远程工作雷达

应用安全工程师 II

Application Security Engineer II

开发工程限定地区(需当地身份)
公司abnormalsecurity
薪资未公开
工作地点Remote - USA
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间2026-08-07
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote - USA 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位描述

Abnormal AI 正在寻找一名应用安全工程师 II,以保护我们基于 AWS 的平台核心的 AI 驱动系统(包括 LLM 集成功能、代理工作流、MCP 连接器和模型供应链)免受提示注入等威胁的影响。这是一个独立贡献者角色,结合了深入的应用安全专业知识和强大的工程基础。您将专注于将安全集成到软件开发生命周期的每个阶段,进行全面的安全评审,并与工程团队合作构建可辩护的架构。

您将负责安全架构和安全编码实践的开发,同时确保安全是工程利益相关者的基石合作伙伴。您将对整个工程组织的开发人员进行应用安全原则的指导,作为跨团队的技术联络人,并直接为保持我们的应用程序和客户安全做出贡献。此职位向安全工程总监汇报。

您将负责的工作

  • 与工程团队合作进行威胁建模和安全架构评审,将安全风险转化为具体的开发行动,特别关注 AI 驱动的功能(LLM 集成、代理工作流、MCP 连接器)。
  • 架构、构建和维护安全工具和集成,使安全开发成为我们 CI/CD 流水线中的默认选项。
  • 设计并部署自动化安全测试,以便在开发过程中早期识别漏洞。
  • 在安全事件中作为一线技术贡献者,通过分析应用层行为并改进响应流程。
  • 指导开发人员进行安全编码、安全架构和针对 AI 原生系统的威胁建模。
  • 定义并跟踪关键的安全态势指标,构建仪表盘或报告以可视化安全覆盖范围和漏洞趋势。

必备条件

  • 5 年以上应用安全工程经验,理想情况下在 AWS 或类似云原生环境中使用现代开发实践进行安全防护。
  • 具有保护 AI/ML 驱动系统的经验,或具备快速掌握提示注入、模型供应链和代理工作流风险的能力。
  • 精通 Python、Go、Java 或 JavaScript/TypeScript 编程。您编写和阅读生产代码,而不仅仅是审查代码。
  • 在 Web 应用安全方面有专长,包括 OWASP Top 10、认证/授权等。
查看英文原文

About the Role

Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.

You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering.

What you will do

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors).
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.

Must Haves

  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
  • Hands-on experience threat modeling and running security architecture reviews.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.

Nice to Have

  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.

#LI-PP1
Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.
In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:
$130,100—$187,000 USD

A note on AI in our process: 
Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位