API Security Engineer
Moderna
August 21, 2026
Full-time
Remote friendly (Cambridge, MA)
Worldwide
IT
Role: Cybersecurity Engineer specializing in API security to enhance Moderna's application, platform, and AI system protections. Responsibilities: design and mature API security architectures, evaluate and deploy security technologies for threat detection and policy enforcement, collaborate with engineering teams to identify and mitigate API vulnerabilities, perform threat modeling and security assessments, define secure API engineering practices, and address emerging identity and trust challenges related to automation and AI. Requirements: 5+ years in cybersecurity, application security, or related fields; hands-on experience with API security risks, controls, and modern API patterns like REST and GraphQL; familiarity with API gateways, service meshes, and cloud-native environments; knowledge of identity concepts for non-human and agentic identities, cloud security fundamentals, and AI-enabled architectures. Preferred: strong analytical, troubleshooting, and communication skills to translate technical findings into remediation; experience working with engineering teams to improve security posture. High-Value: focus on securing APIs for modern, cloud-native applications, including AI-related platforms, with emphasis on authentication, authorization, traffic monitoring, and trust models for machine-to-machine and agent interactions. Work Setup: unspecified, but collaboration across teams is integral.