AssemblyAI logo
AssemblyAI·

Security Operations Engineer - AssemblyAI

Fully remoteFull-timeSenior$180K - $220KWorldwide#security#compliance#pythonEquityHealth401k

About AssemblyAI

AssemblyAI builds best-in-class Voice AI models powering the next generation of voice applications. Our models serve 600M+ inference calls monthly, process 1M+ hours of audio daily, and power 2 billion+ end-user experiences. We are a high-growth, capital-efficient AI company operating as a true meritocracy with outsized ownership and impact for every team member.

About the Role

AssemblyAI is hiring a Security Operations Engineer to join our IT & Security team and take day-to-day ownership of our mature, multi-framework security and compliance program—including SOC 2, ISO 27001, and PCI 4.0.

This role focuses on security operations and GRC: running compliance audit cycles end-to-end, gathering evidence, enforcing controls, executing access reviews, managing vulnerability triage, and responding to customer security questionnaires. You will also build scripts, integrations, and tooling to automate manual workflows and improve our technical security posture.

What You'll Do

  • Drive SOC 2, ISO 27001, PCI 4.0, and other compliance audit cycles: gather and organize evidence, design and build controls, and coordinate with auditors.
  • Own the compliance automation platform (Vanta): monitor control status, keep integrations healthy, and update the risk register.
  • Run vendor and third-party risk reviews, security assessments, and track inventories.
  • Partner with sales and legal to respond to customer and vendor security questionnaires and RFPs.
  • Drive vulnerability triage and prioritization across teams, tracking remediation against SLAs.
  • Monitor and respond to alerts from endpoint, cloud, identity, and application security tools.
  • Support incident response for security events, including evidence collection and post-incident tracking.
  • Maintain and improve security runbooks, process documentation, and operational playbooks.
  • Build automation to reduce manual burden via scripts, integrations, and tooling.

What You'll Need

  • 3+ years of experience in security operations, GRC, IT security, or a related role.
  • 2+ years of experience with compliance audit cycles (evidence gathering, documenting controls, auditor coordination).
  • One or more security certifications (CISA, Security+, AWS Security Specialty, or equivalent).
  • Experience executing recurring security operations work (security reviews, vulnerability tracking, alert triage).
  • Strong organizational skills to manage multi-week evidence collection cycles across stakeholders.
  • Strong written communication skills for audit documentation, security questionnaires, policies, and runbooks.
  • Proficiency in Python and comfort reading code written by others.
  • Experience using AI-assisted development tools (e.g., Claude Code, Copilot) for scripts, automations, and documentation.

Nice to Have

  • Application security fundamentals (threat modeling, secure code review, OWASP Top 10).
  • Experience with security tooling across the development lifecycle (SAST, SCA, DAST, IaC scanning).
  • Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security.
  • Working knowledge of cloud infrastructure (AWS preferred), IAM, and SaaS administration.
  • Experience building or maintaining SIEM detections and alerting pipelines.
  • Experience securing AI/ML systems or inference infrastructure.
  • Experience at a high-growth startup in a security role.

Benefits

Equity, Health, 401k

Open to

Worldwide

Sign in to track applications and earn points.

More roles at AssemblyAI

Similar remote roles