Abnormal AI

Abnormal AI

Abnormal AI provides advanced email security solutions designed to block malicious email attacks, including credential phishing, business email compromise, and account takeover.

Internet Software & Services
Founded 2018

Description

  • Lead threat modeling and security architecture reviews with engineering teams.
  • Architect, build, and maintain security tooling and integrations that support secure development workflows.
  • Collaborate with Engineering, DevOps, and Platform teams to implement security controls in Infrastructure-as-Code and secure CI/CD pipelines.
  • Design and deploy automated security testing frameworks to find vulnerabilities earlier in the development lifecycle.
  • Support security incidents by analyzing application behavior and improving response processes.
  • Mentor junior engineers on secure coding practices, security architecture, and security tooling integrations.
  • Evaluate and improve application security tooling across commercial and open-source options.
  • Define and track security posture metrics, including dashboards and reports for coverage and vulnerability trends.
  • Partner with engineering teams to implement and maintain security controls across applications and services.
  • Assess emerging AI/ML security threats for relevance and application to the business.

Requirements

  • Proven experience in application security engineering, ideally in cloud-native environments with modern development practices.
  • Hands-on experience with SAST, DAST, SCA, and IAST tools, plus security automation in CI/CD pipelines.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript.
  • Proficiency with Git, Linux, and modern development frameworks.
  • Deep knowledge of web application security, including OWASP Top 10, authentication/authorization, cryptography, and secure API design.
  • Experience with threat modeling frameworks such as STRIDE, PASTA, or LINDDUN.
  • Comfort investigating application logs, tracing security events, and supporting incident analysis workflows.
  • Ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams.
  • Strong written communication and documentation skills.
  • Experience securing microservices, containers, and cloud-native applications.
  • Preferred: experience in fast-paced or startup environments with ambiguous ownership.
  • Preferred: familiarity with AI/ML security concepts, including adversarial attacks, model security, and data privacy.
  • Preferred: hands-on experience with tools such as Veracode, Checkmarx, SonarQube, Snyk, or Burp Suite.
  • Preferred: experience building security telemetry pipelines or vulnerability management frameworks.
  • Preferred: exposure to SOC 2 or ISO 27001 compliance frameworks.
  • Preferred: familiarity with bug bounty programs and vulnerability disclosure processes.

Benefits

  • Base salary range of $130,100 to $187,000 USD.
  • Eligibility for bonus or incentive compensation.
  • Eligibility for equity.
  • Comprehensive benefits package.
  • Equal opportunity employer consideration for qualified applicants.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer II, Application Security (Remote Eligible)

Smartsheet 1K-5K Internet Software & Services

Smartsheet is hiring a Senior Security Engineer II to strengthen application security for its global SaaS platform by securing AI-integrated features, expanding security automation, and leading high-impact security reviews.

AWS Azure CI/CD GCP GitLab Go Java JavaScript LLM Penetration Testing Python Ruby TypeScript
9 hours, 19 minutes ago

Senior Application Security Engineer

e.l.f. Beauty 251-1K Consumer Goods

Senior Application Security Engineer role at a remote marketing and digital commerce company focused on securing applications across the software development lifecycle.

Agile AWS Azure CI/CD Cybersecurity DevSecOps GCP HTML JavaScript Penetration Testing Python REST API
1 day, 6 hours ago

Binance Accelerator Program - Blockchain / Smart Contract Security

Binance 5K-10K Capital Markets

Binance is seeking a Binance Accelerator Program participant to support smart contract and blockchain security work, including audits, vulnerability analysis, and risk detection across Web3 systems.

Blockchain Git Python VS Code
2 days, 10 hours ago

Senior Application Security Tester & AI Red Team Subject Matter Expert

Evolve Security Academy 11-50 Internet Software & Services

Evolve Security is seeking a senior offensive security specialist to lead complex web, API, and AI red team engagements while defining the firm’s testing methodology for LLM-enabled and agentic systems.

Bash GraphQL JavaScript JWT Metasploit Nmap OpenID Connect Penetration Testing Postman PowerShell Python REST API SAML SPA TypeScript
3 days, 19 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers