Abnormal AI logo
Abnormal AI
Posted 14 days agoVerified live 4h ago

Application Security Engineer II

Brief overview

Remote
UndergradOr in progress
$130k–$187k/yrStated range
5+ yrsMinimum
39 H-1B approvalsDept. of Labor
12 green cardsCertified filings
Application SecurityAWSAI/ML SecurityPythonGoJavaJavaScript/TypeScriptWeb Application SecurityOWASP Top 10Authentication and AuthorizationCryptographySecure API DesignThreat ModelingSecurity Architecture Reviews

About the company

Abnormal AI logo
Abnormal AIabnormal.ai

Abnormal AI is the leading AI-native human behavior security platform.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
39H-1B approved
100%approval rate
9new H-1B hires
12PERM certified
$170,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
202312
202413
202512
20262
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20236
20249
20253
20263
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20233
20244
20255
Top sponsored roles
Software EngineerSenior Software EngineerMachine Learning EngineerSenior Machine Learning EngineerStaff Software Engineer
Sponsored employees from
IndiaChinaTaiwan

Job description

Summary

Abnormal AI is an AI security company seeking an Application Security Engineer II to secure the AI-powered systems at the core of its AWS-based platform. The role focuses on threat modeling, security architecture reviews, secure development tooling, automated security testing, incident response, developer coaching, and security posture metrics.

Responsibilities

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors)
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines
  • Design and deploy automated security testing to identify vulnerabilities early in the development process
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends

Skills

  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native)
  • Hands-on experience threat modeling and running security architecture reviews
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication
  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability
  • Familiarity with bug bounty programs and vulnerability disclosure processes

Qualifications

Must Haves

  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native)
  • Hands-on experience threat modeling and running security architecture reviews
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication

Nice to Haves

  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability
  • Familiarity with bug bounty programs and vulnerability disclosure processes

Benefits

  • This role may be eligible for bonus or incentive compensation
  • This role may be eligible for equity
  • A comprehensive benefits package

More jobs like this