Senior Security Engineer

Abnormal AI Abnormal AI · Vertical AI · United States · Remote · Security

Senior Security Engineer for Abnormal AI's FedRAMP environment, focusing on security operations engineering, CI/CD, access management, incident response, and automation to ensure compliance and resilience.

What you'd actually do

  1. Maintain and improve CI/CD pipelines to support secure deployments and infrastructure workflows.
  2. Manage infrastructure-as-code (IaC) PR and Change Control Board reviews, ensuring changes are tested, approved, and secure before release.
  3. Perform security impact analyses (SIAs) for system/application changes and provide recommendations.
  4. Run OS and infrastructure patch cycles; manage hardened images and patch workflows for FedRAMP environments.
  5. Govern access management, including account provisioning, RBAC module maintenance, and periodic reviews.

Skills

Required

  • 5 - 7 years in security engineering or infrastructure operations within federal or regulated cloud environments.
  • Strong familiarity with NIST 800-53 controls and continuous monitoring practices.
  • Proven delivery of AWS/SaaS security best practices.
  • Hands-on expertise with CI/CD, infrastructure automation, and IaC security practices.
  • Experience in patch management, hardened baselines, and secure image pipelines.
  • Strong knowledge of identity and access management (IAM) design and enforcement in large-scale environments.
  • Proven ability to manage SIEM pipelines and lead Tier 1/ Tier 2 incident response.
  • Strong technical documentation, collaboration, and incident/project management skills.

Nice to have

  • Experience integrating security automation into CI/CD pipelines and SecOps workflows.
  • Prior experience supporting federal audits or 3PAO engagements.
  • Knowledge of SaaS security operations and monitoring at scale.
  • Experience driving automation in security operations, compliance tracking, and evidence management.
  • Knowledge of SaaS security operations and modern cloud environments; exposure to DevSecOps pipelines or security reviews for Terraform/containers.

What the JD emphasized

  • FedRAMP environment
  • NIST 800-53 controls
  • continuous monitoring practices
  • AWS/SaaS security best practices
  • CI/CD
  • infrastructure automation
  • IaC security practices
  • patch management
  • hardened baselines
  • secure image pipelines
  • identity and access management (IAM)
  • SIEM pipelines
  • incident response