Senior Application Security Engineer
Senior Application Security Engineer
ABOUT THE ROLE
Abnormal AI is looking for a Senior Application Security Engineer to help build the next generation of secure AI-powered cybersecurity applications at scale. This is a senior IC-level role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures. As a technical leader, you will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll mentor junior engineers, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This is a role for engineers who are intellectually curious and motivated to bridge the gap between security principles and application development execution.
WHO YOU ARE:
- An intellectually curious, solution-focused engineer with a security mindset who thrives in fast-paced environments
- A technical leader who can architect secure application solutions while maintaining engineering velocity
- Someone who thinks like an attacker but builds like a defender - understanding both offensive and defensive security principles
- A collaborative engineer who can translate security requirements into actionable development tasks
- A mentor who enjoys teaching secure coding practices and security architecture to junior engineers
WHAT YOU WILL DO
- Lead threat modeling and security architecture reviews with engineering teams by translating security risks into development actions.
- Architect, build, and maintain security tooling and integrations that enable secure development workflows (e.g., SAST, DAST, SCA, IAST tools).
- Collaborate with Engineering, DevOps, and Platform teams to build scalable security controls via Infrastructure-as-Code and secure CI/CD pipelines.
- Design and deploy automated security testing frameworks to identify vulnerabilities early in the development process.
- Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
- Mentor and support junior engineers on secure coding practices, security architecture, and security tooling integrations.
- Evaluate and uplift application security tooling and processes.
