Senior Security Engineer, FedRAMP

Abnormalsecurity

United States

On-site

USD 153,000 - 220,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus eligibility
Equity
Benefits package

Job summary

Abnormal AI is seeking a Senior Security Engineer to ensure our FedRAMP environment operates securely, resiliently, and efficiently. You will own and improve technical workflows across CI/CD pipelines, IaC reviews, and incident response to support compliant Gov systems at scale.

The role requires 5–7 years in security engineering or infrastructure operations in regulated cloud environments, with strong NIST 800-53, AWS/SaaS security, and IAM expertise.

Qualifications

  • 5-7 years in security engineering or infrastructure operations within federal or regulated cloud environments.
  • Strong familiarity with NIST 800-53 controls and continuous monitoring practices.
  • Proven delivery of AWS/SaaS security best practices.
  • Hands-on expertise with CI/CD, infrastructure automation, and IaC security practices.
  • Experience in patch management, hardened baselines, and secure image pipelines.
  • Strong knowledge of identity and access management (IAM) design and enforcement in large-scale environments.
  • Proven ability to manage SIEM pipelines and lead Tier 1 / Tier 2 incident response.
  • Strong technical documentation, collaboration, and incident/project management skills.

Responsibilities

  • Maintain and improve CI/CD pipelines to support secure deployments and infrastructure workflows.
  • Manage infrastructure‑as‑code (IaC) PR and Change Control Board reviews, ensuring changes are tested, approved, and secure before release.
  • Perform security impact analyses (SIAs) for system/application changes and provide recommendations.
  • Run OS and infrastructure patch cycles; manage hardened images and patch workflows for FedRAMP environments.
  • Govern access management, including account provisioning, RBAC module maintenance, and periodic reviews.
  • Manage logging and monitoring pipelines; tune SIEM ingestion and alerting for coverage and accuracy.
  • Triage and respond to security incidents, from alert investigation through containment, recovery, and after‑action reporting.
  • Maintain and refine runbooks, SOPs, and documentation to ensure consistent operations and audit readiness.
  • Collaborate with DevInfra, FedOps, Product, and Compliance teams to embed secure practices into operations and development.

Skills

CI/CD pipelines
IaC security
IAM design
FedRAMP/compliance
AWS security
SIEM management
Incident response
Security automation

Tools

AWS
Terraform
Containers

Job description

About the Role

Abnormal AI is seeking a Senior Security Engineer to ensure Abnormal’s FedRAMP environment operates securely, resiliently, and efficiently. This role focuses on security operations engineering, with responsibilities spanning CI/CD pipelines, access management, patch management, change reviews, incident response, and security automation. The engineer will directly own and improve the technical workflows that keep Abnormal Gov systems compliant and resilient at scale. The ideal candidate combines deep cloud and infrastructure security expertise with operational discipline, and is AI‑enabled to maximize efficiency and reduce overhead.

What you will do
  • Maintain and improve CI/CD pipelines to support secure deployments and infrastructure workflows.
  • Manage infrastructure‑as‑code (IaC) PR and Change Control Board reviews, ensuring changes are tested, approved, and secure before release.
  • Perform security impact analyses (SIAs) for system/application changes and provide recommendations.
  • Run OS and infrastructure patch cycles; manage hardened images and patch workflows for FedRAMP environments.
  • Govern access management, including account provisioning, RBAC module maintenance, and periodic reviews.
  • Manage logging and monitoring pipelines; tune SIEM ingestion and alerting for coverage and accuracy.
  • Triage and respond to security incidents, from alert investigation through containment, recovery, and after‑action reporting.
  • Maintain and refine runbooks, SOPs, and documentation to ensure consistent operations and audit readiness.
  • Collaborate with DevInfra, FedOps, Product, and Compliance teams to embed secure practices into operations and development.
Must Haves
  • 5 - 7 years in security engineering or infrastructure operations within federal or regulated cloud environments.
  • Strong familiarity with NIST 800-53 controls and continuous monitoring practices.
  • Proven delivery of AWS/SaaS security best practices.
  • Hands‑on expertise with CI/CD, infrastructure automation, and IaC security practices.
  • Experience in patch management, hardened baselines, and secure image pipelines.
  • Strong knowledge of identity and access management (IAM) design and enforcement in large‑scale environments.
  • Proven ability to manage SIEM pipelines and lead Tier 1 / Tier 2 incident response.
  • Strong technical documentation, collaboration, and incident/project management skills.
Nice to Have
  • Experience integrating security automation into CI/CD pipelines and SecOps workflows.
  • Prior experience supporting federal audits or 3PAO engagements.
  • Knowledge of SaaS security operations and monitoring at scale.
  • Experience driving automation in security operations, compliance tracking, and evidence management.
  • Knowledge of SaaS security operations and modern cloud environments; exposure to DevSecOps pipelines or security reviews for Terraform/containers.

Base salary range: $153,000—$220,000 USD

Actual compensation will be determined based on several non‑discriminatory factors including skills, experience, qualifications, and geographic location. In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

AI and our hiring process

Abnormal AI uses AI‑assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and identify areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer, FedRAMP
Senior Security Engineer, FedRAMP

Abnormal AI, Inc. • United States

On-site
USD 153,000 - 220,000
Bonus potential
Equity compensation
Comprehensive benefits package
Senior Security Engineer, FedRAMP
Senior Security Engineer, FedRAMP

Menlo Ventures • United States

On-site
USD 153,000 - 220,000
Senior Security Engineer
Senior Security Engineer

Abnormal AI, Inc. • United States

On-site
USD 153,000 - 220,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Socket.dev • United States

On-site
USD 153,000 - 220,000
bonus or incentive compensation
Equity
Comprehensive benefits
Senior Security Engineer
Senior Security Engineer

Abnormalsecurity • United States

On-site
USD 153,000 - 220,000
Senior Security Engineer
Senior Security Engineer

Abnormal AI • United States

On-site
USD 153,000 - 220,000
Bonus eligibility
Equity
Benefits package
Senior Software Engineer - Platform Engineering - Federal Operations
Senior Software Engineer - Platform Engineering - Federal Operations

Abnormalsecurity • United States

On-site
USD 179,800 - 258,500
Comprehensive benefits package
Bonus or incentive compensation
Equity
Software Engineer I - Federated Intelligence Platform
Software Engineer I - Federated Intelligence Platform

Abnormal • United States

On-site
USD 90,000 - 140,000
Application Security Engineer II
Application Security Engineer II

Socket.dev • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI • United States

On-site
USD 130,000 - 187,000