Abnormal
Senior Security Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2 days ago ยท Added yesterday
First listed 2 days ago.
Salary
$153k to $220k per year
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote - USA"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About the Role
Abnormal AI is hiring a Senior Cloud Security Engineer to build and operate the security systems that protect our FedRAMP authorized environment. You will own secure delivery pipelines, infrastructure as code security, patch automation, identity controls, security telemetry, and incident response across a growing federal platform.
You will design and build the capabilities that allow this environment to scale safely. Your work will include creating policy gates for cloud deployments, automating patch and access workflows, strengthening identity controls, improving security telemetry, and generating audit evidence directly from engineering systems. You will have meaningful ownership of both architecture and operational results, with the opportunity to replace repetitive work with reliable automation across the environment.
You will work closely with DevInfra, FedOps, Product Security, Detection and Response, and Compliance to solve cloud security problems that cross traditional team boundaries. You will also use approved AI coding tools, such as Claude Code, to accelerate scripting, testing, documentation, and security automation.
What you will do
Build and improve secure delivery workflows for applications and infrastructure deployed into the federal environment.
Create policy gates that evaluate infrastructure changes, security requirements, test results, and required approvals before deployment.
Integrate security scanning and control validation into delivery workflows so issues are identified early in the development process.
Review infrastructure as code changes that affect the federal boundary and help engineering teams resolve security risks before those changes reach production.
Design automation that produces change records, approval history, test results, and required evidence directly from engineering workflows.
Build and maintain hardened system image pipelines that consistently apply approved configurations, security controls, and operating system updates.
Automate patch deployment across the environment, including testing, scheduling, rollout, validation, exception management, and compliance reporting.
Improve fleet visibility so teams can quickly identify systems that are missing patches, running unsupported software, or operating outside approved configurations.
Design and enforce identity and access controls across a complex cloud environment.
Strengthen cloud security through organization policies, identity controls, resource policies, and automated configuration checks.
Build preventive guardrails that block insecure or unauthorized configurations before they enter the federal environment.
Own the reliability of security logging and monitoring pipelines, including ingestion coverage, data quality, source health, retention, and alerting.
Develop automated checks that identify missing telemetry, delayed events, broken integrations, and other conditions that could reduce security visibility.
Tune security detections to improve signal quality, reduce unnecessary alerts, and focus responders on activity that requires investigation.
Build response automation that gathers context, enriches alerts, preserves evidence, and accelerates investigation and containment.
Lead security incident response for the federal environment, including investigation, containment, recovery, evidence preservation, and after action reporting.
Partner with infrastructure, operations, product security, incident response, and compliance teams to solve security problems that cross team boundaries.
Must Haves
8+ years in cloud security engineering, DevSecOps, infrastructure security, or a closely related engineering discipline, including deep hands-on experience with AWS.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Abnormal, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$153k to $220k per year ยท You'll be taken to the employer's careers page.