Deepgram logo
Deepgram·

Security Engineer - Deepgram

Fully remoteFull-timeMid-levelUTC-8–-4USA only#Docker#ansible#linux

Company Overview

Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words.

Company Operating Rhythm

At Deepgram, we expect an AI-first mindset—AI use and comfort aren’t optional, they’re core to how we operate, innovate, and measure performance.

Every team member who works at Deepgram is expected to actively use and experiment with advanced AI tools, and even build your own into your everyday work. We measure how effectively AI is applied to deliver results, and consistent, creative use of the latest AI capabilities is key to success here.

The Opportunity

Deepgram is looking for a Security Engineer to build and automate the technical controls behind our security program. Most of our infrastructure is bare metal in colocation datacenters — GPU-intensive, running containerized workloads on Docker, managed with Ansible, and shipped through CI/CD on GitHub Actions — with AWS used for overflow capacity and a small set of services. Our engineering culture is high-trust and fast-moving. That means controls have to be delivered as code, be reproducible, and produce their own audit evidence.

You will own real surface area: host hardening and configuration management across the fleet, vulnerability and patch management, penetration testing, container security, detection and response, CI/CD and supply chain security, and the engineering work behind our SOC 2, PCI DSS, and ISO 27001 obligations.

Responsibilities

  • Build, deploy, and maintain security controls across our bare-metal fleet and AWS footprint — access management, network segmentation and firewalling, encryption and secrets management, logging and detection coverage, endpoint security, and vulnerability management.
  • Own configuration management and host hardening as code with Ansible, so baselines are reproducible across hundreds of Linux hosts and drift is detectable.
  • Secure containerized workloads: Docker image build pipelines, registry scanning, runtime hardening and detection, and secrets management.
  • Run vulnerability management end to end — discovery, prioritization by real exploitability, and driving remediation with engineering teams.
  • Own patch and update management as a program for the server fleet, endpoint fleet, base images, OS and package updates, and dependency upgrades.
  • Own the penetration testing lifecycle: scoping, vendor selection, scheduling, triaging findings, and verifying fixes on retest.
  • Write detections, tune out noise, and take part in incident response.
  • Automate compliance evidence collection for SOC 2, PCI DSS, and ISO 27001, and support audit fieldwork on technical questions.
  • Harden GitHub Actions CI/CD and the software supply chain: dependency and secret scanning, action pinning, SBOM, artifact and image signing, and least-privilege OIDC.
  • Apply AI and agentic tooling to security work — triage, evidence gathering, code review, detection engineering — and help secure how the rest of the company uses AI.
  • Provide the technical input behind customer-facing security work: questionnaire and architecture answers, penetration test summaries, and hardening guidance for customers running Deepgram self-hosted.

Skills Needed

  • Solid experience in security engineering or infrastructure engineering with a security focus.
  • Deep Linux knowledge: hardening, debugging, and reasoning about a large fleet of physical Linux hosts (users and sudo, SSH, systemd, kernel and package updates, host firewalls).
  • Ansible at fleet scale is required.
  • Strong scripting skills in Python and/or Go, plus real shell competence.
  • Production experience securing Docker containers and the pipelines that build them.
  • Hands-on experience securing GitHub and GitHub Actions: branch protection, CODEOWNERS, workflow permissions, secrets, and third-party action risk.
  • Experience running vulnerability and patch management as an ongoing program.
  • Experience managing third-party penetration tests from the inside.
  • Hands-on involvement in at least one formal audit (ISO 27001, PCI DSS, or SOC 2) as the engineer producing and defending evidence.
  • Comfortable using AI coding and agentic tools in daily work while remaining clear-eyed about their risks.
  • Pragmatic approach to balancing security controls with operational velocity.

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Deepgram

Similar remote roles