Application Security Engineer II

Abnormal AI, Inc.
Las Vegas, NV, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$130,100.0 - $187,000.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Artificial Intelligence Amazon Web Services Architectural Patterns Burp Suite Cloud Computing Cyber Security Computer Programming DevOps Python (Programming Language) Open Web Application Security
+14 more
Secure Coding Web Application Security Software Engineering SonarQube Systems Integration TypeScript Software Vulnerability Management Large Language Models Software Security Veracode Production Code Checkmarx Golang Microservices

Job description

Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You’ll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.

You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You’ll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering. What you will do

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors).
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends., Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and identify areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person.

Requirements

  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
  • Hands-on experience threat modeling and running security architecture reviews.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.

Nice to Have

  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.

Benefits & conditions

Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location. In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package. Base salary range: $130,100-$187,000 USD

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:15 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Niels Tanis Niels Tanis · WWC 2024

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

2:41 min

Dynamic application security testing during the test phase

Milecia Mcgregor · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all