Application Security Engineer II
Hiring in only
This employer appears to hire only in the region above. Confirm you're eligible to be hired there before applying.
Lead threat modeling and security architecture reviews for AI-powered systems
Lead threat modeling and security architecture reviews with engineering teams, focusing on AI-powered features like LLM integrations and agentic workflows. Architect, build, and maintain security tooling and integrations for CI/CD pipelines to make secure development the default. Design and deploy automated security testing to identify vulnerabilities early in the development process.
Why This Role?
Direct impact on securing AI-native systems at production scale with founder access
Key Responsibilities
- Lead threat modeling and security architecture reviews with engineering teams
- Architect, build, and maintain security tooling and integrations in CI/CD pipelines
- Design and deploy automated security testing to identify vulnerabilities early
- Serve as a hands-on technical contributor during security incidents
- Coach developers on secure coding and threat modeling for AI-native systems
- Define and track key security posture metrics with dashboards or reports
Requirements
- 5+ years of experience in application security engineering roles
- Experience securing AWS or comparable cloud-native environments
- Experience securing AI/ML-powered systems or ability to ramp fast on prompt injection risks
- Strong programming skills in Python, Go, Java, or JavaScript/TypeScript
- Expertise in web application security including OWASP Top 10
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
View Original Description from WeWorkRemotely
Original description from WeWorkRemotely
Headquarters: Remote - USA About the Role Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures. You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering. What you will do Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors). Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines. Design and deploy automated security testing to identify vulnerabilities early in the development process. Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes. Coach developers on secure coding, security architecture, and threat modeling for AI-native systems. Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends. Must Haves 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices. Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks. Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it. Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native). Hands-on experience threat modeling and running security architecture reviews. Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication. Nice to Have Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program. Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite) Prior experience building security telemetry pipelines or vulnerability management frameworks. Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability. Familiarity with bug bounty programs and vulnerability disclosure processes. #LI-PP1 Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location. In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package. Base salary range: $130,100 — $187,000 USD A note on AI in our process: Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore. They do not make hiring decisions or sc
Salary Context
Similar Engineering roles on LokerDollar pay around $170k/yr (range $855–1000k/yr, n=703 active listings).
Hiring at Abnormal
Abnormal has 4 other active roles on LokerDollar and has been hiring here since Jun 11, 2026 — across Engineering, Sales & Business Development, Operations, Data & Analytics.
View all Abnormal openings →This listing is sourced from WeWorkRemotely, with the company profile and full details on this page. The one thing we can't auto-confirm is whether this specific apply link opens cleanly — it usually does, so go ahead and try it. Check back later if it doesn't load.
Frequently asked questions
- Is Application Security Engineer II at Abnormal a remote job?
- Yes. Application Security Engineer II at Abnormal is a fully remote role open to candidates worldwide.
- What is the salary for Application Security Engineer II at Abnormal?
- The listed pay range for this role is $130.1k–187k/yr.
- What type of employment is Application Security Engineer II at Abnormal?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at Abnormal.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Remote ≠ Remote: The Skills That Open Global Work to Indonesians (2026)12,891 remote listings: the highest-paid coding skills are the most geo-locked for Indonesia-based applicants. CC BY 4.0 aggregate dataset.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Remote Job Market Update: September 2026Explore the latest remote job trends, salary comparisons, and hiring insights from top global companies.
- 7 Latest Remote Jobs in September 2026Explore 7 new remote job opportunities in September 2026, from AWS Solutions Architect to Product Tester. Find flexible global career options here.
- Common Mistakes to Avoid in Remote AI JobDon't miss out on remote AI job opportunities! Learn from common mistakes to increase your chances of landing a USD-paying remote AI job in 2026.