Senior Security Engineer, FedRAMP
Abnormal · Remote
MeritLog read this listing from Abnormal's Greenhouse job board and last checked it on September 9, 2026.
Source: the employer's Greenhouse job board. Open the original listing for current details.
Job details
- Work model
- Remote
- Salary
- Conflicting source ranges
- Location
- Remote - USA
Hiring context
How this role compares at Abnormal
Abnormal has 64 live roles in MeritLog’s catalog across 10 job families, and 25 of them are in engineering. 0 of those listings publish a pay range, a disclosure rate of 0%.
Abnormal concentrates this hiring in:
Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.
What the role asks for
What you'd do
- Build and improve secure delivery workflows for applications and infrastructure deployed into the federal environment.
- Create policy gates that evaluate infrastructure changes, security requirements, test results, and required approvals before deployment.
- Integrate security scanning and control validation into delivery workflows so issues are identified early in the development process.
- Review infrastructure as code changes that affect the federal boundary and help engineering teams resolve security risks before those changes reach production.
- Design automation that produces change records, approval history, test results, and required evidence directly from engineering workflows.
- Build and maintain hardened system image pipelines that consistently apply approved configurations, security controls, and operating system updates.
- Automate patch deployment across the environment, including testing, scheduling, rollout, validation, exception management, and compliance reporting.
- Improve fleet visibility so teams can quickly identify systems that are missing patches, running unsupported software, or operating outside approved configurations.
- Design and enforce identity and access controls across a complex cloud environment.
- Strengthen cloud security through organization policies, identity controls, resource policies, and automated configuration checks.
- Build preventive guardrails that block insecure or unauthorized configurations before they enter the federal environment.
- Own the reliability of security logging and monitoring pipelines, including ingestion coverage, data quality, source health, retention, and alerting.
- Develop automated checks that identify missing telemetry, delayed events, broken integrations, and other conditions that could reduce security visibility.
- Tune security detections to improve signal quality, reduce unnecessary alerts, and focus responders on activity that requires investigation.
- Build response automation that gathers context, enriches alerts, preserves evidence, and accelerates investigation and containment.
- Lead security incident response for the federal environment, including investigation, containment, recovery, evidence preservation, and after action reporting.
- Partner with infrastructure, operations, product security, incident response, and compliance teams to solve security problems that cross team boundaries.
- 8+ years in cloud security engineering, DevSecOps, infrastructure security, or a closely related engineering discipline, including deep hands-on experience with AWS.
- Strong experience building or securing cloud deployment pipelines and infrastructure as code workflows.
- Proficiency in at least one scripting or programming language, preferably Python, with a record of automating recurring operational work.
- Working knowledge of identity and access management design and enforcement in large cloud environments.
- Production experience with security monitoring and incident response, including investigation, containment, recovery, and operational follow through.
What they're asking for
- Experience integrating security automation into CI/CD pipelines and SecOps workflows.SkillPreferred
- Prior experience supporting federal audits or 3PAO engagements.SkillPreferred
- Knowledge of SaaS security operations and monitoring at scale.SkillPreferred
- Experience driving automation in security operations, compliance tracking, and evidence management.SkillPreferred
- Knowledge of SaaS security operations and modern cloud environments; exposure to DevSecOps pipelines or security reviews for Terraform/containers.SkillPreferred
- Experience with FedRAMP, DoD IL4, DoD IL5, government, or another highly regulated cloud environment, including support for 3PAO assessments or federal audits.SkillPreferred
- Familiarity with NIST SP 800-53 controls, continuous monitoring, security impact analysis, and technical evidence requirements.SkillPreferred
- Experience building compliance automation, continuous control monitoring, or automated evidence management capabilities.SkillPreferred
Parsed by MeritLog from the employer’s own posting. The full description follows below.
