Software Engineer I
Job description
About the role
Abnormal's AI-native security products protect critical communications, identities, and infrastructure for organizations of every size. These systems are data- and systems-intensive, delivering precise outcomes at global scale and low latency across multiple clouds and regions. On the Federated Intelligence Platform (FIP) team, you will design and maintain high-volume ingestion pathways and low-latency services that power detection accuracy and identity protection as the security footprint expands. You will gain hands-on experience designing production-grade systems, working within an AI-first engineering culture, and contributing to services that are dependable, scalable, and security-critical. FIP operates as the federated intelligence layer within the Abnormal Data Platform, handling the ingestion, storage, and retrieval of entity insights and threat indicators that drive core detection and the customer portal. This role is positioned at the intersection of infrastructure and security where your work will directly influence how data fuels intelligent protection mechanisms. You will be part of a team that values clarity, ownership, and the ability to translate complex requirements into robust production systems. The position is ideal for an engineer who wants to build foundational components that serve high-stakes security workloads.
What you'll do
- Design intake pipelines that reliably pull high volume data from diverse sources into staging areas while preserving data integrity and consistency.
- Build low-latency ingestion services using Python, Go, or TypeScript, with clear interfaces and robust observability to support real-time security decisions.
- Own smaller tasks and components end-to-end, including clarifying requirements, breaking work into steps, writing code, and validating changes in test and production environments with team support.
- Refactor components to strengthen correctness and maintainability while fixing bugs and simplifying bottlenecks that impact throughput or reliability.
- Investigate incidents, improve runbooks, and practice debugging to prepare for broader operational ownership and reduce mean time to resolution.
- Collaborate with Detection, Product, Infra, and partner teams to trace cross-system impacts of each change and ensure alignment on security and performance goals.
- Use AI tools during code generation, testing, and documentation while validating output to engineering standards and security best practices.
- Write clear comments, update documentation and runbooks, and share insights from reviews and incidents to create a continuously learning codebase.
- Seek feedback, pair with teammates, and claim progressively larger work as your experience and confidence grow within the security engineering domain.
- Implement data transformations and enrichment logic that normalize inputs from multiple protocols and formats into unified internal representations.
- Contribute to the reliability and performance of the federated intelligence layer by monitoring service health and identifying capacity constraints before they affect detection.
- Support the evolution of the Abnormal Data Platform by integrating new entity insights and threat indicators into scalable storage and retrieval mechanisms.
- Assist in maintaining high standards for security, privacy, and compliance within the data pipelines that underpin customer protection.
- Participate in on-call rotations and incident response activities to ensure that critical ingestion paths remain available and performant.
Requirements
- Must bring one or more years of professional software engineering experience from jobs, research, or substantial personal projects that demonstrate practical application of concepts.
- Must show solid skills in at least one language common at Abnormal such as Python, Go, or TypeScript and JavaScript with the ability to write clean, testable code.
- Must demonstrate grasp of data structures, basic algorithms, clean code, debugging techniques, and version control with Git to manage changes in a collaborative environment.
- Must handle relational or NoSQL storage, including schema design for persistence and retrieval needs that support high-throughput security workloads.
- Must operate comfortably with AWS, Docker, or Kubernetes while understanding container orchestration basics and deployment patterns.
- Must understand event-driven architectures and message queuing concepts in distributed settings to build resilient ingestion services.
- Must communicate clearly, ask thoughtful questions, and collaborate effectively in a remote distributed team that spans multiple time zones.
- Must embrace feedback, own mistakes, and stay motivated to improve your craft and your impact on the product and the customers it protects.
Nice to have
- Experience with distributed systems or large-scale data stores such as PostgreSQL, DynamoDB, Redis, RocksDB, Kafka, Spark, or OpenSearch.
- Familiarity with Airflow or similar workflow orchestration tools for building data pipelines that automate complex ingestion and enrichment jobs.
- Background in production monitoring, tracing, and structured logging practices to support observability and rapid troubleshooting.
Practical notes
- Location is Remote
- Singapore with full flexibility to work from that region.
- Engagement is Full-time indicating a standard schedule and long-term commitment to the role.
- Compensation is set between 85000 USD to 110000 USD per year, aligned with experience and impact.
- The role involves interaction with sensitive security data, requiring professionalism and adherence to internal policies at all times.
- Work will be conducted in an AI-first engineering environment where tools are used to augment development speed and accuracy.
- There may be occasional collaboration with teams across regions, so awareness of asynchronous communication norms is helpful.
- This position contributes directly to the Federated Intelligence Platform and the broader Abnormal Data Platform mission.