Senior Security Engineer

Abnormalsecurity

United States

On-site

USD 153,000 - 220,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Abnormal AI seeks a Senior Cyber Security Engineer to own scalable security architecture in an AWS-based environment, directing AI-assisted tooling to draft and review security controls and detections. You will balance fast delivery with strong security judgment and collaborate across platform, product, and IT teams.

You will lead threat modeling, review new features for data exposure and access control, and drive scalable security controls via IaC.

Qualifications

  • Proven delivery in security engineering or infrastructure security roles.
  • Deep comprehension of native AWS architecture services and identity/access patterns (IAM, STS, cross-account roles, VPC, KMS).
  • Strong scripting and dev fundamentals in Python and/or Go; read, critique, modify AI-generated code.

Responsibilities

  • Lead threat modeling and security design discussions with platform and product teams, translating risks into engineering actions and using AI to stress-test designs against attack scenarios.
  • Review security architecture of new product features — assessing data exposure, access control, and abuse-risk before release, using AI to speed first-pass analysis.
  • Collaborate with Platform, Infra and DevOps to build scalable preventative controls in AWS via Infrastructure-as-Code using AI scaffolding for Terraform/CloudFormation; reserve time for least-privilege review and blast-radius analysis.
  • Evaluate and uplift security tooling across cloud-native and AI-assisted capabilities, focusing on scale, efficiency, and precision.
  • Mentor engineers on leveraging AI, reviewing AI-generated code and infrastructure, turning feedback into reusable playbooks.

Skills

Python
Go
AWS
Terraform
CloudFormation
Kubernetes
AI tooling
Security design
Incident response

Tools

Claude Code
Cursor
Copilot

Job description

About the Role

Abnormal AI is looking for a Senior Cyber Security Engineer to help build the next generation of security capabilities at scale. This is a senior IC-level role that blends deep security expertise with the judgment to direct AI tools effectively — you'll increasingly rely on AI to scaffold Terraform modules, prototype detection logic, and draft integrations, while you own the architecture decisions, validate what ships, and catch the failure modes AI won't flag on its own (overprivileged roles, missed edge cases, subtle logic gaps).


As a technical lead, you will own the architecture and correctness of systems that enhance both preventative guardrails and detective capabilities across our primarily AWS-based cloud environment, partnering closely with both platform engineering and product teams on security architecture reviews. You'll raise the AI leverage of the engineers around you — not by teaching scripting basics, but by turning your review judgment into reusable standards the team can build on directly. You'll act as a technical liaison across teams and contribute directly to keeping our platforms and customers secure.


This is a role for engineers who are intellectually curious and motivated to bridge security principles, engineering execution, and AI-accelerated delivery.


Who you are


  • An intellectually curious, solution-focused engineer with a security mindset who thrives in fast-paced environments

  • A technical leader who can architect scalable security solutions while maintaining engineering velocity — increasingly by directing AI to do the first draft and applying judgment to the result

  • Someone who thinks like an attacker but builds like a defender, and who treats AI-generated infrastructure and detection logic with the same scrutiny as a junior engineer's first PR

  • Someone with high agency who proactively spots what in their own workflow (and the team's) AI can absorb, and actually builds the automation to make that real — not someone waiting to be told

  • A collaborative engineer who can translate security requirements into actionable engineering tasks

  • A mentor who scales their judgment across the team — reviewing AI-generated code and infra for security gaps, and encoding what they learn into reusable playbooks and standards rather than repeating the same feedback one engineer at a time


What you will do


  • Lead threat modeling and security design discussions with both platform and product teams, translating risks into engineering actions and using AI to rapidly stress-test designs against attack scenarios before committing engineering time to a direction.

  • Partner with product engineering to review the security architecture of new product features — assessing designs for data exposure, access control, and abuse-case risk before they ship — using AI to speed up first-pass analysis so your review time goes toward the highest-risk decisions.

  • Collaborate with Platform, Infra, and DevOps teams to build scalable preventative controls in AWS via Infrastructure-as-Code — using AI coding agents to scaffold and iterate on Terraform/CloudFormation modules, reserving your own time for least-privilege review, blast-radius analysis, and edge cases.

  • Evaluate and uplift security tooling across commercial, cloud-native, and AI-assisted capabilities, focusing on scale, efficiency, and precision.

