Avatar for AssemblyAI
AssemblyAI
Actively Hiring
API platform for State-of-the-Art AI models
  • Responds within two weeks
    Based on past data, AssemblyAI usually responds to incoming applications within two weeks
  • B2B
  • Growth Stage
    Expanding market presence
  • +3

Security Operations Engineer

  • $180k – $220k
  • |Remote (
    Everywhere
    )
  • |Full Time
Posted: 6 days ago• Recruiter recently active
Hires remotely in
Everywhere
Visa Sponsorship

Not Available

RelocationNot Allowed
Hiring contact
Veronica Sanchez
Talent Sourcer
image

About the job

About the role:

AssemblyAI runs a mature, multi-framework security and compliance program—including SOC 2 (all trust criteria), ISO 27001, and PCI 4.0—that protects the infrastructure and customer data behind our industry-leading Voice AI API. We're hiring a Security Operations Engineer to join our IT & Security team and take day-to-day ownership of the operational backbone of that program.

This role is centered on security operations and GRC: running compliance audit cycles end to end, gathering and organizing evidence, enforcing and verifying controls, executing access reviews, managing vulnerability triage and remediation follow-up, and responding to customer security questionnaires. It's the work that turns a security program on paper into one that demonstrably runs. You'll also have room to grow the technical side of the role. We automate wherever we can, and you'll be encouraged to build scripts, integrations, and tooling that reduce manual toil and improve the program.

This is a high-ownership role on a small team. You'll work closely with engineers across the company, partner with sales and legal on customer-facing security needs, and have a direct hand in how AssemblyAI enforces security across its products, infrastructure, and internal tools—including a rapidly growing landscape of agentic AI development.

What You'll Do:

  • Drive SOC 2, ISO 27001, PCI 4.0, and other compliance audit cycles: gather and organize evidence, document, design, and build controls, coordinate directly with auditors through fieldwork, and collaborate with internal teams on remediation.
  • Own the compliance automation platform (Vanta): monitor control status, chase down failing checks, keep integrations healthy, and update the risk register as the business and infrastructure evolve.
  • Run vendor and third-party risk reviews, security assessments of new tools, periodic re-reviews, and track subprocessor and vendor inventories.
  • Partner with sales and legal responding to customer and vendor security questionnaires, RFP security sections, and trust-and-safety inquiries.
  • Drive vulnerability triage and prioritization across teams, tracking remediation against SLAs and reporting metrics to stakeholders.
  • Monitor and respond to alerts from endpoint, cloud, identity, and application security tools; investigate, escalate, and close the loop.
  • Support incident response for security events: evidence collection, timeline construction, documentation, and tracking of post-incident action items.
  • Maintain and improve security runbooks, process documentation, and operational playbooks.
  • Build automation to reduce the manual burden via scripts, integrations, reporting, and tooling.

What You'll Need:

  • 3+ years of experience in security operations, GRC, IT security, or a related role
  • 2+ years of experience with compliance audit cycles—you've gathered evidence, documented controls, and worked with auditors
  • One or more security certifications—CISA, Security+, AWS Security Specialty, or equivalent
  • Experience executing recurring security operations work: security reviews, vulnerability tracking, alert triage, or control monitoring
  • Strong organization—you can run a multi-week evidence collection cycle across many stakeholders without dropping threads
  • Strong written communication skills—you'll write audit documentation, security questionnaire responses, policy documents, and runbooks regularly
  • Proficiency in Python and comfort reading code written by others
  • Experience using AI-assisted development tools (e.g., Claude Code, Copilot, or similar) to write scripts, build automations, and accelerate documentation—AI tool fluency is a core expectation at AssemblyAI
  • Role is for US based candidates only

Nice to have

  • Application security fundamentals: threat modeling, secure code review, or familiarity with common vulnerability classes (OWASP Top 10, CWE)
  • Experience with security tooling across the development lifecycle—SAST, SCA, DAST, secret scanning, or IaC scanning—and routing findings to the right owners
  • Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security
  • Working knowledge of cloud infrastructure (AWS preferred), including IAM concepts, and of identity and SaaS administration
  • Experience building or maintaining SIEM detections, queries, and alerting pipelines
  • Familiarity with endpoint security platforms and cloud security posture tooling
  • Experience securing AI/ML systems or inference infrastructure
  • Experience at a high-growth startup in a security role

Pay Transparency:

AssemblyAI strives to recruit and retain exceptional talent from diverse backgrounds while ensuring pay equity for our team. Our salary ranges are based on paying competitively for our size, stage, and industry, and are one part of many compensation, benefit, and other reward opportunities we provide.

There are many factors that go into salary determinations, including relevant experience, skill level, qualifications assessed during the interview process, and maintaining internal equity with peers on the team. The range shared below is a general expectation for the function as posted, but we are also open to considering candidates who may be more or less experienced than outlined in the job description. In this case, we will communicate any updates in the expected salary range.

The provided range is the expected salary for candidates in the U.S. Outside of those regions, there may be a change in the range which will be communicated to candidates throughout the interview process.

Salary range: $180,000 - $220,000 USD

The expected base compensation for this role is listed above. Our total compensation package includes competitive equity grants, 100% employer-paid benefits, and the flexibility of being fully remote. A 401k match up to 4% is offered to all US-based full time team members.

About the company

AssemblyAI company logo

AssemblyAI

Actively Hiring
API platform for State-of-the-Art AI models51-200 Employees
Company Size
51-200
Company Type
Artificial Intelligence
Company Industries
Developer APIs
Company Industries
Artificial Intelligence / Machine Learning
Company Industries
B2B · SaaS · Mobile · Artificial Intelligence / Machine Learning
  • Responds within two weeks
    Based on past data, AssemblyAI usually responds to incoming applications within two weeks
  • B2B
  • Growth Stage
    Expanding market presence
  • Top Investors
    This company has received a significant amount of investment from top investors
  • YC Funded
    Startup funded by Y Combinator
  • Growing fast
    Showed strong hiring growth in the past month
Learn more about AssemblyAI image

Funding

AMOUNT RAISED
$59.2M
FUNDED OVER
3 rounds
Rounds
B
$30000000
Series B - Jul 2022+2

Perks

Premium Healthcare
100% Covered for You + Dependents
Vision / Dental Care
Maternity / Paternity Leave
Equity (Stock Options)
Remote-First Team
Unlimited PTO
Most people on our team take about 3-4 weeks off per year!
Annual Team Retreats
$1K for Your Home Office Setup
Life & Disability Insurance

Similar Jobs

Sosuv Consulting company logo
Sosuv Consulting
We provide specialised Product, Software Development and Support services to the global fi
stakefish company logo
stakefish
We are the leading staking service provider for blockchain projects. Delegate to us, stake with us
Meelance company logo
Meelance
Elevating Media and Entertainment Careers through Discovery and Connection
Ketryx company logo
Ketryx
Ketryx is saving and improving lives by making medical software safe and reliable
Avijo company logo
Avijo
Quick commerce Healthcare Platform
Maple company logo
Maple
Voice AI for Local Businesses
EliseAI company logo
EliseAI
Building AI agents that transform complex healthcare and housing systems