Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Lead Cloud Security/AppSec Engineer

Flagship Pioneering, Inc.
CompanyFlagship Pioneering, Inc.
CategoryEngineering
LocationCambridge
RemoteOn-site (inferred)
EmploymentNot stated
LevelLead
SalaryNot stated by the employer
Posted16 Apr 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Who We Are Flagship Pioneering is a biotechnology company that invents and builds platform companies that change the world. We bring together the greatest scientific minds with entrepreneurial company builders and assemble the capital to allow them to take courageous leaps. Those big leaps in human health and sustainability exponentially accelerate scientific progress in areas ranging from cancer detection and treatment to nature-positive agriculture.   What sets Flagship apart is our ability to advance biotechnology by uniting life science innovation, company creation, and capital investment under one roof in a way that is largely without precedent. Our scientific founders, entrepreneurial leaders, and professional capital managers are each aligned around an institutionalized process that enables us to innovate and transform for the benefit of people and planet.   Many of the companies Flagship has founded have addressed humanity’s most urgent challenges: vaccinating billions of people against COVID-19, curing intractable diseases, improving human health, preempting illness, and feeding the world by improving the resiliency and sustainability of agriculture.  Flagship has been recognized twice on FORTUNE’s “Change the World” list, an annual ranking of companies that have made a positive social and environmental impact through activities that are part of their core business strategies, and has been twice named to Fast Company’s annual list of the World’s Most Innovative Companies. About the Role The Information Security team has strong detection and response capability and a maturing compliance program. This is a greenfield opportunity to build Flagship’s cloud security and application security engineering practice in earnest — with the CISO and Director of Security Engineering as your strategic partners and a well-resourced program behind you. You’ll define how cloud posture management, SSDLC security, and cloud-side DLP get done at Flagship — in deep partnership with the Infrastructure & Operations team, who are your primary counterparts for cloud architecture, network, and endpoint infrastructure. What makes this role distinctive is the expectation that you’ll build AI-augmented workflows from the start — using LLMs and agentic tooling to handle the routine 80% so your expertise stays focused on the 20% that actually requires human judgment. If you want to own a practice area rather than execute someone else’s playbook, this is that role. You'll own the technical execution of cloud security and AppSec across Flagship and its portfolio, working directly with engineering teams to embed security into their pipelines, not just review them after the fact. What You'll Own Cloud security posture management: own remediation execution against Wiz findings in close partnership with Infrastructure & Operations — building shared remediation playbooks, coordinating finding resolution across AWS environments, and ensuring security controls are implemented consistently with I&O’s infrastructure standards CI/CD and SSDLC security: design and implement security guardrails in engineering pipelines — SAST, secrets scanning, IaC security, container scanning — working directly with portfolio engineering teams, and building AI-powered pipeline security automation (e.g., LLM-assisted code review, automated fix suggestions for SAST findings) that reduces developer friction and scales security coverage beyond what manual review allows Cloud-side DLP enforcement: build and operationalize data loss prevention controls at the cloud and application layer, not just policy definition Cloud identity and access: own technical execution on Entra/Azure AD conditional access, BYOD policy enforcement, and cloud identity governance in partnership with Infrastructure & Operations, who manage the underlying directory and endpoint infrastructure Detection engi
HOUSE ADYou found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →
Lead Cloud Security/AppSec Engineer — Flagship Pioneering, Inc. · Job Opportunities API