  • Mentor engineers on how to get real leverage from AI — reviewing AI-generated code and infrastructure together, and turning recurring feedback into standards and reusable playbooks instead of repeating it review after review.

  • Use AI to rapidly prototype automation for signal correlation, alert enrichment, and auto-remediation of known failure patterns, then harden and productionize what proves out rather than hand-building every workflow from a blank file.

  • Architect, build, and validate integrations between AWS and other cloud-native infrastructure and security tooling (e.g., SIEM, SOAR, IAM tooling), with a growing share of first‑draft code AI-generated and human-owned.

  • Serve as a hands‑on technical contributor during security incidents, using AI to accelerate log and telemetry triage while owning the judgment calls that determine root cause and response.

  • Build and maintain reusable AI‑assisted playbooks (for IaC security review, detection authoring, alert triage) that scale your judgment across the security and platform teams.


Must Haves


  • Proven delivery in security engineering or infrastructure security roles, ideally in cloud-native environments.

  • Deep comprehension of native AWS architecture services and identity/access patterns — IAM, STS, cross‑account roles and resource policies, VPC and network segmentation, KMS — with AWS as our primary cloud platform, plus working knowledge of Azure and GCP.

  • Strong scripting and dev fundamentals in Python and/or Go — enough to read, critique, and confidently modify AI-generated code, not just prompt for it; proficiency with Git, Linux, and infrastructure automation patterns.

  • Demonstrated fluency directing AI coding/agent tools (e.g., Claude Code, Cursor, Copilot) to accelerate delivery, paired with the judgment to catch when AI-generated infrastructure or security logic is wrong, incomplete, or dangerous.

  • Expertise in integrating or building tooling for SIEM, SOAR, vulnerability management, and CSPM platforms.

  • Experience deploying security controls via Infrastructure-as-Code (Terraform or CloudFormation), primarily in AWS.

  • Comfortable investigating logs, tracing events, and contributing to incident analysis workflows.

  • Proven ability to influence and collaborate cross‑functionally with engineering, infra, product, and IT.

  • Strong written communication and documentation skills and being able to convey complex designs clearly.

  • Background with using and securing container orchestration (Kubernetes), including workload security and service mesh controls.


Nice to Have


  • Experience working in fast‑paced or startup environments with sometimes ambiguous ownership lines.

  • Experience building or operating agentic workflows/AI tooling for security use cases (detection authoring, alert triage, IaC generation/review).

  • Familiarity with JavaScript or TypeScript, particularly in the context of DevOps tooling or plugins.

  • Hands‑on experience with commercial Cloud Security tools (CNAPP, CSPM, DSPM, KSPM)

  • Partner with cloud infrastructure teams to implement and maintain security controls across AWS accounts and services.

  • Prior experience building security telemetry pipelines or log correlation frameworks.

  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how engineering decisions affect auditability.

  • Familiarity with CI/CD systems and integrating security checks into developer workflows.


Actual compensation will be determined based on several non‑discriminatory factors including skills, experience, qualifications, and geographic location. In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.


Base salary range: $153,000 — $220,000 USD


A note on AI in our process:
Abnormal AI uses AI‑assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre‑employment checks which must be successfully completed to progress to a final offer. All processes and pre‑employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.


Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Abnormal AI, Inc. • United States

On-site
USD 153,000 - 220,000
Application Security Engineer II
Application Security Engineer II

Socket.dev • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI, Inc. • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormalsecurity • United States

On-site
USD 130,000 - 187,000
Bonus potential
Equity
Benefits package
Application Security Engineer II
Application Security Engineer II

Abnormal • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI • United States

On-site
USD 130,000 - 187,000
Senior Security Engineer, FedRAMP
Senior Security Engineer, FedRAMP

Abnormalsecurity • United States

On-site
USD 153,000 - 220,000
Bonus eligibility
Equity
Benefits package
Senior Privacy Counsel
Senior Privacy Counsel

Abnormalsecurity • United States

On-site
USD 200,000 - 235,000
Equity
Bonus eligibility
Comprehensive benefits
Senior Privacy Counsel
Senior Privacy Counsel

Abnormal AI, Inc. • United States

On-site
USD 200,000 - 235,000
Equity
Comprehensive benefits package
Senior Software Engineer - Product Engineering (Identity Security)
Senior Software Engineer - Product Engineering (Identity Security)

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 180,000 - 259,000