Senior Security Operations Engineer

AssemblyAI
Anywhere
Workplace: RemoteFull timeUSD 180,000 - 220,000 annuallyFunction: Solutions Engineering & Sales EngineeringSkills: ["Written communication"]

Own AssemblyAI’s security engineering and security operations in a high-ownership role on the first security engineering team. Split time between threat modeling, secure code reviews, security tooling (SAST/SCA/DAST, secret scanning, IaC scanning, CI/CD guardrails), and AWS/infrastructure hardening. Drive vulnerability triage and remediation, manage SOC 2/ISO 27001/PCI compliance cycles, respond to alerts, and support customer-facing security questionnaires across a rapidly evolving AI product landscape.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
AssemblyAI
AssemblyAI
3 months ago

Senior Security Operations Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 17 hours agoStatus: Live

Job Summary

Own AssemblyAI’s security engineering and security operations in a high-ownership role on the first security engineering team. Split time between threat modeling, secure code reviews, security tooling (SAST/SCA/DAST, secret scanning, IaC scanning, CI/CD guardrails), and AWS/infrastructure hardening. Drive vulnerability triage and remediation, manage SOC 2/ISO 27001/PCI compliance cycles, respond to alerts, and support customer-facing security questionnaires across a rapidly evolving AI product landscape.
Location: Anywhere
Workplace: Remote
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Conduct threat modeling and security design reviews for new features, services, and architectural changes.
  • •Perform secure code reviews and provide actionable feedback across authentication, authorization, secrets management, input handling, and data protection.
  • •Deploy and maintain security tooling across the development lifecycle, including SAST/SCA/DAST, secret scanning, IaC scanning, and CI/CD security guardrails.
  • •Drive vulnerability triage, prioritization, and remediation tracking, stepping in to remediate via patches and PRs where needed.
  • •Support SOC 2, ISO 27001, PCI 4.0 compliance cycles and monitor/respond to alerts while maintaining runbooks and operational playbooks.

Pay and Benefits

Salary: USD 180,000 - 220,000 annually
Perks:401k

Key Requirements

  • •5+ years of experience in security engineering or security operations, combining both disciplines.
  • •Hands-on experience with at least one of SOC 2, ISO 27001, or PCI compliance audit cycles, including evidence and working with auditors.
  • •Strong application security fundamentals including threat modeling, secure code review, and familiarity with OWASP Top 10 and CWE.
  • •Experience using security tooling across the development lifecycle (SAST, SCA, DAST, secret scanning, or IaC scanning).
  • •Working knowledge of AWS infrastructure and services (IAM, VPC networking, and security configurations), plus Terraform (preferred) and CI/CD security.
Experience:Security engineeringSecurity operationsSOC 2ISO 27001PCI 4.0
Skills:Written communication
Certifications:CISSPCSSLPAWS Security Specialty
Languages:English
Tech Stack:SOC 2ISO 27001PCI 4.0AWSIAMVPCTerraformCI/CDSASTSCADASTSecret scanningIaC scanningThreat modelingSecure code reviewOWASP Top 10CWEEndpoint securitySIEMClaude Code

Company Brief

AssemblyAI
Builds developer-focused speech-to-text and audio intelligence APIs using deep learning. Offers transcription, speaker diarization, content moderation, sentiment and intent analysis, and other audio understanding tools for enterprises and developers to integrate voice capabilities.
Industry: API Platforms
Company Size: Medium (51 to 250 employees)
Growth: Growth Stage Startup
Headquarters: San Francisco, United States
Founded: 2017
WebsiteLinkedIn