Software Engineer II - ADEX

United States Digital Space LLC

Bengaluru

Hybrid

INR 900,000 - 1,400,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Abnormal is seeking a Software Engineer II on the ADEX Team to own end-to-end detection projects, focused on impersonation detection and AI-driven capabilities. You will design, implement, and operate detection at scale with a focus on reliability and precision.

You will work with engineers, PMs, and data scientists in a highly AI-forward environment. You will analyze attack data and build reusable detection logic, including LLM-based agents, while contributing to on-call duties and cross-region

Qualifications

  • 3+ years of professional software engineering experience with production systems.
  • Strong Python programming and data-analysis skills.
  • Experience with distributed systems and scalable architectures.
  • Familiarity with AI-native development and evaluation.
  • Comfort working in on-call and incident-response scenarios.

Responsibilities

  • Design, build, and operate detection that is core to Abnormal's products, from design through rollout.
  • Own detection projects end-to-end, including ambiguity, milestones, and delivery.
  • Analyze attacks, study data, identify patterns, and translate into detection improvements.
  • Write and tune detection logic using signals; minimize false positives.
  • Build and evaluate LLM-based detection agents with rigorous measurement.
  • Surface detections as reusable intelligence for other teams.
  • Participate in on-call rotation; resolve escalations and feed learnings back into design.

Skills

Python
Data analysis
Distributed systems
CS fundamentals
AI-native development

Tools

Docker
Kubernetes
PostgreSQL
OpenSearch/Elasticsearch
Spark

Job description

About the Role

Enterprises of all sizes trust Abnormal's AI-native security products to stop cybercrime and protect critical communications, identities, and infrastructure in the cloud. Our products are data- and systems-intensive, operating at high scale and low latency across multiple clouds and regions.

As a Software Engineer II on the ADEX Team, you are a highly capable detection feature owner: you take a detection problem, come up with an idea, design a technical approach, and drive it end-to-end, from design and implementation through launch, operation, and continuous improvement. You will work with a world-class group of engineers, product managers, and data scientists to build and operate detection that is reliable, scalable, and AI-native by default.

This role focuses on impersonation detection, including brand, lookalike-domain, VIP and employee impersonation. It is ideal for an engineer who has already shipped meaningful production systems, wants more ownership and impact, and is excited to use AI to build detection that was not possible before.

About the Team

The Advanced Detection of EXtended threats (ADEX) is an attack-detection team inside Abnormal's Detection org. We own several of the highest-visibility detection surfaces at the company, spanning attachment-based attacks, fraud, and impersonation. We work the way an analyst would: we study the attacks that get through, understand the underlying pattern, and translate it into system-level detection enhancements that generalize beyond the individual attack.

We are also one of the most AI-forward teams at Abnormal. We build and operate LLM-based detection agents and treat internal AI tooling as a first-class deliverable. Every engineer here writes detection logic and builds AI agents. Impersonation is one of the most damaging and visible classes of attack we defend against, where even simple attacks that slip through erode customer trust, so this is a surface we hold to a very high bar.

