AssemblyAI logo
AssemblyAI
Posted 24 days agoVerified live 8h ago

Security Operations Engineer

Brief overview

Remote
UndergradOr in progress
$180k–$220k/yrStated range
3+ yrsMinimum
Security OperationsGovernance, Risk, and Compliance (GRC)SOC 2ISO 27001PCI DSSSecurity Certifications CISASecurity Certifications Security+Security CertificationsSecurity Certifications AWS Security SpecialtyVulnerability ManagementIncident ResponsePythonAI-Assisted Development ToolsVendor Risk ManagementApplication Security

About the company

AssemblyAI logo
AssemblyAIassemblyai.com

AssemblyAI is an artificial intelligence company that engages in building a platform of APIs to transcribe and understand audio data.

Visa sponsorship history

1 year sponsoring, last filed FY2024

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
$94,016median wage / yr
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20241
Top sponsored roles
Solutions Architect

Job description

Summary

AssemblyAI builds Voice AI models that power voice applications and its Voice AI API. The Security Operations Engineer will own day-to-day security operations and GRC activities, including compliance audits, control monitoring, access reviews, vulnerability remediation, customer security questionnaires, and incident response support. The role will also build automation and tooling to improve security processes across products, infrastructure, and internal systems.

Responsibilities

  • Drive SOC 2, ISO 27001, PCI 4.0, and other compliance audit cycles: gather and organize evidence, document, design, and build controls, coordinate directly with auditors through fieldwork, and collaborate with internal teams on remediation
  • Own the compliance automation platform (Vanta): monitor control status, chase down failing checks, keep integrations healthy, and update the risk register as the business and infrastructure evolve
  • Run vendor and third-party risk reviews, security assessments of new tools, periodic re-reviews, and track subprocessor and vendor inventories
  • Partner with sales and legal responding to customer and vendor security questionnaires, RFP security sections, and trust-and-safety inquiries
  • Drive vulnerability triage and prioritization across teams, tracking remediation against SLAs and reporting metrics to stakeholders
  • Monitor and respond to alerts from endpoint, cloud, identity, and application security tools; investigate, escalate, and close the loop
  • Support incident response for security events: evidence collection, timeline construction, documentation, and tracking of post-incident action items
  • Maintain and improve security runbooks, process documentation, and operational playbooks
  • Build automation to reduce the manual burden via scripts, integrations, reporting, and tooling

Skills

  • 3+ years of experience in security operations, GRC, IT security, or a related role
  • 2+ years of experience with compliance audit cycles—you've gathered evidence, documented controls, and worked with auditors
  • One or more security certifications—CISA, Security+, AWS Security Specialty, or equivalent
  • Experience executing recurring security operations work: security reviews, vulnerability tracking, alert triage, or control monitoring
  • Strong organization—you can run a multi-week evidence collection cycle across many stakeholders without dropping threads
  • Strong written communication skills—you'll write audit documentation, security questionnaire responses, policy documents, and runbooks regularly
  • Proficiency in Python and comfort reading code written by others
  • Experience using AI-assisted development tools (e.g., Claude Code, Copilot, or similar) to write scripts, build automations, and accelerate documentation—AI tool fluency is a core expectation at AssemblyAI
  • Application security fundamentals: threat modeling, secure code review, or familiarity with common vulnerability classes (OWASP Top 10, CWE)
  • Experience with security tooling across the development lifecycle—SAST, SCA, DAST, secret scanning, or IaC scanning—and routing findings to the right owners
  • Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security
  • Working knowledge of cloud infrastructure (AWS preferred), including IAM concepts, and of identity and SaaS administration
  • Experience building or maintaining SIEM detections, queries, and alerting pipelines
  • Familiarity with endpoint security platforms and cloud security posture tooling
  • Experience securing AI/ML systems or inference infrastructure
  • Experience at a high-growth startup in a security role

Qualifications

Must Haves

  • 3+ years of experience in security operations, GRC, IT security, or a related role
  • 2+ years of experience with compliance audit cycles—you've gathered evidence, documented controls, and worked with auditors
  • One or more security certifications—CISA, Security+, AWS Security Specialty, or equivalent
  • Experience executing recurring security operations work: security reviews, vulnerability tracking, alert triage, or control monitoring
  • Strong organization—you can run a multi-week evidence collection cycle across many stakeholders without dropping threads
  • Strong written communication skills—you'll write audit documentation, security questionnaire responses, policy documents, and runbooks regularly
  • Proficiency in Python and comfort reading code written by others
  • Experience using AI-assisted development tools (e.g., Claude Code, Copilot, or similar) to write scripts, build automations, and accelerate documentation—AI tool fluency is a core expectation at AssemblyAI

Nice to Haves

  • Application security fundamentals: threat modeling, secure code review, or familiarity with common vulnerability classes (OWASP Top 10, CWE)
  • Experience with security tooling across the development lifecycle—SAST, SCA, DAST, secret scanning, or IaC scanning—and routing findings to the right owners
  • Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security
  • Working knowledge of cloud infrastructure (AWS preferred), including IAM concepts, and of identity and SaaS administration
  • Experience building or maintaining SIEM detections, queries, and alerting pipelines
  • Familiarity with endpoint security platforms and cloud security posture tooling
  • Experience securing AI/ML systems or inference infrastructure
  • Experience at a high-growth startup in a security role

Benefits

  • Competitive equity grants
  • 100% employer-paid benefits
  • Fully remote work flexibility
  • 401k match up to 4% for all US-based full time team members

More jobs like this