Job description
About the Role Abnormal AI is hiring a Senior Cloud Security Engineer to build and operate the security systems that protect our FedRAMP authorized environment. You will own secure delivery pipelines, infrastructure as code security, patch automation, identity controls, security telemetry, and incident response across a growing federal platform. You will design and build the capabilities that allow this environment to scale safely. Your work will include creating policy gates for cloud deployments, automating patch and access workflows, strengthening identity controls, improving security telemetry, and generating audit evidence directly from engineering systems. You will have meaningful ownership of both architecture and operational results, with the opportunity to replace repetitive work with reliable automation across the environment. You will work closely with DevInfra, FedOps, Product Security, Detection and Response, and Compliance to solve cloud security problems that cross traditional team boundaries. You will also use approved AI coding tools, such as Claude Code, to accelerate scripting, testing, documentation, and security automation. What you will do • Build and improve secure delivery workflows for applications and infrastructure deployed into the federal environment. • Create policy gates that evaluate infrastructure changes, security requirements, test results, and required approvals before deployment. • Integrate security scanning and control validation into delivery workflows so issues are identified early in the development process. • Review infrastructure as code changes that affect the federal boundary and help engineering teams resolve security risks before those changes reach production. • Design automation that produces change records, approval history, test results, and required evidence directly from engineering workflows. • Build and maintain hardened system image pipelines that consistently apply approved configurations, security controls, and operating system updates. • Automate patch deployment across the environment, including testing, scheduling, rollout, validation, exception management, and compliance reporting. • Improve fleet visibility so teams can quickly identify systems that are missing patches, running unsupported software, or operating outside approved configurations. • Design and enforce identity and access controls across a complex cloud environment. • Strengthen cloud security through organization policies, identity controls, resource policies, and automated configuration checks. • Build preventive guardrails that block insecure or unauthorized configurations before they enter the federal environment. • Own the reliability of security logging and monitoring pipelines, including ingestion coverage, data quality, source health, retention, and alerting. • Develop automated checks that identify missing telemetry, delayed events, broken integrations, and other conditions that could reduce security visibility. • Tune security detections to improve signal quality, reduce unnecessary alerts, and focus responders on activity that requires investigation. • Build response automation that gathers context, enriches alerts, preserves evidence, and accelerates investigation and containment. • Lead security incident response for the federal environment, including investigation, containment, recovery, evidence preservation, and after action reporting. • Partner with infrastructure, operations, product security, incident response, and compliance teams to solve security problems that cross team boundaries. Must Haves • 8+ years in cloud security engineering, DevSecOps, infrastructure security, or a closely related engineering discipline, including deep hands-on experience with AWS. • Strong experience building or securing cloud deployment pipelines and infrastructure as code workflows. • Proficiency in at least one scripting or programming language, preferably Python, with a record of automating recurring operational work. • Working knowledge of identity and access management design and enforcement in large cloud environments. • Production experience with security monitoring and incident response, including investigation, containment, recovery, and operational follow through. Nice to Have • Experience integrating security automation into CI/CD pipelines and SecOps workflows. • Prior experience supporting federal audits or 3PAO engagements. • Knowledge of SaaS security operations and monitoring at scale. • Experience driving automation in security operations, compliance tracking, and evidence management. • Knowledge of SaaS security operations and modern cloud environments; exposure to DevSecOps pipelines or security reviews for Terraform/containers. • Experience with FedRAMP, DoD IL4, DoD IL5, government, or another highly regulated cloud environment, including support for 3PAO assessments or federal audits. • Familiarity with NIST SP 800-53 controls, continuous monitoring, security impact analysis, and technical evidence requirements. • Experience building compliance automation, continuous control monitoring, or automated evidence management capabilities. #LI-JT1 Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location. In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package. Base salary range: $153,000-$220,000 USD A note on AI in our process: Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards. Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.
Keep exploring
More Engineering roles
- Electrical Engineer – Radio Frequency (RF) SystemsSaronic Technologies · On-site
- Senior Proposals and Capture ManagerSaronic Technologies · On-site
- Production Engineering ManagerSaronic Technologies · On-site
- Mechanical Engineer, Hardware IntegrationSaronic Technologies · On-site
- Hardware Engineer - Forward DeployedSaronic Technologies · On-site
- Shipyard Industrial EngineerSaronic Technologies · On-site