高级云安全工程师 (AWS)
Senior Cloud Security Engineer (AWS)
职位描述
Abnormal AI 正在寻找一位高级云安全工程师,帮助我们在大规模环境下构建下一代安全能力。这是一个高级专家级别的职位,需要结合深入的安全专业知识和有效指导 AI 工具的判断力——你将越来越多地依靠 AI 来构建 Terraform 模块、原型检测逻辑和编写集成方案,同时你将负责架构决策、验证交付内容,并发现 AI 无法自行标记的故障模式(如权限过高的角色、遗漏的边缘情况、细微的逻辑漏洞)。
作为技术负责人,你将负责增强我们主要基于 AWS 的云环境中的预防性防护措施和检测能力的系统架构和正确性,与平台工程和产品团队紧密合作进行安全架构评审。你将提升周围工程师的 AI 利用率——不是通过教授基础脚本编写,而是通过将你的评审判断转化为团队可以直接使用的可重用标准。你将在各团队之间担任技术联络人,并直接为保障我们的平台和客户安全做出贡献。
这个职位适合那些对安全原则、工程执行和 AI 加速交付充满兴趣并有动力去连接它们的工程师。
你是什么样的人
- 一位具有安全思维、解决问题导向的工程师,能够在快节奏环境中茁壮成长
- 一位技术领导者,能够构建可扩展的安全解决方案,同时保持工程速度——越来越多地通过指导 AI 完成初步设计,并对结果应用判断力
- 一位像攻击者一样思考,但像防御者一样构建的人,对待 AI 生成的基础设施和检测逻辑,会像对待初级工程师的第一个 PR 一样严格审查
- 一位具有高度主动性的人,能够主动发现自己的工作流程(以及团队的工作流程)中 AI 可以吸收的部分,并实际构建自动化来实现这一点——而不是等待被通知
- 一位善于协作的工程师,能够将安全需求转化为可执行的工程任务
- 一位能够将判断力扩展到整个团队的导师——评审 AI 生成的代码和基础设施中的安全漏洞,并将所学内容编码为可重用的指南和标准,而不是逐个工程师重复同样的反馈
你将做什么
- 与平台和产品团队一起主导威胁建模和安全设计讨论,将风险转化为
查看英文原文
About the Role
Abnormal AI is looking for a Senior Cloud Security Engineer to help build the next generation of security capabilities at scale. This is a senior IC-level role that blends deep security expertise with the judgment to direct AI tools effectively — you'll increasingly rely on AI to scaffold Terraform modules, prototype detection logic, and draft integrations, while you own the architecture decisions, validate what ships, and catch the failure modes AI won't flag on its own (overprivileged roles, missed edge cases, subtle logic gaps).
As a technical lead, you will own the architecture and correctness of systems that enhance both preventative guardrails and detective capabilities across our primarily AWS-based cloud environment, partnering closely with both platform engineering and product teams on security architecture reviews. You'll raise the AI leverage of the engineers around you — not by teaching scripting basics, but by turning your review judgment into reusable standards the team can build on directly. You'll act as a technical liaison across teams and contribute directly to keeping our platforms and customers secure.
This role is for engineers who are intellectually curious and motivated to bridge security principles, engineering execution, and AI-accelerated delivery.
