Moderna is a pioneering company revolutionizing medicine through mRNA technology. They are seeking a Senior Security Data Engineer for Vulnerability Risk Management to enhance and scale data products that support risk modeling and executive visibility, while ensuring high-quality data processing and operational reporting.
Responsibilities:
- Design, build, and operate reliable ingestion pipelines for asset, vulnerability, finding, remediation, threat intelligence, and business-context data sources
- Build reusable ingestion patterns that can absorb new sources without brittle, one-off logic
- Support batch and incremental processing patterns from raw source capture through normalized, model-ready data products
- Partner with source-system owners to clarify schema changes, source freshness, field semantics, and operational constraints
- Own transformations from raw evidence into normalized security entities such as assets, vulnerabilities, findings, owners, exposure context, risk-reduction actions, and validation states
- Engineer model-ready features that encode asset ownership, exposure, business importance, exploitability, remediation state, and organizational context
- Support risk model outputs and operational reporting datasets used by remediation owners and leadership
- Model ownership and accountability signals across code, artifacts, platforms, infrastructure, and application contexts to reduce ambiguity in remediation routing
- Make pragmatic normalization decisions for messy, heterogeneous data while documenting assumptions, confidence, and tradeoffs
- Adapt vulnerability detection and triage data flows to support increasing AI-driven finding volume without losing ownership, severity, or remediation context
- Build data foundations for scanning workflows across code repositories, build artifacts, deployed platforms, and runtime environments
- Connect vulnerability signals to remediation workflow needs, including owner routing, action state, validation evidence, exception paths, and closure reporting
- Partner with security, engineering, and platform teams to unify how findings are represented from discovery through remediation
- Implement data quality checks for schema validity, completeness, freshness, duplication, drift, and unexpected distribution changes
- Maintain lineage documentation so risk scores, reports, and owner views can be traced back to source inputs
- Build monitoring, alerting, and runbooks for data pipeline reliability and source degradation
- Partner with downstream users to resolve data defects and improve trust in pipeline outputs
- Prepare reliable, pre-aggregated data products for dashboards, operational views, risk reporting, and experimentation
- Collaborate with partners to translate new questions into durable data features
- Improve data contracts, documentation, and self-service access patterns for technical and non-technical stakeholders
- Continuously refine feature hypotheses and data products as the vulnerability risk model and remediation operating model mature
Requirements:
- 5+ years of experience in data engineering, analytics engineering, security data engineering, or related technical disciplines
- Strong hands-on proficiency with Python and SQL in production data pipeline environments
- Experience designing, building, and operating ETL/ELT pipelines across heterogeneous source systems
- Experience with data modeling, schema evolution, incremental processing, and data quality controls
- Ability to work with messy, incomplete, or inconsistent datasets and make pragmatic normalization decisions
- Experience supporting data products from source ingestion through reporting, analytics, model inputs, or decision-support outputs
- Experience designing data models that support ownership routing, triage, workflow state, or operational decision-making
- Strong analytical, troubleshooting, documentation, and communication skills
- Experience with medallion, lakehouse, or data-product architecture patterns
- Experience engineering features for probabilistic, predictive, prioritization, or risk models
- Experience in regulated environments such as biotech, pharmaceutical, healthcare, GxP, SOX, or similar control environments
- Exposure to cybersecurity, vulnerability management, threat intelligence, security operations, or security data platforms
- Exposure to application security, software supply chain security, shift-left scanning, artifact security, platform security, or unified remediation workflows
- Experience building lineage, observability, monitoring, and operational runbooks for critical data pipelines
- Familiarity with orchestration, data catalog, data contract, business intelligence, or operational reporting patterns
- Exposure to AI/Agentic/LLM-assisted coding tools