Summary
Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of their AWS-based platform. The role involves integrating security into the software development lifecycle, conducting security reviews, and partnering with engineering teams to ensure secure coding practices.
Responsibilities
- Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors)
- Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines
- Design and deploy automated security testing to identify vulnerabilities early in the development process
- Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes
- Coach developers on secure coding, security architecture, and threat modeling for AI-native systems
- Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends
Skills
- 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices
- Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks
- Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it
- Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native)
- Hands-on experience threat modeling and running security architecture reviews
- Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication
- Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program
- Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
- Prior experience building security telemetry pipelines or vulnerability management frameworks
- Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability
- Familiarity with bug bounty programs and vulnerability disclosure processes
Qualifications
Must Haves
- 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices
- Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks
- Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it
- Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native)
- Hands-on experience threat modeling and running security architecture reviews
- Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication
Nice to Haves
- Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program
- Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
- Prior experience building security telemetry pipelines or vulnerability management frameworks
- Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability
- Familiarity with bug bounty programs and vulnerability disclosure processes
Benefits
- This role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.