
Senior Software Engineer, Security
AssemblyAI21 days ago
Remote, WorldwideSenior
Base Salary
$180k - $220k/yr
Responsibilities
- Conduct threat modeling and security design reviews for features, services, and architectural changes.
- Perform secure code reviews focused on authentication, authorization, input handling, secrets management, and data protection.
- Deploy and maintain SAST, SCA, DAST, secret scanning, IaC scanning, and CI/CD security guardrails.
- Partner with platform engineering on AWS hardening, Terraform reviews, network segmentation, and environment isolation.
- Investigate security incidents, perform root cause analysis, and implement post-incident hardening.
- Drive vulnerability triage, prioritization, remediation tracking, metrics, and direct remediation through patches and pull requests.
- Respond to customer and vendor security questionnaires, RFP security sections, and trust-and-safety inquiries with sales and legal.
- Support SOC 2, ISO 27001, PCI 4.0, and other audits by gathering evidence, documenting controls, and coordinating with auditors.
- Monitor endpoint, cloud, and application security alerts and manage remediation follow-up.
- Execute user access reviews, IAM hygiene tasks, and RBAC maintenance.
- Maintain security runbooks, process documentation, and operational playbooks while building automation with AI-assisted development tools.
Requirements
- 5+ years of experience in security engineering, security operations, or a role combining both.
- Hands-on experience with at least one SOC 2, ISO 27001, or PCI compliance audit cycle, including evidence gathering, control documentation, and auditor collaboration.
- Strong application security fundamentals, including threat modeling, secure code review, OWASP Top 10, and CWE familiarity.
- Experience with development-lifecycle security tooling such as SAST, SCA, DAST, secret scanning, or IaC scanning.
- Working knowledge of AWS infrastructure and services, including IAM, VPC networking, and security configurations.
- Familiarity with infrastructure-as-code, preferably Terraform, and CI/CD pipeline security.
- Proficiency in Python and ability to read backend service code.
- Strong written communication skills for audit documentation, security questionnaires, policies, and runbooks.
- Comfort using AI-assisted development tools such as Claude Code, Copilot, or similar.
- Preferred qualifications include AI/ML systems or inference infrastructure security experience, endpoint and cloud security tooling familiarity, security incident handling, SIEM detection and alerting experience, vulnerability management program experience, CISSP/CSSLP/AWS Security Specialty or equivalent certification, and startup security experience.
Benefits
- Fully remote work arrangement.
- 100% employer-paid benefits.
- Competitive equity grants.
- 401k match up to 4% for US-based full-time team members.
About AssemblyAI
AssemblyAI is the best way to build Voice AI apps. We build the industry’s best speech-to-text and speech understanding models, including promptable speech recognition, that serve as critical infrastructure for top Voice AI products like Granola, Dovetail, Ashby, and Cluely. Our speech-to-text models lead the industry in accuracy and quality, so you can build reliable product experiences on top of voice data. And our Speech Understanding models help you go beyond transcription to uncover insights, identify speakers, and highlight key information. We make it simple to get started, with a developer-first API and usage-based pricing that scales effortlessly to millions of hours.