Lead threat modeling and security design discussions with platform and product teams.
Review product security architectures for data exposure, access control, and abuse-case risks.
Build scalable AWS preventative controls using Terraform or CloudFormation and conduct least-privilege and blast-radius reviews.
Evaluate and improve commercial, cloud-native, and AI-assisted security tooling.
Prototype and productionize automation for signal correlation, alert enrichment, and known-issue auto-remediation.
Build and validate integrations among AWS, SIEM, SOAR, IAM, and other security tooling.
Contribute hands-on technical judgment during security incidents, including log and telemetry triage.
Create reusable AI-assisted playbooks for IaC security review, detection authoring, and alert triage.
Mentor engineers and encode security review feedback into reusable standards and playbooks.
Influence engineering, infrastructure, product, and IT teams through clear security documentation and collaboration.
Requirements
Proven experience delivering security engineering or infrastructure security solutions, preferably in cloud-native environments.
Deep knowledge of AWS architecture and identity/access patterns, including IAM, STS, cross-account roles, resource policies, VPC, network segmentation, and KMS; working knowledge of Azure and GCP is also required.
Strong scripting and development fundamentals in Python and/or Go, with proficiency in Git, Linux, and infrastructure automation patterns.
Experience directing AI coding or agent tools such as Claude Code, Cursor, or Copilot while validating AI-generated infrastructure and security logic.
Expertise integrating or building tooling for SIEM, SOAR, vulnerability management, and CSPM platforms.
Experience deploying security controls through Infrastructure-as-Code with Terraform or CloudFormation, primarily in AWS.
Ability to investigate logs, trace events, and contribute to incident analysis workflows.
Proven ability to influence and collaborate cross-functionally with engineering, infrastructure, product, and IT teams.
Strong written communication, documentation, and complex-design communication skills.
Experience using and securing Kubernetes, including workload security and service mesh controls.
Experience in fast-paced or startup environments is preferred.
Experience building or operating agentic AI workflows for security use cases is preferred.
Familiarity with JavaScript or TypeScript for DevOps tooling or plugins is preferred.
Hands-on experience with commercial cloud security tools such as CNAPP, CSPM, DSPM, or KSPM is preferred.
Experience building security telemetry pipelines or log correlation frameworks is preferred.
Exposure to SOC 2 and ISO 27001 compliance frameworks is preferred.
Familiarity with CI/CD systems and integrating security checks into developer workflows is preferred.
Benefits
Base salary ranges from $153,000 to $220,000 USD.
The role may include bonus or incentive compensation, equity, and a comprehensive benefits package.
Abnormal AI is an equal opportunity employer and conducts required pre-employment checks in accordance with applicable legislation and company policies.
Salary: $153k - $220k/yr
Abnormal Security
Abnormal AI is the leading AI-native human behavior security platform, leveraging machine learning to stop sophisticated inbound attacks and detect compromised accounts across email and connected applications.