backgrounds, and ideas, we create an environment where every employee can contribute their best. Moderna is committed to offering reasonable accommodations to qualified job applicants with disabilities. Any applicant requiring an accommodation in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should contact the Accommodations team at leavesandaccommodations@modernatx.com.

Export Control Notice

This position may involve access to technology or data that is subject to U.S. export control laws, including the Export Administration Regulations (EAR). As such, employment is contingent upon the applicant’s ability to access export‑controlled information in accordance with U.S. law. Due to the nature of the work and regulatory requirements, only individuals who qualify as U.S. persons (citizens, permanent residents, asylees, or refugees) are eligible for this position. For this role Moderna is unable to sponsor non‑U.S. persons to apply for an export control license.

Our Mission and Vision

At Moderna we are pioneering the development of a new class of drugs made of messenger RNA (mRNA). This novel drug platform builds on the discovery that modified mRNA can direct the body’s cellular machinery to produce nearly any protein of interest, from native proteins to antibodies and other entirely novel protein constructs that can have therapeutic activity inside and outside of cells. We have a clear mission to propel the field of mRNA science forward and deliver new medicines to patients and a unique vision for how to achieve this mission. Our Mission: To deliver on the promise of transformative messenger RNA (mRNA) science to bring new medicines to patients. Our Vision: To unlock the potential of mRNA by establishing an ecosystem of teams and partners that will work together to develop the broadest possible array of drugs, across diverse therapeutic areas and routes of administration, for serious diseases that are not treatable today.

Third Party Staffing Agencies

Moderna does not accept unsolicited resumes from any source other than directly from candidates. For the protection of all parties involved in the recruiting process, resumes will only be accepted from recruiters/agencies if a signed agreement is in place at the inception of the recruiting effort and authorized for a specified position. Unsolicited resumes sent to Moderna from recruiters/agencies do not constitute any type of relationship between the recruiter/agency and Moderna and do not obligate Moderna to pay fees if we hire from those resumes.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. AI Red Team Engineer
Sr. AI Red Team Engineer

Moderna Therapeutics • United States

Hybrid
USD 146,000 - 234,000
Healthcare
Well-being resources
Family planning
+3
API Security Engineer
API Security Engineer

Moderna Therapeutics • Cambridge (MA)

On-site
USD 122,000 - 195,000
Competitive healthcare
Well-being resources
Family planning benefits
+1
API Security Engineer
API Security Engineer

Moderna • Cambridge (MA)

On-site
USD 122,000 - 195,000
Healthcare
Well-being resources
Generous PTO
+1
Sr. Cyber Risk 3rd Party Analyst
Sr. Cyber Risk 3rd Party Analyst

Moderna Therapeutics • Cambridge (MA)

On-site
USD 146,000 - 234,000
Counsel, US Market Access and Operations
Counsel, US Market Access and Operations

Moderna Therapeutics • West Windsor (NJ)

On-site
USD 184,000 - 330,000
Competitive healthcare
Well-being resources
Family planning benefits
+3
Principal Research Associate, Analytical Development
Principal Research Associate, Analytical Development

Moderna Therapeutics • Norwood (MA)

On-site
USD 90,000 - 144,000
Competitive healthcare
Well-being resources
Family planning benefits
+3
Sr. Manager, COE SAP Technical Authority
Sr. Manager, COE SAP Technical Authority

Moderna Therapeutics • Norwood (MA)

On-site
USD 131,000 - 209,000
Healthcare
Well-being programs
Family planning benefits
+3
API Security Engineer
API Security Engineer

BioSpace • Cambridge (MA)

On-site
USD 122,000 - 195,000
Healthcare
Well-being resources
Paid time off
+2
Senior Infrastructure Automation Engineer
Senior Infrastructure Automation Engineer

Moderna Therapeutics • Seattle (WA)

On-site
USD 131,000 - 209,000
Competitive healthcare
Well-being programs
Family planning benefits
+3
Director, Clinical Sciences, Oncology
Director, Clinical Sciences, Oncology

Moderna Therapeutics • West Windsor (NJ)

Hybrid
USD 184,000 - 330,000
Hybrid work model
Annual bonus eligibility
Equity award eligibility