Himalayas logo
Abnormal SecurityAS

Senior Application Security Engineer

Abnormal Security is an AI-native email security platform that uses behavioral data science to protect enterprises from the widest range of email attacks.

Abnormal Security

Employee count: 501-1000

Salary: 145k-170k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About the Role

Abnormal AI is looking for a Senior Application Security Engineer to help build the next generation of secure AI-powered cybersecurity applications at scale. This is a senior IC-level role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.

As a technical leader, you will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll mentor junior engineers, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure.

This is a role for engineers who are intellectually curious and motivated to bridge the gap between security principles and application development execution.

Who you are:

  • An intellectually curious, solution-focused engineer with a security mindset who thrives in fast-paced environments
  • A technical leader who can architect secure application solutions while maintaining engineering velocity
  • Someone who thinks like an attacker but builds like a defender - understanding both offensive and defensive security principles
  • A collaborative engineer who can translate security requirements into actionable development tasks
  • A mentor who enjoys teaching secure coding practices and security architecture to junior engineers

What you will do

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into development actions.
  • Architect, build, and maintain security tooling and integrations that enable secure development workflows (e.g., SAST, DAST, SCA, IAST tools).
  • Collaborate with Engineering, DevOps, and Platform teams to build scalable security controls via Infrastructure-as-Code and secure CI/CD pipelines.
  • Design and deploy automated security testing frameworks to identify vulnerabilities early in the development process.
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
  • Mentor and support junior engineers on secure coding practices, security architecture, and security tooling integrations.
  • Evaluate and uplift application security tooling across commercial and open-source capabilities by focusing on scale, efficiency, and precision.
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.
  • Partner with engineering teams to implement and maintain security controls across applications and services.
  • Stay current with emerging AI/ML security threats, evaluating them for business applicability and integration.

Must Haves

  • Proven delivery in application security engineering roles, ideally in cloud-native environments with modern development practices.
  • Hands-on experience with security testing tools (SAST, DAST, SCA, IAST) and working knowledge of security automation in CI/CD pipelines.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript; proficiency with Git, Linux, and modern development frameworks.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design.
  • Experience with threat modeling frameworks (STRIDE, PASTA, LINDDUN) and security architecture review processes.
  • Comfortable investigating application logs, tracing security events, and contributing to incident analysis workflows.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams.
  • Strong written communication and documentation skills and being able to convey complex security concepts clearly.
  • Background with securing modern application architectures including microservices, containers, and cloud-native applications.

Nice to Have

  • Experience working in fast-paced or startup environments with sometimes ambiguous ownership lines.
  • Familiarity with AI/ML security concepts including adversarial attacks, model security, and data privacy considerations.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Snyk, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.

At Abnormal AI, certain roles are eligible for a bonus, restricted stock units (RSUs), and benefits. Individual compensation packages are based on factors unique to each candidate, including their skills, experience, qualifications and other job-related reasons.

Base salary range:
$144,500$170,000 USD

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Salary

Salary: 145k-170k USD

Location requirements

Hiring timezones

United States +/- 0 hours

About Abnormal Security

Learn more about Abnormal Security and their company culture.

View company profile

At Abnormal Security, we are at the forefront of cybersecurity innovation, pioneering a revolutionary approach to protect the modern enterprise from the most sophisticated and damaging email attacks. Through our groundbreaking, AI-native human behavior security platform, we are fundamentally transforming how organizations defend against threats that exploit human vulnerability. Our core technology leverages advanced machine learning and behavioral data science to create a precise, identity-based understanding of every individual within and outside an organization. This allows us to detect subtle anomalies in communication patterns, relationships, and business processes that signal a potential attack, stopping threats that traditional security solutions miss. We are not just building another security product; we are engineering a new paradigm of defense that is autonomous, adaptive, and capable of anticipating and neutralizing never-before-seen attacks in real-time.

Our commitment to innovation extends beyond our core detection engine. We are building a comprehensive security platform that provides complete protection across the entire cloud email environment. This includes inbound email security to block phishing, malware, and social engineering attacks; robust protection against internal and external account takeovers; and full security operations center (SOC) automation to streamline threat response and reduce manual effort. By integrating seamlessly with major cloud platforms like Microsoft 365 and Google Workspace via a simple API, we provide immediate value without disrupting email flow. The team at Abnormal Security is composed of industry veterans and bright minds from leading technology companies like Google, Twitter, and Amazon, all driven by a shared passion for solving the most critical challenges in cybersecurity. We are dedicated to building a future where organizations can operate securely and confidently in an increasingly complex digital world, empowered by the intelligence and autonomy of our AI-driven platform.

Employee benefits

Learn about the employee benefits and perks provided at Abnormal Security.

View benefits

Mental Health Resources

Access to mental health resources.

401K

Abnormal Security offers a 401K plan.

Virtual lunch budget

Monthly virtual lunch budget for employees.

Flexible PTO

All regular salaried team members enjoy unlimited PTO.

View Abnormal Security's employee benefits
Claim this profileAbnormal Security logoAS

Abnormal Security

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

16 remote jobs at Abnormal Security

Explore the variety of open remote roles at Abnormal Security, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Abnormal Security

Remote companies like Abnormal Security

Find your next opportunity by exploring profiles of companies that are similar to Abnormal Security. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Abnormal Security hiring Senior Application Security Engineer • Remote (Work from Home) | Himalayas