--- title: 'Application Security Engineer II at Abnormal' canonical: 'https://feeny.ai/job/application-security-engineer-ii-abnormal-united-states-c1yf9ppa31vm' type: 'job' last_seen: '2026-09-11' --- # Application Security Engineer II at Abnormal - **Company:** Abnormal - **Location:** United States - **Compensation:** $130k–$187k - **Work type:** remote - **Posted:** 2026-08-07 - **Last confirmed live:** 2026-09-11 - **Apply:** https://abnormal.ai/careers/jobs/7832743003?gh_jid=7832743003 ## Job description ## About the Role Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures. You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering. ## What you will do - Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors). - Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines. - Design and deploy automated security testing to identify vulnerabilities early in the development process. - Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes. - Coach developers on secure coding, security architecture, and threat modeling for AI-native systems. - Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends. Must Haves - 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices. - Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks. - Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it. - Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native). - Hands-on experience threat modeling and running security architecture reviews. - Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication. ## Nice to Have - Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program. - Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite) - Prior experience building security telemetry pipelines or vulnerability management frameworks. - Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability. - Familiarity with bug bounty programs and vulnerability disclosure processes. ## #LI-PP1 Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location. In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package. Base salary range: $130,100—$187,000 USD A note on AI in our process: Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards. Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please [click here](https://assets.contentstack.io/v3/assets/blt3a076cfd9753fa1f/blt9cbda641db7c0045/6a1e3d3a66aea075cd33e462/AAP_and_EEO_Statement.pdf). If you would like more information on your EEO rights under the law, please [click here](https://assets.contentstack.io/v3/assets/blt3a076cfd9753fa1f/blt4eb3a265cc7b1ca9/6a1e3d3bfe33e73c16ff026b/EEOC_Know_Your_Rights_Oct_30_2025.pdf). ## About Abnormal ## Company Overview - **One-liner**: Abnormal Security uses behavioral AI to autonomously detect and stop sophisticated email attacks, account takeovers, and insider threats for enterprises. - **Entity Type**: Private (Series D) - **Headquarters**: San Francisco, California, USA - **Founded**: 2018 - **Founders**: Evan Reiser (CEO) and Sanjay Jeyakumar (CTO) ## Core Business - **Primary industry**: Cybersecurity (Cloud Email Security, Identity Security, AI Security) - **Target customers**: B2B, Enterprise (over 25% of the Fortune 500) - **Mission statement**: "Stop crime with AI and bring cybersecurity from the future to defenders today." ## Products & Services - **Abnormal Behavioral Security Platform**: An AI-native, cloud-based platform that builds behavioral baselines for every user and entity in an organization to detect anomalies that indicate attacks. - **Email Security**: Autonomous detection and remediation of BEC, phishing, and account takeover attacks via API-based, cloud-native architecture. Deploys in 60 seconds with no MX changes. - **Identity Security**: Harden identities, detect compromise, and prevent insider threats by analyzing behavioral signals in real-time. - **Insider Threat**: Blocks fraudulent actors and malicious insiders by autonomously addressing anomalies. - **AI Security (Attune AI)**: Provides visibility and policy enforcement for all AI tools used within an organization, enabling AI governance. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed (last reported Series D valuation was $2.6B in 2022) - **Key Metric**: Over 25% of the Fortune 500 are customers. The company has stopped millions of attacks and saved billions in financial losses. - **Notable Investors/Partners**: Insight Partners, Greylock Partners, Menlo Ventures, CrowdStrike Falcon Fund (strategic investor) - **Growth Signals**: The company is AI-native from day one, with revenue growing rapidly. It is expanding its platform from email security into identity, insider threat, and AI governance. Headcount has grown significantly, and the company continues to hire across engineering, GTM, and operations. ## Competitive Advantages - **Behavioral AI Moat**: Unlike signature-based or rules-based security tools, Abnormal builds a unique