SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 130,100 - 187,000 / annual
Abnormal AI is seeking an Application Security Engineer II to secure AI-powered systems at the core of their AWS-based platform. This individual contributor role blends deep application security expertise with strong engineering fundamentals, focusing on integrating security into every phase of the software development lifecycle.
Key responsibilities include leading threat modeling and security architecture reviews with engineering teams, with particular focus on AI-powered features like LLM integrations, agentic workflows, and MCP connectors. You will architect and maintain security tooling and integrations within CI/CD pipelines, design and deploy automated security testing to identify vulnerabilities early, and serve as a hands-on technical contributor during security incidents by analyzing application-level behavior.
You will coach developers across the organization on secure coding, security architecture, and threat modeling for AI-native systems. You'll define and track key security posture metrics, building dashboards to visualize security coverage and vulnerability trends. This role reports to the Director of Security Engineering and requires strong cross-functional collaboration with engineering, DevOps, and product teams.
Required qualifications include 5+ years of application security engineering experience, ideally in AWS or comparable cloud-native environments. You must have experience securing AI/ML-powered systems or the ability to quickly ramp on prompt injection, model supply chain, and agentic-workflow risks. Strong programming skills in Python, Go, Java, or JavaScript/TypeScript are essential—you write and read production code, not just review it.
Expertise in web application security (OWASP Top 10, authentication/authorization, cryptography, secure API design) and hands-on experience with threat modeling and security architecture reviews are required. Proven ability to influence and collaborate cross-functionally with strong written communication is critical.
Nice-to-have qualifications include experience in fast-paced startup environments, hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite), experience building security telemetry pipelines or vulnerability management frameworks, exposure to compliance frameworks (SOC 2, ISO 27001), and familiarity with bug bounty programs.