Deepgram

Security Engineer

Deepgram
Apply
10 hours ago
Remote, United StatesMid Level / Senior
H1B sponsor

Base Salary

$150k - $245k/yr

Responsibilities

  • Build, deploy, and maintain security controls across Deepgram’s bare-metal fleet and AWS footprint, including access management, network segmentation, firewalling, encryption, secrets management, logging, detection, endpoint security, and vulnerability management.
  • Own Ansible-based configuration management and host hardening across hundreds of Linux hosts, ensuring reproducible baselines and detectable configuration drift.
  • Secure Docker workloads and image pipelines through registry scanning, runtime hardening, detection, and secrets management.
  • Run vulnerability management and patch management programs, including prioritization, remediation coordination, patch SLAs, exception tracking, and automation.
  • Own the penetration testing lifecycle from scoping and vendor selection through remediation tracking, retesting, and customer-shareable summaries.
  • Write and tune detections, participate in incident response, and improve logging, telemetry, and security-agent coverage.
  • Automate log and access reviews and generate repeatable evidence for SOC 2, PCI DSS, and ISO 27001 audits.
  • Harden GitHub Actions CI/CD and the software supply chain through dependency and secret scanning, action pinning, SBOMs, artifact and image signing, and least-privilege OIDC.
  • Apply AI and agentic tooling to security work and help secure the company’s use of AI.
  • Provide technical input for customer-facing security questionnaires, architecture answers, penetration test summaries, and guidance for self-hosted customers.

Requirements

  • Experience in security engineering or infrastructure engineering with a security focus, including ownership of production controls.
  • Deep Linux experience, including hardening, debugging, users and sudo, SSH, systemd, kernel and package updates, host firewalls, and host-based agents.
  • Required fleet-scale Ansible experience.
  • Strong scripting skills in Python and/or Go, along with shell proficiency.
  • Production experience securing Docker containers and their build pipelines.
  • Hands-on experience securing GitHub and GitHub Actions, including branch protection, CODEOWNERS, workflow permissions, secrets, and third-party action risk.
  • Experience operating vulnerability and patch management programs and driving remediation across engineering teams.
  • Experience managing third-party penetration tests and converting findings into completed engineering work.
  • Hands-on involvement in at least one ISO 27001, PCI DSS, or SOC 2 audit as the engineer producing and defending evidence.
  • Comfort using AI coding and agentic tools while understanding prompt injection, secret leakage, and supply-chain risks.
  • Preferred experience includes datacenter or colocation infrastructure, IPMI/BMC, detection engineering, SIEM/HIDS ownership, HashiCorp Vault, AWS security, Terraform, Kubernetes security, penetration testing or red teaming, PCI DSS in a cardholder data environment, secure SDLC ownership, GPU infrastructure, ML platforms, or multi-tenant inference workloads.
  • Preferred certifications include OSCP, GIAC, CISSP, or AWS Security Specialty.

Benefits

  • The role is open to strong mid-level and senior candidates, with title, scope, and compensation calibrated to demonstrated experience.
  • The role reports to the Director of Information Security.
  • The position offers hands-on ownership of security controls on a small, high-trust, fast-moving team.
  • Employees are expected to actively use and experiment with AI and agentic tooling in their daily work.

Tech Stack

Categories

Deepgram

About Deepgram

201-500 employees

Deepgram builds Voice AI infrastructure for developers, offering speech-to-text, text-to-speech, and voice agent tooling through real-time APIs and deployable on-prem software. Privately held and founded in 2015, the company is headquartered in San Francisco. Customers such as Twilio, Cloudflare, and Jack in the Box use its models to power production voice features; products include Nova-3 STT, Aura TTS, and a Voice Agent API.

Contact me