behavioral baseline for every organization and user. This allows it to detect novel attacks that no other vendor sees. - **AI-Native Operations**: The company doesn't just build AI products—it runs its entire business (product, CS, finance, HR) with AI agents, compounding its speed of innovation. - **Deep Enterprise Trust**: Over 25% of the Fortune 500 give Abnormal the authority to autonomously make security decisions, a level of trust very few vendors achieve. - **Founding Team Origins**: Founders came from adtech (building anomaly-detection AI at scale) rather than traditional cybersecurity, giving them an outsider's perspective that led to the behavioral AI approach. ## Strategic Focus - **Platform Expansion**: Moving beyond email security into identity, insider threat, and AI security, building a unified behavioral security platform. - **AI-First Product Development**: Using AI agents to compress product development cycles from quarters to weeks, rapidly launching new products. - **Operational Efficiency**: Embedding AI across every internal function to drive automation and efficiency, allowing the company to scale without linear headcount growth. - **Market Leadership**: Capitalizing on the wave of AI-generated attacks to position behavioral AI as the only viable defense. ## Why Work Here - **Remote-First Culture**: From day one, Abnormal has been remote-first. Employees have the choice to work from home, from hub offices, or from co-working spaces (WeWork). Async work is the default, with deliberate synchronous overlap time. [abnormal.ai](https://abnormal.ai/careers/culture) - **High Autonomy, High Accountability**: No micromanagement. Clear expectations. Growth is based on impact, not tenure or title. "You don't wait your turn." [abnormal.ai](https://abnormal.ai/careers/culture) - **AI-Native Work Environment**: Every employee, regardless of role, gets access to the best AI tools and is expected to use them. The company rebuilds work processes around what AI makes possible—not by bolting AI onto old workflows. [abnormal.ai](https://abnormal.ai/careers/culture) - **Compressed Growth Timeline**: Because everything moves fast with AI, impact that would take quarters elsewhere happens in weeks. One person can do what used to take a team. Outsized impact is rewarded proportionally. [abnormal.ai](https://abnormal.ai/careers/culture) - **Transparent and Direct Culture**: "We say what's true, even when it's uncomfortable." Leaders are accessible, teams share learnings openly, and new hires get real ownership immediately. [abnormal.ai](https://abnormal.ai/about) - **Notable Perks**: Compensation is tied to impact, not role. The company offers flexibility as infrastructure, not a benefit. Employees see direct results from their work in a fast-growing, mission-driven company. ## Sources 1. [Abnormal AI - Official Website](https://abnormal.ai/) 2. [Abnormal AI - About Page](https://abnormal.ai/about) 3. [Abnormal AI - Careers & Culture](https://abnormal.ai/careers/culture) 4. [Abnormal AI - Open Roles](https://abnormal.ai/careers/open-roles) 5. [Abnormal AI - What We Are](https://abnormal.ai/about/what-we-are) 6. [Crunchbase - Abnormal Security](https://www.crunchbase.com/organization/abnormalsecurity) 7. [PitchBook - Abnormal Security](https://pitchbook.com/profiles/abnormal-security-168693-47) ## Other roles at Abnormal - [Sr. Customer Success Manager, Fed/SLED](https://feeny.ai/job/sr-customer-success-manager-fed-sled-abnormal-united-states-21zv7g243q1e) — United States - [Enterprise Account Executive - Chicago](https://feeny.ai/job/enterprise-account-executive-chicago-abnormal-united-states-j7jwcngch2k4) — United States - [Customer Success Manager, Enterprise (Missouri Valley)](https://feeny.ai/job/customer-success-manager-enterprise-missouri-valley-abnormal-united-states-2pjfc170be3k) — United States - [Professional Services Consultant (Spanish-Speaking)](https://feeny.ai/job/professional-services-consultant-spanish-speaking-abnormal-united-states-b8jeg5vrspgf) — United States - [Senior Professional Service Consultant](https://feeny.ai/job/senior-professional-service-consultant-abnormal-united-states-pnra459c653c) — United States - [Customer Success Manager, Canada (Toronto)](https://feeny.ai/job/customer-success-manager-canada-toronto-abnormal-canada-pf5jqvw84g5m) — Canada - [Digital Customer Success Manager](https://feeny.ai/job/digital-customer-success-manager-abnormal-united-states-0ybk9s6g3595) — United States - [Technical Support Engineer](https://feeny.ai/job/technical-support-engineer-abnormal-bengaluru-qs8a8wg1khm7) — Bengaluru, India - [Media Relations Manager](https://feeny.ai/job/media-relations-manager-abnormal-united-states-c1ha3y51t2hr) — United States - [FedRamp Compliance Analyst](https://feeny.ai/job/fedramp-compliance-analyst-abnormal-united-states-enrwqkx2fz1a) — United States