$158,600 – $285,500
Listed on Moderna’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
Lead the design and implementation of enterprise AI identity governance, secrets management, and endpoint execution controls across a small team of senior security engineers. This role suits experienced security architects who excel at balancing hands-on technical depth with cross-functional stakeholder management and have worked extensively with credential lifecycles and agentic AI security.
Our summary, not Moderna’s wording. The full posting is on their site.
Skills this role names
- CI/CD
- Group Policy
- HashiCorp Vault
- Infrastructure as Code
- JSON Web Token (JWT)
- Kubernetes
- Microsoft Intune
- Security Assertion Markup Language (SAML)
Log in to see which of these are already on your profile.
What they ask for
Required
- 8+ years in security engineering, identity engineering, or platform engineering with principal-level technical leadership
- Deep understanding of non-human identity patterns and programmatic credential use in modern systems
- Hands-on experience implementing credential security controls including secrets management, PKI lifecycle, token issuance, short-lived credentials, and automated rotation
- Strong knowledge of authentication and authorization concepts including OAuth 2.0, OIDC, SAML, JWT, mTLS, and key management
- Experience designing operational processes for credential inventory, ownership, attestation, and lifecycle governance at scale
- Endpoint platform knowledge across Windows and macOS including OS security primitives and device management
- Experience implementing endpoint execution controls and configuration baselines across Windows and macOS
- Familiarity and hands-on experience with modern AI platforms and developer assistants in enterprise environments
- Ability to drive complex initiatives across multiple teams balancing risk reduction, delivery timelines, and stakeholder alignment
- Experience leading and scaling delivery through direct reports, contingent workers, and professional services partners
- Strong cybersecurity fundamentals and experience designing preventive and detective control-plane architectures
Nice to have
- Experience with enterprise secrets/token platforms like HashiCorp Vault, Conjur, Azure Key Vault, or cloud equivalents
- Experience in GxP regulated environments
- Workload identity and federation patterns such as SPIFFE/SPIRE or cloud workload identity
- Familiarity with endpoint management ecosystems including Microsoft Intune, Jamf, and MDM configuration profiles
- Experience with Windows Defender Application Control and code-signing strategies at scale
- Background building security guardrails for AI and automation systems including agent tool permissioning and policy-as-code
- Experience with threat modeling and red-team/blue-team collaboration