Senior Security Engineer

Abnormal AI

United States

On-site

USD 153,000 - 220,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus eligibility
Equity
Benefits package

Job summary

Abnormal AI is seeking a Senior Cloud Security Engineer to own the architecture and correctness of scalable security systems in our AWS-based cloud environment. You will lead threat modeling, drive security reviews with product teams, and harness AI to scaffold Terraform modules and detection logic while applying your judgment to ensure safety and correctness.

You will collaborate with Platform, Infra, and DevOps to deploy scalable preventative controls via IaC, while mentoring engineers on

Qualifications

  • Proven delivery in security engineering or infrastructure security roles.
  • Deep comprehension of native AWS architecture services and identity/access patterns.
  • Strong scripting and dev fundamentals in Python and/or Go.
  • Demonstrated fluency directing AI coding/agent tools to accelerate delivery.
  • Expertise in integrating or building tooling for SIEM, SOAR, vulnerability management, and CSPM platforms.

Responsibilities

  • Lead threat modeling and security design discussions with platform and product teams, translating risks into engineering actions.
  • Partner with product engineering to review security architecture of new features before they ship.
  • Collaborate with Platform, Infra, and DevOps to build scalable preventative controls in AWS via IaC.
  • Evaluate and uplift security tooling focusing on scale, efficiency, and precision.
  • Mentor engineers on leveraging AI to gain real leverage in security reviews.
  • Use AI to prototype automation for signal correlation, alert enrichment, and auto-remediation.
  • Architect, build, and validate integrations between AWS and other cloud-native tooling.
  • Hands-on contributor during security incidents, guiding root-cause analysis and response.
  • Build and maintain reusable AI-assisted playbooks for IaC security review and detection.

Skills

Security engineering
Cloud security
AWS security
Python
Go
AI tooling
Threat modeling
Infrastructure as Code
Incident response
Communication

Tools

Terraform
CloudFormation
SIEM
SOAR
Kubernetes
Git
CI/CD tooling

Job description

About The Role

Abnormal AI is looking for a Senior Cloud Security Engineer to help build the next generation of security capabilities at scale. This is a senior IC-level role that blends deep security expertise with the judgment to direct AI tools effectively – you'll increasingly rely on AI to scaffold Terraform modules, prototype detection logic, and draft integrations, while you own the architecture decisions, validate what ships, and catch the failure modes AI won’t flag on its own (overprivileged roles, missed edge cases, subtle logic gaps). As a technical lead, you will own the architecture and correctness of systems that enhance both preventative guardrails and detective capabilities across our primarily AWS-based cloud environment, partnering closely with both platform engineering and product teams on security architecture reviews. You’ll raise the AI leverage of the engineers around you – not by teaching scripting basics, but by turning your review judgment into reusable standards the team can build on directly. You’ll act as a technical liaison across teams and contribute directly to keeping our platforms and customers secure.

