SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer

Abnormal AI - Remote - Remote - posted 2026-08-20

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Abnormal AI is hiring a Senior Security Engineer to architect and lead the next generation of cloud security capabilities, with a strong emphasis on leveraging AI tools to accelerate delivery while maintaining rigorous security judgment. In this senior individual contributor role, you will own the architecture and correctness of preventative and detective security systems across a primarily AWS-based cloud environment. You'll partner closely with platform engineering and product teams on security architecture reviews, threat modeling, and design validation. A core part of the role is directing AI coding agents (Claude Code, Cursor, Copilot) to scaffold Terraform modules, prototype detection logic, and draft integrations—while you own the final validation, catch failure modes AI misses (overprivileged roles, edge cases, logic gaps), and encode your judgment into reusable standards. Key responsibilities include: leading threat modeling and security design discussions; reviewing product feature security architecture for data exposure and access control risks; collaborating with platform and infrastructure teams to build scalable preventative controls in AWS via Infrastructure-as-Code; evaluating and uplifting security tooling; mentoring engineers on effective AI leverage; prototyping automation for signal correlation and alert enrichment; architecting integrations between AWS and cloud-native security tools (SIEM, SOAR, IAM); serving as a hands-on technical contributor during security incidents; and building reusable AI-assisted playbooks that scale your judgment across teams. You must have proven delivery in security engineering or infrastructure security roles in cloud-native environments. Deep expertise required in AWS architecture (IAM, STS, cross-account roles, VPC, KMS), with working knowledge of Azure and GCP. Strong scripting fundamentals in Python and/or Go—enough to read, critique, and modify AI-generated code confidently. Demonstrated fluency directing AI coding tools paired with the judgment to catch when AI-generated infrastructure or security logic is wrong, incomplete, or dangerous. Expertise in SIEM, SOAR, vulnerability management, and cloud-native security tooling. You should think like an attacker, build like a defender, and treat AI-generated code with the same scrutiny as a junior engineer's first PR.

Similar roles