Senior Security Engineer, FedRAMP
AbnormalRemote (USA)1mo ago
Job description
About the role
Abnormal AI is seeking a Senior Security Engineer to maintain and enhance the security posture of our FedRAMP environment. This role is centered on security operations engineering with a focus on protecting government cloud workloads. The successful hire will own the technical processes that ensure Abnormal Gov systems remain compliant and secure in demanding environments. You will leverage strong cloud and infrastructure security knowledge while applying operational rigor to every task. The ideal candidate will use AI tools strategically to improve efficiency and scale security efforts. You will be responsible for bridging the gap between secure development and compliant operations.
Key facts
What you'll do
- Refine CI/CD pipelines to enforce security gates across software delivery and infrastructure operations.
- Scrutinize infrastructure-as-code pull requests and validate change control processes before any deployment occurs.
- Lead security impact assessments for system and application changes, translating findings into actionable recommendations.
- Orchestrate software update cycles for operating systems and infrastructure, managing approved images and update workflows for FedRAMP environments.
- Oversee access management, including account provisioning, role-based access control (RBAC) system maintenance, and recurring access validations.
- Optimize logging and monitoring systems by tuning SIEM data intake and alerting rules for better coverage and accuracy.
- Drive the investigation and response to security incidents, guiding the process from detection through containment and recovery.
- Author and revise operational procedures, standard operating procedures (SOPs), and system documentation to support audits and consistent execution.
- Collaborate with DevInfra, FedOps, Product, and Compliance teams to embed secure practices across development lifecycles and operations.
- Monitor cloud workloads and SaaS environments to identify misconfigurations and strengthen security hygiene at scale.
- Implement identity and access management (IAM) guardrails and role designs for complex, multi-account systems.
- Build and maintain detection logic within SIEM platforms to improve threat visibility for Tier 1 and Tier 2 analysts.
- Coordinate patch management activities and ensure secure baselines are enforced across all infrastructure components.
- Prepare audit evidence and artifacts to streamline third-party assessments and government security reviews.
Requirements
- Bring 5 to 7 years of hands-on experience in security engineering or infrastructure operations within government or regulated cloud environments.
- Demonstrate a solid understanding of NIST 800-53 controls and ongoing monitoring strategies for compliance.
- Show practical experience implementing AWS security best practices and securing infrastructure-as-code templates.
- Apply proven expertise in CI/CD tools, infrastructure automation, and the secure design of pipelines.
- Have direct experience with patch management, maintaining secure system baselines, and managing secure image creation workflows.
- Exhibit proficient knowledge of identity and access management (IAM) design, enforcement, and federation in large-scale systems.
- Prove ability to manage SIEM pipelines and lead incident response efforts from Tier 1 through Tier 2 scenarios.
- Hold strong written and verbal communication skills for collaborating with technical and non-technical stakeholders.
Nice to have
- Experience integrating security automation into CI/CD pipelines and SecOps operational workflows.
- Prior involvement in supporting federal audits or working with third-party assessment organization (3PAO) teams.
- Familiarity with SaaS security operations, monitoring, and log analysis at enterprise scale.
- Track record of driving automation in security operations, compliance tracking, and evidence collection.
- Exposure to modern cloud environments, DevSecOps pipelines, and security reviews for infrastructure as code using Terraform or containers.
Practical notes
- Compensation band is specified as $153,000 - $220,000 USD for this role.
- This position may be eligible for additional bonuses, incentive plans, and equity components as part of the total rewards package.
- Abnormal AI utilizes AI tools internally to assist the recruiting team in analyzing resumes and role requirements to suggest interview questions. These tools support decision processes but do not make final hiring choices.
- Employment decisions are based solely on objective evaluations of skills and experience.
- Abnormal AI is committed to being an equal opportunity employer for all candidates.
- All official correspondence and interview invitations will originate from an @abnormal.ai email domain.
- The hiring process includes video interviews and identity verification steps as part of standard pre-employment checks.
- Conditional job offers are contingent upon successful completion of background and reference verification.
- Applications are generally reviewed within a two-week window after submission.
- This position is open to remote-based candidates located anywhere within the United States.
- The selected candidate will operate in a primarily asynchronous remote environment with an expectation of disciplined communication.
- You are expected to maintain professional availability during agreed working hours for collaboration with global teams.
- Travel is not required for this role, though occasional in-person meetings may be requested for team collaboration.
- Visa sponsorship may be considered for exceptional candidates where legal eligibility and role requirements align.
- Deadlines for application review are not fixed, but early submissions are encouraged to ensure full consideration.
- Security clearance requirements, if applicable, will be discussed with the candidate upon conditional offer.
- Continued professional development in FedRAMP and cloud security practices is encouraged to keep pace with evolving regulations.
- This role reports to the Security leadership team and participates in on-call rotations as defined by the incident management schedule.
- Performance goals will align with security objectives, including audit readiness, incident reduction, and process maturity improvements.