Skip to main content
Moderna logo

API Security Engineer

Moderna
September 02, 2026
Full-time
Remote friendly (Cambridge, MA)
Worldwide
IT
Role: Cybersecurity Engineer specializing in API security, focused on designing, implementing, and enhancing Moderna's API security across enterprise applications, platform services, and AI-enabled systems. Responsibilities: develop security controls for APIs, evaluate and operationalize security technologies, identify and remediate API vulnerabilities, perform threat modeling and security assessments of microservices and integrations, and shape identity models for non-human and agentic access. Requirements: 5+ years in cybersecurity or application security, deep expertise in API security risks and controls (authentication, authorization, traffic monitoring), experience with REST and GraphQL APIs in cloud-native environments, familiarity with API gateways and service meshes, and knowledge of identity concepts for machine-to-machine and automation interactions. Preferred: experience with AI architecture, cloud security fundamentals, and emerging agentic identity patterns. High-Value: API security for modern applications, microservices, AI platforms, and service identity trust models. Collaboration with engineering, security, and platform teams; focus on risk reduction, security best practices, and compliance within a biopharma context. Location: Not specified; technical role with emphasis on cross-team partnership.