Jobs · Full-time

AppSec Engineer II at Abnormal AI - Remote USA — Columbus

LocationColumbus
CompanyAbnormal
Sourceweworkremotely
Posted2026-08-24 07:30:47

Traveler-Friendly Insight

Location Constraint: US-Based Remote Only. Despite the "Anywhere in the World" hint, the job posting explicitly states "Remote - USA" headquarters and the salary is quoted in USD with geographic location as a compensation factor. This strongly implies US residency or at minimum a US work authorization requirement. Digital nomads outside the US are unlikely to qualify without a US work visa.

Schedule & Async Potential: The posting does not specify required hours or a timezone window, which is a mild green flag for async-friendliness. However, the role requires close collaboration with engineering, DevOps, and product teams, and involves incident response — suggesting some real-time availability during US business hours (likely ET or PT) is expected. This limits full timezone freedom.

Salary vs. Nomad Cost of Living: The $130K–$187K USD range is highly competitive globally. Quick comparisons:

  • Lisbon, Portugal: Comfortable living runs ~$2,500–$3,500/month. Even at $130K, you'd have significant savings potential.
  • Bangkok, Thailand: Monthly costs of ~$1,500–$2,500 make this salary exceptional — roughly 4–6x a comfortable local budget.
  • Medellín, Colombia: ~$1,500–$2,200/month allows very comfortable living; salary buys real financial freedom.

No travel-specific perks (coworking stipend, equipment budget, meetup allowance) are explicitly mentioned, though the comprehensive benefits package may include some. Nomads in the US or with valid US work status who can operate during core US hours would find the financial upside of this role significant in lower-cost destinations.

Headquarters: Remote - USA

About the Role

Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform — including LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain — against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.

You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You'll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering.

What You Will Do

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors).
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.

Must Haves

  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript — you write and read production code, not just review it.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
  • Hands-on experience with threat modeling and running security architecture reviews.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.

Nice to Have

  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite).
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.

Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.
In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range: $130,100 — $187,000 USD

A note on AI in our process:
Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

To apply: https://weworkremotely.com/remote-jobs/abnormal-application-security-engineer-ii

Frequently Asked Questions

Is this role fully remote or does it require working from an office?
The role is fully remote but based in the USA. Abnormal AI's headquarters is listed as Remote - USA, so US residency or work authorization is expected.
What is the salary range for the Application Security Engineer II position?
The base salary range is $130,100 to $187,000 USD, depending on skills, experience, qualifications, and geographic location. The role may also be eligible for bonus or incentive compensation and equity.
Do I need prior AI/ML security experience to apply?
AI/ML security experience is preferred, but the posting explicitly states that a "clear ability to ramp fast" on prompt injection, model supply chain, and agentic-workflow risks is an acceptable alternative to direct experience.
What programming languages are required for this role?
Candidates should have strong skills in Python, Go, Java, or JavaScript/TypeScript. The role requires writing and reading production code, not just reviewing it.
Does Abnormal AI use AI tools in its hiring process?
Yes — Abnormal AI uses AI-assisted tools to help interviewers prepare questions based on your resume and role requirements, but all hiring decisions are made by humans. Pre-employment checks are also required before a final offer.
Job4Travelers
Curated By

Job4Travelers

Helping travelers find remote work and build location-independent careers around the world.

Similar Opportunities