hirq
← All jobs

Abnormal

Director of Security Engineering

Remote - USA · Remote · Security

$214K – $308K

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

AWSKubernetesMachine LearningSOC 2ISO 27001Cloud Security
About the Role Abnormal AI protects organizations from the most sophisticated email and collaboration attacks using behavioral AI. Security is not a bolt-on at Abnormal; it is core to the product we sell and the trust our customers place in us. Our security organization operates a commercial cloud environment and a separate FedRAMP-authorized environment, and we are pursuing increasingly rigorous federal authorizations as we grow. We are hiring a Director of Security reporting to the CISO and leading the Security Engineering organization. You will build and scale high-performing security teams, own major security programs end to end, and operate autonomously in the CISO's absence, including representing security to executive leadership, customers, and auditors. This is a role for a deeply technical leader with a software engineering background who has grown into people leadership. You have built security teams from the ground up, you write and review code and architecture when it matters, and you believe the best security organizations earn their influence through partnership rather than policy enforcement. Our Security Philosophy We run security the way the best engineering-led companies do: - Security reduces toil. Our job is to make the rest of the company faster and safer at the same time. If a control adds friction without reducing risk, it is a defect. - Paved paths, safe by default. We invest in guardrails, golden paths, and secure-by-default infrastructure so the easy choice is the secure choice. We prefer preventing classes of problems over chasing individual findings. - Partnership over gatekeeping. Security succeeds only through deep collaboration with engineering, IT, and business teams. We embed with builders, we ship alongside them, and we take on their constraints as our own. - Engineering-grade rigor. We treat security problems as engineering problems: automated, measurable, code-reviewed, and continuously improved. If the security cultures that value freedom and responsibility, context over control, and guardrails over gates resonate with you, you will feel at home here. What You Will Do - Serve as deputy to the CISO: act with full authority in the CISO's absence and represent the security organization to executives, customers, and regulators. - Lead, coach, and grow managers and senior engineers across Security Engineering and Security Operations. - Own the security engineering roadmap: cloud security architecture (AWS-first), detection and response, identity, vulnerability management, and secure-by-default platform investments. - Drive cross-functional programs with Engineering, IT, and Product, from AI security governance to data perimeter controls to federal compliance initiatives. - Set and defend engineering standards for the security organization: everything as code, automated where possible, measured against outcomes rather than activity. - Build hiring pipelines and raise the bar on every hire; own performance management, promotion cases, and succession planning within your teams. - Translate technical risk into business terms for the executive team and board, and translate business priorities into a coherent security strategy. Must Haves - 10+ years in security or software engineering, including 4+ years managing security teams, ideally including managers of managers or equivalent scope. - A genuine software engineering background: you have shipped production software, and you evaluate security solutions the way an engineer would. - A proven record of building and scaling high-performing security teams, with alumni who would work for you again. - Deep technical fluency in cloud-native environments: AWS organizations and multi-account governance, Kubernetes, identity and access, detection engineering, and modern SDLC security. - Demonstrated cross-functional leadership: you have earned the trust of engineering leaders and shipped security outcomes through their teams, not around them. - Strong written communication: you produce decision-ready documents and can drive alignment asynchronously. - Executive presence: comfortable presenting to C-level leadership, customers, and auditors without preparation from the CISO. Strong Signals - You are currently a security engineering manager or senior manager at a fintech, high-growth startup, or forward-leaning enterprise, and you are ready for broader scope. - You have built paved-path or secure-by-default platforms that measurably reduced both risk and developer friction. - Experience with compliance-driven environments (FedRAMP, SOC 2, ISO 27001) without letting compliance define the security program. - Experience securing AI/ML systems or governing AI adoption at scale. - You have operated in environments where security headcount was scarce and automation was the only way to scale. Why This Role You will inherit strong teams, an executive staff that treats security as a first-class function, and a CISO who wants a true partner rather than a lieutenant. The scope is broad, the autonomy is real, and the ceiling on this role is defined by what you take on. #LI-ML1 Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location. In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package. Base salary range: $214,200—$308,000 USD A note on AI in our process: Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards. Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.