Confirmed on the employer's own hiring board on Oct 11, 2026. First seen by Alion on Sep 3, 2026.
Join Abnormal AI as a Senior Cyber Security Engineer, where you'll lead the architecture and correctness of security systems in our AWS-based cloud environment. You'll collaborate with platform engineering and product teams, mentor engineers on AI leverage, and serve as a hands-on technical contributor during security incidents. This role requires deep security expertise, a collaborative mindset, and a passion for leveraging AI in security engineering.
Missions
- Lead the architecture and correctness of systems that enhance both preventative guardrails and detective capabilities across a primarily AWS-based cloud environment.
- Own the architecture decisions, validate what ships, and catch the failure modes AI won't flag on its own, while increasingly relying on AI to scaffold Terraform modules, prototype detection logic, and draft integrations.
- Mentor engineers on how to get real leverage from AI, reviewing AI-generated code and infrastructure together, and turning recurring feedback into standards and reusable playbooks.
Profil recherché
- Someone with high agency who proactively spots what in their own workflow (and the team's) AI can absorb, and actually builds the automation to make that real - not someone waiting to be told- Someone who thinks like an attacker but builds like a defender, and who treats AI-generated infrastructure and detection logic with the same scrutiny as a junior engineer's first PR
- A technical leader who can architect scalable security solutions while maintaining engineering velocity - increasingly by directing AI to do the first draft and applying judgment to the result
- A mentor who scales their judgment across the team - reviewing AI-generated code and infra for security gaps, and encoding what they learn into reusable playbooks and standards rather than repeating the same feedback one engineer at a time
- An intellectually curious, solution-focused engineer with a security mindset who thrives in fast-paced environments
- A collaborative engineer who can translate security requirements into actionable engineering tasks
- Background with using and securing container orchestration (Kubernetes), including workload security and service mesh controls
- Expertise in integrating or building tooling for SIEM, SOAR, vulnerability management, and CSPM platforms
- Proven ability to influence and collaborate cross-functionally with engineering, infra, product, and IT
- Deep comprehension of native AWS architecture services and identity/access patterns - IAM, STS, cross-account roles and resource policies, VPC and network segmentation, KMS - with AWS as our primary cloud platform, plus working knowledge of Azure and GCP
- Experience deploying security controls via Infrastructure-as-Code (Terraform or CloudFormation), primarily in AWS
- Demonstrated fluency directing AI coding/agent tools (e.g., Claude Code, Cursor, Copilot) to accelerate delivery, paired with the judgment to catch when AI-generated infrastructure or security logic is wrong, incomplete, or dangerous
- Strong written communication and documentation skills, with the ability to convey complex designs clearly
- Comfortable investigating logs, tracing events, and contributing to incident analysis workflows
- Proven delivery in security engineering or infrastructure security roles, ideally in cloud-native environments
- Strong scripting and dev fundamentals in Python and/or Go - enough to read, critique, and confidently modify AI-generated code, not just prompt for it; proficiency with Git, Linux, and infrastructure automation patterns
- Experience working in fast-paced or startup environments with sometimes ambiguous ownership lines
- Familiarity with JavaScript or TypeScript, particularly in the context of DevOps tooling or plugins
- Experience building or operating agentic workflows/AI tooling for security use cases (detection authoring, alert triage, IaC generation/review)
- Hands-on experience with commercial Cloud Security tools (CNAPP, CSPM, DSPM, KSPM)
- Partner with cloud infrastructure teams to implement and maintain security controls across AWS accounts and services
- Prior experience building security telemetry pipelines or log correlation frameworks
- Familiarity with CI/CD systems and integrating security checks into developer workflows
- Exposure to compliance frameworks (SOC 2, ISO 27001) and how engineering decisions affect auditability