Who you are
- An intellectually curious, solution-focused engineer with a security mindset who thrives in fast-paced environments
- A technical leader who can architect scalable security solutions while maintaining engineering velocity — increasingly by directing AI to do the first draft and applying judgment to the result
- Someone who thinks like an attacker but builds like a defender, and who treats AI-generated infrastructure and detection logic with the same scrutiny as a junior engineer's first PR
- Someone with high agency who proactively spots what in their own workflow (and the team's) AI can absorb, and actually builds the automation to make that real — not someone waiting to be told
- A collaborative engineer who can translate security requirements into actionable engineering tasks
- A mentor who scales their judgment across the team — reviewing AI-generated code and infra for security gaps, and encoding what they learn into reusable playbooks and standards rather than repeating the same feedback one engineer at a time
What you will do
- Lead threat modeling and security design discussions with both platform and product teams, translating risks into engineering actions and using AI to rapidly stress-test designs against attack scenarios before committing engineering time to a direction
- Partner with product engineering to review the security architecture of new product features — assessing designs for data exposure, access control, and abuse-case risk before they ship — using AI to speed up first-pass analysis so your review time goes toward the highest-risk decisions
- Collaborate with Platform, Infra, and DevOps teams to build scalable preventative controls in AWS via Infrastructure-as-Code — using AI coding agents to scaffold and iterate on Terraform/CloudFormation modules, reserving your own time for least-privilege review, blast-radius analysis, and edge cases
- Evaluate and uplift security tooling across commercial, cloud-native, and AI-assisted capabilities, focusing on scale, efficiency, and precision
- Mentor engineers on how to get real leverage from AI — reviewing AI-generated code and infrastructure together, and turning recurring feedback into standards and reusable playbooks instead of repeating it review after review
- Use AI to rapidly prototype automation for signal correlation, alert enrichment, and auto-remediation of known failure patterns, then harden and productionize what proves out rather than hand-building every workflow from a blank file
- Architect, build, and validate integrations between AWS and other cloud-native infrastructure and security tooling (e.g., SIEM, SOAR, IAM tooling), with a growing share of first-draft code AI-generated and human-owned
- Serve as a hands-on technical contributor during security incidents, using AI to accelerate log and telemetry triage while owning the judgment calls that determine root cause and response
- Build and maintain reusable AI-assisted playbooks (for IaC security review, detection authoring, alert triage) that scale your judgment across the security and platform teams
Must Haves
- Proven delivery in security engineering or infrastructure security roles, ideally in cloud-native environments
- Deep comprehension of native AWS architecture services and identity/access patterns — IAM, STS, cross-account roles and resource policies, VPC and network segmentation, KMS — with AWS as our primary cloud platform, plus working knowledge of Azure and GCP
- Strong scripting and dev fundamentals in Python and/or Go — enough to read, critique, and confidently modify AI-generated code, not just prompt for it; proficiency with Git, Linux, and infrastructure automation patterns
- Demonstrated fluency directing AI coding/agent tools (e.g., Claude Code, Cursor, Copilot) to accelerate delivery, paired with the judgment to catch when AI-generated infrastructure or security logic is wrong, incomplete, or dangerous
- Expertise in integrating or building tooling for SIEM, SOAR, vulnerability management, and CSPM platforms
- Experience deploying security controls via Infrastructure-as-Code (Terraform or CloudFormation), primarily in AWS
- Comfortable investigating logs, tracing events, and contributing to incident analysis workflows
- Proven ability to influence and collaborate cross-functionally with engineering, infra, product, and IT
- Strong written communication and documentation skills, with the ability to convey complex designs clearly
- Background with using and securing container orchestration (Kubernetes), including workload security and service mesh controls
Nice to Have
- Experience working in fast-paced or startup environments with sometimes ambiguous ownership lines
- Experience building or operating agentic workflows/AI tooling for security use cases (detection authoring, alert triage, IaC generation/review)
- Familiarity with JavaScript or TypeScript, particularly in the context of DevOps tooling or plugins
- Hands-on experience with commercial Cloud Security tools (CNAPP, CSPM, DSPM, KSPM)
- Partner with cloud infrastructure teams to implement and maintain security controls across AWS accounts and services
- Prior experience building security telemetry pipelines or log correlation frameworks
- Exposure to compliance frameworks (SOC 2, ISO 27001) and how engineering decisions affect auditability
- Familiarity with CI/CD systems and integrating security checks into developer workflows
#LI-PP1
Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.
In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.
Base salary range:
$153,000—$220,000 USD
A note on AI in our process:
Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.
Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.