Abnormal
Application Security Engineer II
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 3 weeks ago ยท Added yesterday
Been open since 3 weeks ago, still being checked, but it has been live a while.
Salary
$130k to $187k per year
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote - USA"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About the Role
Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.
You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering.
What you will do
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors).
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.
Must Haves
5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it.
Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
Hands-on experience threat modeling and running security architecture reviews.
Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.
Nice to Have
Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
Prior experience building security telemetry pipelines or vulnerability management frameworks.
Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
Familiarity with bug bounty programs and vulnerability disclosure processes.
#LI-PP1
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Abnormal, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$130k to $187k per year ยท You'll be taken to the employer's careers page.