Skip to content
NEXTMOVEFDE careers · United States

Lead Cloud Security/AppSec Engineer

AI summary of the role

Greenfield opportunity to build Flagship Pioneering's cloud security and AppSec engineering practice from scratch, owning cloud posture management, SSDLC security, and cloud-side DLP across the company and its portfolio.

What you’ll do

  • Own cloud security posture management: remediate Wiz findings, build shared playbooks, and coordinate resolution across AWS environments in partnership with Infrastructure & Operations.
  • Design and implement CI/CD and SSDLC security guardrails (SAST, secrets scanning, IaC security, container scanning) and build AI-powered pipeline security automation.
  • Build and operationalize cloud-side DLP controls at the cloud and application layer.
  • Own technical execution on Entra/Azure AD conditional access, BYOD policy enforcement, and cloud identity governance.

What you’ll bring

  • 5+ years in cloud security, application security, or closely related security engineering discipline.
  • Deep hands-on experience with AWS security services (Security Hub, GuardDuty, IAM, SCPs, CloudTrail) and cloud posture tooling (Wiz strongly preferred).
  • Practical AppSec experience integrating SAST/DAST/SCA tooling into CI/CD pipelines and working directly with developers.
  • Experience with cloud identity platforms (Entra ID / Azure AD) including conditional access policy design and enforcement.

Technologies

AWS · Wiz · SAST · DAST · SCA · Entra ID · Azure AD · Python · Terraform · LLM · Kubernetes · EKS

About Flagship Pioneering

Bioplatform innovation firm that invents, funds, and scales life-sciences companies in-house across therapeutics, preemptive health, sustainability, and AI-enabled biology.

Private Late · 500–1000 people

Source and classification

Internal deployment & tooling · Evidence for this classification:

Engineering as your strategic partners and a well-resourced program behind you. You’ll define how cloud posture management, SSDLC security, and cloud-side DLP get done at Flagship — in deep partnership with the Infrastructure & Operations team, who are your primary counterparts for cloud architecture, network, and endpoint infrastructure. What makes this role distinctive is the expectation that you’ll build AI-augmented workflows from the start — using LLMs and agentic tooling to handle the routine 80% so your expertise stays focused on the 20% that actually requires human judgment. If you want to own a practice area rather than execute someone else’s playbook, this is that role. You'll own the technical execution of cloud security and AppSec across Flagship and its portfolio, working directly with engineering teams to embed security into their pipelines, not just review them after the
More from the job description

Who We Are Flagship Pioneering is a biotechnology company that invents and builds platform companies that change the world. We bring together the greatest scientific minds with entrepreneurial company builders and assemble the capital to allow them to take courageous leaps. Those big leaps in human health and sustainability exponentially accelerate scientific progress in areas ranging from cancer detection and treatment to nature-positive agriculture. What sets Flagship apart is our ability to advance biotechnology by uniting life science innovation, company creation, and capital investment under one roof in a way that is largely without precedent. Our scientific founders, entrepreneurial leaders, and professional capital managers are each aligned around an institutionalized process that enables us to innovate and transform for the benefit of people and planet. Many of the companies Flagship has founded have addressed humanity’s most urgent challenges: vaccinating billions of people against COVID-19, curing intractable diseases, improving human health, preempting illness, and feeding the world by improving the resiliency and sustainability of agriculture. Flagship has been recognized twice on FORTUNE’s “Change the World” list, an annual ranking of companies that have made a positive social and environmental impact through activities that are part of their core business stra [... source excerpt omitted ...] o your expertise stays focused on the 20% that actually requires human judgment. If you want to own a practice area rather than execute someone else’s playbook, this is that role. You'll own the technical execution of cloud security and AppSec across Flagship and its portfolio, working directly with engineering teams to embed security into their pipelines, not just review them after the fact. What You'll Own Cloud security posture management: own remediation execution against Wiz findings in close partnership with Infrastructure & Operations — building shared remediation playbooks, coordinating finding resolution across AWS environments, and ensuring security controls are imp [... source excerpt omitted ...] aborator throughout it Design and maintain AI-augmented workflows across all functional areas you own — using LLMs, agentic tooling, and automation to multiply your own capacity. You'll be expected to treat AI as a core part of your engineering toolkit, not an experiment: building prompt-driven triage pipelines, automating remediation drafting, and continuously identifying where human judgment is the bottleneck versus where it's being wasted on pattern-matchable work. What We're Looking For 5+ years in cloud security, application security, or a closely related security engineering discipline Deep hands-on experience with AWS security services (Security Hub, GuardDuty, IAM,

How jobs are selected

Employer postings · Data from · Sources