Application Security Engineer II

Abnormal

United States

On-site

USD 130,000 - 187,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Abnormal AI is seeking an Application Security Engineer II to secure our AWS-based platform with AI-powered features, agentic workflows, MCP connectors, and the model supply chain. This role blends deep security expertise with strong engineering fundamentals, focusing on integrating security into the SDLC and conducting comprehensive security reviews.

You will own security architecture, coach developers on secure coding, and collaborate across teams, reporting to the Director of Security

Qualifications

  • 5+ years of application security engineering experience (AWS/cloud-native).
  • Experience securing AI/ML-powered systems or ramping on prompt-injection and model supply chain risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript.
  • Web application security expertise including OWASP Top 10, auth, cryptography, API security, microservices and containers.
  • Hands-on threat modeling and security-architecture review experience.
  • Ability to influence and collaborate across engineering, DevOps, and product teams with strong written communication.

Responsibilities

  • Lead threat modeling and security architecture reviews for AI-powered features.
  • Architect, build, and maintain security tooling integrated into CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early.
  • Contribute hands-on during security incidents and improve response processes.
  • Coach developers on secure coding and threat modeling for AI-native systems.
  • Define and track security posture metrics with dashboards and reports.

Skills

5+ years security experience
AWS security
Python
Go
Java
JavaScript/TypeScript
OWASP Top 10
Threat modeling
Cross-functional collaboration

Tools

Veracode
Burp Suite
SonarQube
Semgrep

Job description

About the Role

Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.

You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering.

What you will do
  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors).
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.
Must Haves
  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
  • Hands-on experience threat modeling and running security architecture reviews.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.
Nice to Have
  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.

#LI-PP1

Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.

  • In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range: $130,100 - $187,000 USD

AI and our hiring process
Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and identify areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer II
Application Security Engineer II

Abnormalsecurity • United States

On-site
USD 130,000 - 187,000
Bonus potential
Equity
Benefits package
Application Security Engineer II
Application Security Engineer II

Socket.dev • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI, Inc. • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI • United States

On-site
USD 130,000 - 187,000
Staff Software Engineer, Security & Privacy
Staff Software Engineer, Security & Privacy

Menlo Ventures • United States

On-site
USD 210,000 - 303,000
Software Engineer II, Model Platform
Software Engineer II, Model Platform

Abnormal • United States

On-site
USD 149,000 - 215,000
Bonus or incentive compensation
Equity
Comprehensive benefits package
Application Security Engineer
Application Security Engineer

Pantera Capital • Palo Alto (CA)

On-site
USD 100,000 - 258,000
Equity
Medical coverage
401(k)
Software Engineer II, Model Platform
Software Engineer II, Model Platform

Abnormal AI • United States

On-site
USD 149,000 - 215,000
Senior Software Engineer, Adaptive Classification Team
Senior Software Engineer, Adaptive Classification Team

Abnormalsecurity • United States

On-site
USD 179,000 - 259,000
Staff Software Engineer, Security & Privacy
Staff Software Engineer, Security & Privacy

Abnormalsecurity • United States

On-site
USD 210,000 - 303,000
Comprehensive benefits package
Bonus or incentive compensation
Equity options