Who you are
  • An intellectually curious, solution-focused engineer with a security mindset who thrives in fast-paced environments
  • A technical leader who can architect scalable security solutions while maintaining engineering velocity – increasingly by directing AI to do the first draft and applying judgment to the result
  • Someone who thinks like an attacker but builds like a defender, and who treats AI-generated infrastructure and detection logic with the same scrutiny as a junior engineer's first PR
  • Someone with high agency who proactively spots what in their own workflow (and the team's) AI can absorb, and actually builds the automation to make that real – not someone waiting to be told
  • A collaborative engineer who can translate security requirements into actionable engineering tasks
  • A mentor who scales their judgment across the team – reviewing AI-generated code and infra for security gaps, and encoding what they learn into reusable playbooks and standards rather than repeating the same feedback one engineer at a time
What you will do
  • Lead threat modeling and security design discussions with both platform and product teams, translating risks into engineering actions and using AI to rapidly stress-test designs against attack scenarios before committing engineering time to a direction
  • Partner with product engineering to review the security architecture of new product features – assessing designs for data exposure, access control, and abuse-case risk before they ship – using AI to speed up first-pass analysis so your review time goes toward the highest-risk decisions
  • Collaborate with Platform, Infra, and DevOps teams to build scalable preventative controls in AWS via Infrastructure-as-Code – using AI coding agents to scaffold and iterate on Terraform/CloudFormation modules, reserving your own time for least-privilege review, blast-radius analysis, and edge cases
  • Evaluate and uplift security tooling across commercial, cloud-native, and AI-assisted capabilities, focusing on scale, efficiency, and precision
  • Mentor engineers on how to get real leverage from AI – reviewing AI-generated code and infrastructure together, and turning recurring feedback into standards and reusable playbooks instead of repeating it review after review
  • Use AI to rapidly prototype automation for signal correlation, alert enrichment, and auto-remediation of known failure patterns, then harden and productionize what proves out rather than hand-building every workflow from a blank file
  • Architect, build, and validate integrations between AWS and other cloud-native infrastructure and security tooling (e.g., SIEM, SOAR, IAM tooling), with a growing share of first-draft code AI-generated and human-owned
  • Serve as a hands-on technical contributor during security incidents, using AI to accelerate log and telemetry triage while owning the judgment calls that determine root cause and response
  • Build and maintain reusable AI-assisted playbooks (for IaC security review, detection authoring, alert triage) that scale your judgment across the security and platform teams
Must Haves
  • Proven delivery in security engineering or infrastructure security roles, ideally in cloud-native environments
  • Deep comprehension of native AWS architecture services and identity/access patterns – IAM, STS, cross-account roles and resource policies, VPC and network segmentation, KMS – with AWS as our primary cloud platform, plus working knowledge of Azure and GCP
  • Strong scripting and dev fundamentals in Python and/or Go – enough to read, critique, and confidently modify AI-generated code, not just prompt for it; proficiency with Git, Linux, and infrastructure automation patterns
  • Demonstrated fluency directing AI coding/agent tools (e.g., Claude Code, Cursor, Copilot) to accelerate delivery, paired with the judgment to catch when AI-generated infrastructure or security logic is wrong, incomplete, or dangerous
  • Expertise in integrating or building tooling for SIEM, SOAR, vulnerability management, and CSPM platforms
  • Experience deploying security controls via Infrastructure-as-Code (Terraform or CloudFormation), primarily in AWS
  • Comfortable investigating logs, tracing events, and contributing to incident analysis workflows
  • Proven ability to influence and collaborate cross-functionally with engineering, infra, product, and IT
  • Strong written communication and documentation skills, with the ability to convey complex designs clearly
  • Background with using and securing container orchestration (Kubernetes), including workload security and service mesh controls
Nice to Have
  • Experience working in fast-paced or startup environments with sometimes ambiguous ownership lines
  • Experience building or operating agentic workflows/AI tooling for security use cases (detection authoring, alert triage, IaC generation/review)
  • Familiarity with JavaScript or TypeScript, particularly in the context of DevOps tooling or plugins
  • Hands-on experience with commercial Cloud Security tools (CNAPP, CSPM, DSPM, KSPM)
  • Partner with cloud infrastructure teams to implement and maintain security controls across AWS accounts and services
  • Prior experience building security telemetry pipelines or log correlation frameworks
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how engineering decisions affect auditability
  • Familiarity with CI/CD systems and integrating security checks into developer workflows
Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.

In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:

$153,000—$220,000 USD

A note on AI in our process:

Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EOO rights under the law, please click here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Abnormal AI, Inc. • United States

On-site
USD 153,000 - 220,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Socket.dev • United States

On-site
USD 153,000 - 220,000
bonus or incentive compensation
Equity
Comprehensive benefits
Senior Security Engineer
Senior Security Engineer

Abnormalsecurity • United States

On-site
USD 153,000 - 220,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Socket.dev • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI, Inc. • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormalsecurity • United States

On-site
USD 130,000 - 187,000
Bonus potential
Equity
Benefits package
Application Security Engineer II
Application Security Engineer II

Abnormal • United States

On-site
USD 130,000 - 187,000
Senior Security Engineer, FedRAMP
Senior Security Engineer, FedRAMP

Abnormalsecurity • United States

On-site
USD 153,000 - 220,000
Bonus eligibility
Equity
Benefits package
Software Engineer II - Dev Accelerator
Software Engineer II - Dev Accelerator

Abnormal Security • United States

On-site
USD 149,000 - 215,000