What You'll Do
  • Design, build, and operate detection that is core to Abnormal's products, from initial design through rollout, monitoring, and ongoing maintenance.
  • Own detection projects end-to-end, including those that begin with a degree of ambiguity: scope loosely defined problems, identify risks, define milestones, and deliver reliably.
  • Analyze attacks that get through. Pull and study missed-attack data, read the messages the way an attacker and an analyst would, identify the underlying pattern, and translate it into detection enhancements or entirely new detection systems.
  • Write and tune detection logic using scored signals and attributes, add new signals across the pipeline, and drive changes to launch with a strong focus on minimizing false positives.
  • Build and evaluate LLM-based detection agents, and measure precision and recall rigorously with our evaluation tooling.
  • Surface your detections as reusable intelligence that other products and teams across the platform can consume.
  • Participate in the on-call rotation for your detection surfaces, debug and resolve customer escalations, and feed learnings back into design, observability, and runbooks across regions.
  • Leverage AI as a core part of your development loop for code, tests, data analysis, experiments, and documentation, while maintaining strong engineering judgment and validation practices.
  • Contribute to team health and culture by documenting heavily, sharing learnings, and giving thoughtful feedback in code and design reviews.
Must Haves
  • 3+ years of professional software engineering experience, with a track record of shipping and operating production systems.
  • Strong software engineering fundamentals: data structures, algorithms, system design basics, testing, debugging, and clean, maintainable code.
  • Strong Python proficiency and comfort learning new languages and frameworks as needed.
  • Solid data-analysis instincts. You are comfortable with SQL and reasoning over large datasets to find signals in noise.
  • A detection or adversarial mindset. You enjoy thinking like an attacker, reading real attack samples, and asking, "How would I get past this?"
  • Genuine fluency with AI-native development. You already use AI coding agents in your daily work and are excited to build LLM-powered detection, not just consume AI tools.
  • Demonstrated ability to own projects that carry some initial ambiguity: clarify and scope loosely defined requirements, make tradeoffs explicit, deliver on time, and communicate status clearly.
  • Excellent written and verbal communication, especially in remote, distributed teams. We make decisions in writing.
  • A strong growth mindset and sense of ownership.
Nice to Have Skills
  • Experience with distributed systems, high-throughput pipelines, or large-scale data stores (e.g., PostgreSQL, DynamoDB, Redis, RocksDB, Kafka, Spark, OpenSearch/Elasticsearch).
  • Background in security, threat detection, anti-abuse, fraud detection, or trust and safety, particularly systems processing high volumes of email or communication data.
  • Experience with ML or LLM evaluation: precision/recall tradeoffs, eval harnesses, prompt iteration.
  • Familiarity with domain and DNS concepts (such as typosquatting and homoglyphs) or with identity and impersonation signals.
  • Experience with large-scale data tooling (e.g., Databricks, Spark, Airflow) and distributed pipelines.
  • Experience with containerization and orchestration (Docker, Kubernetes) and infrastructure-as-code tooling.
  • Familiarity with modern frontend frameworks (e.g., React) for full-stack roles, or with ML/ML Ops for Detection/MLE-focused roles.
  • Prior experience in a fast-paced, high-growth startup environment where you’ve had to balance speed, quality, and ambiguity.
Why You'll Love It Here
  • You’ll solve hard, meaningful problems at the intersection of AI, security, and large-scale detection, where your work maps directly to attacks caught and customers protected.
  • You’ll work with smart, kind, and ambitious teammates who care deeply about detection craft, learning, and helping each other grow.
  • You’ll get real ownership and autonomy over an important detection surface, not a ticket queue, with clear opportunities to grow toward Senior and Staff roles.
  • You’ll be part of an AI-native R&D organization with strong investment in tools, workflows, and training to help engineers use AI to move faster while raising the quality bar.

#LI-AD2

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer - Message Security Detection
Senior Software Engineer - Message Security Detection

Menlo Ventures • Bengaluru

On-site
INR 3,500,000 - 7,500,000
Senior Software Engineer / Tech Lead - Message Security Detection
Senior Software Engineer / Tech Lead - Message Security Detection

United States Digital Space LLC • Bengaluru

Hybrid
INR 4,000,000 - 6,000,000
Senior Software Engineer / Tech Lead - Message Security Detection
Senior Software Engineer / Tech Lead - Message Security Detection

Abnormal AI • Bengaluru

On-site
INR 380,000 - 700,000
Senior / Principal Detection Engineer Overview
Senior / Principal Detection Engineer Overview

Blumberg Capital Company • Pune District

On-site
INR 1,500,000 - 2,000,000
Competitive compensation package including equity
Opportunity to shape autonomous cyber defense
AI Detection Engineer - SOC Analyst IV
AI Detection Engineer - SOC Analyst IV

Ten Eleven Ventures • Bengaluru

On-site
INR 2,000,000 - 3,000,000
AI Detection Engineer - SOC Analyst IV
AI Detection Engineer - SOC Analyst IV

Medium • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Software Engineer - Product Data Gateway
Senior Software Engineer - Product Data Gateway

United States Digital Space LLC • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000
Software Engineer II - Full Stack_Identity Platform
Software Engineer II - Full Stack_Identity Platform

Menlo Ventures • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Staff Software Engineer - MPP Growth
Staff Software Engineer - MPP Growth

Abnormal AI • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Software Engineer II - Full Stack_Identity Platform
Software Engineer II - Full Stack_Identity Platform

Abnormalsecurity • Bengaluru

Hybrid
INR 1,500,000 - 2,500,000