{"id":2145257,"url":"https://alion.io/job/abnormal-security-application-security-engineer","title":"Application Security Engineer","company":{"id":3399,"name":"Abnormal Security","domain":"abnormalsecurity.com","url":"https://alion.io/company/abnormal-security","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Welcome to the Jungle","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":130100,"max":187000,"currency":"USD","period":"year","gross":null,"usd_annual":187000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"AWS","optional":false},{"name":"Burp Suite","optional":false},{"name":"Checkmarx","optional":false},{"name":"CI/CD","optional":false},{"name":"ISO 27001","optional":false},{"name":"JavaScript","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Semgrep","optional":false},{"name":"SOC 2","optional":false},{"name":"SonarQube","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"Veracode","optional":false},{"name":"Wiz","optional":false}],"status":"live","first_seen_at":"2026-08-16T00:01:37Z","employer_posted_date":"2026-10-09","last_verified_at":"2026-10-11T00:03:07Z","board_verified":true,"closed_at":null,"days_open":56,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":56},"description":"Join Abnormal AI as an Application Security Engineer II, where you'll secure our AI-powered systems against threats like prompt injection. This individual contributor role requires deep application security expertise and strong engineering fundamentals. You'll integrate security into every phase of our software development lifecycle, conduct comprehensive security reviews, and partner with engineering teams to build defensible architectures. You'll also coach developers on application security principles and contribute directly to keeping our applications and customers secure.\nMissions\nLead threat modeling and security architecture reviews with engineering teams, focusing on AI-powered features.\nArchitect, build, and maintain security tooling and integrations that make secure development the default in CI/CD pipelines.\nCoach developers on secure coding, security architecture, and threat modeling for AI-native systems.\nProfil recherché\n - Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks- Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it\n- Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native)\n- 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices\n- Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication\n- Hands-on experience threat modeling and running security architecture reviews\n- Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program\n- Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)\n- Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability\n- Prior experience building security telemetry pipelines or vulnerability management frameworks\n- Familiarity with bug bounty programs and vulnerability disclosure processes","description_format":"text","description_chars":2331,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Fraud Detection","Information Security","Cybersecurity AI"],"lifecycle":[{"event":"open","at":"2026-10-09T04:14:15Z"}],"visa":[],"liveness":{"score":42,"band":"fade","label":"Fading","p_open":1,"p_active":0.757,"p_room":0.55,"age_days":55,"expected_fill_days":40,"reasons":["conf:2","velocity","win:tail"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":187000,"is_top_pay":true},"html_url":"https://alion.io/job/abnormal-security-application-security-engineer","json_url":"https://alion.io/job/abnormal-security-application-security-engineer.json","meta":{"generated_at":"2026-10-11T00:41:43Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":830,"day_limit":5000,"remaining_today":4170,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3399},"rest":"https://alion.io/mcp/rest/get_company?id=3399"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fabnormal-security-application-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fabnormal-security-application-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fabnormal-security-application-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/abnormal-security-application-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fabnormal-security-application-security-engineer"}]}