Software Engineer II - Identity Security Posture Management (ISPM)
Job Description
About Abnormal AI
Abnormal AI is the leading AI-native security platform, protecting enterprise organizations from the full spectrum of cyber attacks. Powered by behavioral AI that understands human and machine identity, Abnormal detects and prevents attacks that evade traditional security tools — from sophisticated email threats to identity compromise and SaaS application abuse.
Trusted by more than 2,500 enterprises — including over 25% of the Fortune 500 — Abnormal processes billions of identity signals daily to protect people, data at scale.
Why this role exists
To address rapidly escalating customer demand, the BIS organization is growing its team dedicated to Identity Security Posture Management (ISPM). ISPM provides ongoing tracking of an enterprise's identity setups—including Okta, Google Workspace, and Microsoft Entra—revealing hidden vulnerabilities that build up across these networks. It packages these insights into an intuitive, actionable format, empowering security teams to understand their current defense status and prioritize critical remediation efforts.
With identity now serving as the main attack vector for modern enterprises, having complete visibility to understand every identity in your environment and proactively eliminate risk before it's exploited is more essential than ever. As one of Abnormal's fastest-growing divisions, ISPM is seeking a Software Engineer to help build the next generation of identity security defenses.
About the role
This is a hands-on engineering role at the intersection of identity security and distributed systems engineering. You'll write code, build and scale backend services, and contribute to technical designs — while partnering closely with senior engineers and Product Management to deliver what we build next.
You'll work across the backend: services that continuously evaluate millions of identity configurations, and the data infrastructure that powers posture scoring and proactive risk remediation.
What you'll do
Technical Contribution & Design
- Take well-defined problems from product requirements and deliver backend solutions end-to-end — from data modeling through APIs and evaluation logic.
- Contribute to the design of core identity security posture systems, and author and review technical design documents.
- Participate in architectural discussions and design reviews, raising trade-offs and edge cases.
- Uphold engineering best practices across testing, code quality, API design, and observability.
Software Engineering & Architecture
- Construct and scale high-performance backend services using Go — including event-driven systems, REST/gRPC APIs, cron jobs, and integration layers.
- Design, model, and optimize database schemas capable of handling large-scale multi-tenant identity workloads.
- Implement event-driven workflows using Kafka as a message queue to manage asynchronous processing and ensure continuous evaluation of identity postures.
- Maintain operational reliability and service health through standard runbooks, feature flags, and robust monitoring setups.
Team Collaboration & Delivery
- Collaborate closely with TL,, the EM, and fellow engineers to align on feature scope, prioritize work, and deliver quarterly key results and milestones.
- Participating in on-call rotation, incident response, and SLO management.
- Work autonomously and asynchronously within a distributed team located across India and Singapore.
Must have qualifications
- 4+ years of software development experience, with ~2 years building production-grade backend services.
- Extensive backend production experience with Go — writing idiomatic services with clean design patterns, thorough testing, and robust error handling.
- Good system design skills — experience building and running scalable, multi-tenant, event-driven distributed systems.
- Hands-on experience with Kafka or similar high-throughput event-streaming technologies.
- Strong proficiency in SQL and PostgreSQL — including schema design, query optimization, and data modeling for multi-tenant workloads.
- Strong communication abilities — able to detail technical trade-offs, contribute to design documents, and work effectively with TL/PM and fellow engineers.
- Comfort with ambiguity — able to make decisions with partial data and iterate quickly.
- Familiarity with AI-assisted software development workflows and tools
Nice-to-have qualifications
- Experience in identity security, IAM, or security posture management — familiarity will be good.
- Background in cybersecurity products.
- Experience with gRPC/Protobuf API design.
- Production-level React and TypeScript skills for occasional user-facing contributions.
#LI-LR1 AI and our hiring process Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and identify areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person.
Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.