Talent Apply
Log in
All jobs
MI

API Security Engineer

Moderna, Inc.
Cambridge, Massachusetts
On-siteUSD 145,900 - 234,200 / year

About this role

About the Role

Moderna is seeking an API Security Engineer to design, implement, and mature Moderna’s API security strategy across enterprise apps, shared services, integrations, and AI-enabled workflows. The role focuses on securing APIs and the systems that expose and consume them, improving visibility, control, and risk reduction across a growing set of patterns, with support for initiatives like AI Gateway and shared platforms where needed. The ideal candidate collaborates across engineering, architecture, and security teams and thinks ahead about evolving identity and trust models, including service identities, machine-to-machine access, and agentic software interactions with APIs and sensitive data. What You'll Do

  • Help design, implement, and mature Moderna’s API security capabilities across enterprise applications, shared services, integrations, and AI-related platforms.

  • Support the evaluation, deployment, and operationalization of API security technologies used for API discovery, posture assessment, traffic monitoring, anomaly detection, and policy enforcement.

  • Partner with application, platform, and engineering teams to identify insecure API designs, weak authentication or authorization patterns, excessive data exposure, and other common API security risks.

  • Perform API-focused threat modeling and security assessments for modern services, microservices, integrations, and AI-enabled workflows.

  • Define and promote secure API engineering practices, including strong authentication, authorization, rate limiting, schema validation, secrets handling, and secure service-to-service communication.

  • Help shape security approaches for non-human and agentic identity models, including how services, automation, and software agents authenticate to APIs, obtain scoped access, and interact with sensitive systems safely.

  • Analyze API telemetry and findings to identify abuse paths, misconfigurations, shadow APIs, and control gaps, then work with stakeholders to drive remediation.

  • Collaborate with broader security teams to connect API security findings with cloud, application, identity, and detection engineering workflows.

  • Provide practical engineering guidance that helps teams improve API security while preparing for new trust and identity challenges introduced by automation and AI-enabled systems. What We're Looking For

  • 5+ years of experience in cybersecurity, application security, platform security, or a related engineering discipline, with meaningful hands-on experience in API security.

  • Strong understanding of API security risks and controls, including authentication, authorization, token handling, rate limiting, data exposure, input validation, and service-to-service trust models.

  • Experience assessing or securing REST, GraphQL, or other modern API patterns in cloud-native or distributed application environments.

  • Experience working with engineering and platform teams to improve API design, security posture, and operational controls.

  • Familiarity with API gateways, service meshes, reverse proxies, or related control points used to secure and observe API traffic.

  • Ability to perform threat modeling and technical risk assessments for APIs, integrations, backend services, and machine-to-machine interaction patterns.

  • Working knowledge of identity and access concepts relevant to non-human identities, workload identities, and emerging agentic access patterns is strongly preferred.

  • Working knowledge of cloud and application security fundamentals, including identity, secrets management, logging, and common security design patterns.

  • Familiarity with AI-enabled architectures or gateway patterns is a plus, particularly where APIs are used to broker access to models, tools, or sensitive data flows.

  • Strong analytical and troubleshooting skills, with the ability to turn technical findings into pragmatic remediation guidance.

  • Strong written and verbal communication skills, with the ability to work across technical and non-technical stakeholder groups. Compensation & Benefits

  • Salary range: $145,900.00 - $234,200.00 USD per year.

  • Competitive healthcare, plus voluntary benefit programs to support your needs.

  • Holistic well-being resources including fitness, mindfulness, and mental health support.

  • Family planning benefits, including fertility, adoption, and surrogacy support.

  • Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown.

  • Savings and investments to help you plan for the future.

  • Location-specific perks and extras.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →