7 дней назад
API Security Engineer (AI)
121 600 - 194 500$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
API Security Engineer (AI): Building and maturing API security capabilities across enterprise applications, shared services, integrations, and AI-enabled platforms with an accent on authentication, authorization, threat modeling, and non-human identity security. Focus on securing service-to-service and agentic access, detecting shadow APIs and control gaps, and driving remediation across cloud, application, identity, and detection engineering workflows.
Location: Cambridge, Massachusetts, United States; 70% in-office and 30% remote. Only U.S. persons are eligible due to U.S. export control requirements.
Salary: $121,600–$194,500 per year, with potential discretionary bonus, incentive compensation, or equity.
Company
develops mRNA-based therapeutics and vaccines using advances in mRNA science, delivery technology, and manufacturing.
What you will do
- Design, implement, and mature API security capabilities across applications, shared services, integrations, and AI-enabled platforms.
- Evaluate and operationalize technologies for API discovery, posture assessment, traffic monitoring, anomaly detection, and policy enforcement.
- Assess API designs, authentication and authorization patterns, data exposure, service-to-service trust, and other security risks.
- Perform API-focused threat modeling and security assessments for microservices, integrations, and AI-enabled workflows.
- Define secure API practices covering authentication, authorization, rate limiting, schema validation, secrets handling, and service communication.
- Analyze telemetry and findings, identify abuse paths, shadow APIs, and control gaps, and coordinate remediation with engineering and security teams.
Requirements
- U.S. person status is required because the role involves access to export-controlled technology or data; non-U.S. persons cannot be sponsored for an export control license.
- 5+ years of experience in cybersecurity, application security, platform security, or a related engineering discipline, including hands-on API security experience.
- Strong knowledge of API security risks and controls, including authentication, authorization, token handling, rate limiting, input validation, data exposure, and service-to-service trust.
- Experience securing REST, GraphQL, or other modern APIs in cloud-native or distributed environments.
- Experience with API gateways, service meshes, reverse proxies, threat modeling, and technical risk assessments.
- Working knowledge of cloud security, application security, identity, secrets management, logging, workload identities, and agentic access patterns.
Nice to have
- Familiarity with AI-enabled architectures or gateway patterns for access to models, tools, or sensitive data.
- Experience with non-human identity models and emerging agentic security patterns.
Culture & Benefits
- In-person collaboration supported by a 70/30 work model.
- Healthcare and voluntary benefits.
- Fitness, mindfulness, and mental health resources.
- Family planning benefits, including fertility, adoption, and surrogacy support.
- Paid vacation, volunteer days, sabbatical, global recharge days, and year-end shutdown.
- Savings and investment programs plus location-specific perks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
8 дней назад
AI Security Engineer
150 000 - 178 000$
Nscale
9 дней назад
Staff Security Engineer, Product & Platform Security (AI Infrastructure)
190 000 - 240 000$
10 дней назад
Product Security Engineer (AI)
145 300 - 244 850$
8 дней назад
Senior Staff Product Security Engineer, AI Security & Security Assurance
184 000 - 245 000$
7 дней назад
Staff Engineer - DevSecOps (AI)
148 000 - 210 500$
Jito
8 дней назад
Senior Security Engineer (AI Security)
180 000 - 200 000$