Skip to main content
AssemblyAI

Senior Software Engineer, Security

RemoteUnited States only
Published
Role
Security
Experience
Senior
Company size
Startup
$180k–$220k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior Software Engineer with 5+ years of combined security engineering and operations experience. Must have hands-on experience with SOC 2, ISO 27001, or PCI compliance. Requires strong application security fundamentals, experience with security tooling, AWS, Python, and AI-assisted development tools. Role involves threat modeling, secure code reviews, security tooling, infrastructure hardening, and operational tasks like vulnerability management and compliance audits.

Core skills

security engineeringsecurity operationscompliance

Required skills

PythonAWSSASTSCADASTsecret scanningIaC scanningthreat modelingsecure code reviewTerraform

Optional skills

AI/ML systems securityinference infrastructure securityendpoint security platformscloud security toolingSIEM detectionsvulnerability management programsCISSPCSSLP

Required languages

English

What you'll do

  • Conduct threat modeling and security design reviews for new features, services, and architectural changes—partnering with product and platform engineers early in the design phase.
  • Perform secure code reviews and provide actionable feedback, focusing on authentication, authorization, input handling, secrets management, and data protection.
  • Deploy and maintain security tooling across the development lifecycle—SAST, SCA, DAST, secret scanning, IaC scanning, and CI/CD security guardrails.
  • Support best practices to adopt secure-by-default libraries, frameworks, paved-road patterns, and developer guidance to reduce classes of vulnerabilities across the codebase.
  • Partner with platform engineering on infrastructure and environment security—including AWS resource hardening, Terraform-managed infrastructure reviews, network segmentation, and environment isolation improvements.
  • Contribute to incident response for security events: investigation, root cause analysis, and post-incident hardening.
  • Drive vulnerability triage and prioritization across teams, tracking remediation against targets and reporting metrics.
  • Step in to remediate directly through patches and PRs where you identify high-impact opportunities.
  • Partner with sales and legal responding to customer and vendor questionnaires, RFP security sections, and trust-and-safety inquiries.
  • Support SOC 2, ISO 27001, PCI 4.0, and other compliance audit cycles by gathering evidence, documenting controls, and coordinating with auditors.
  • Monitor and respond to alerts from endpoint, cloud, and application security tools; manage vulnerability tracking and remediation follow-up across the environment.
  • Execute recurring user access reviews, IAM hygiene tasks, and RBAC maintenance required by compliance frameworks.
  • Maintain and improve security runbooks, process documentation, and operational playbooks—building automation where possible to reduce manual burden using AI-assisted development tools.

What they require

  • 5+ years of experience in security engineering, security operations, or a related role that combined both
  • Hands-on experience with at least one of SOC 2, ISO 27001, or PCI compliance audit cycles—you've gathered evidence, documented controls, and worked with auditors, not just read about it
  • Strong application security fundamentals: threat modeling, secure code review, and familiarity with common vulnerability classes (OWASP Top 10, CWE)
  • Experience with security tooling across the development lifecycle: SAST, SCA, DAST, secret scanning, or IaC scanning
  • Working knowledge of AWS infrastructure and services, including IAM, VPC networking, and security configurations
  • Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security
  • Proficiency in Python and comfort reading code across backend services
  • Strong written communication skills—you'll write audit documentation, security questionnaire responses, policy documents, and runbooks regularly
  • Comfort using AI-assisted development tools (e.g., Claude Code, Copilot, or similar) to write scripts, build automations, and accelerate documentation—AI tool fluency is a core expectation at AssemblyAI

Benefits

  • Competitive equity grants
  • 100% employer-paid benefits
  • Flexibility of being fully remote
  • 401k match up to 4% is offered to all US-based full time team members.

AssemblyAI builds Voice AI models powering voice applications. Its models serve hundreds of millions of inference calls monthly, process millions of hours of audio daily, and serve thousands of customers including Granola, Fireflies, Figure AI, and CallRail.

🇺🇸 United StatesArtificial IntelligenceStartup
Also posted in 2 other channels
$180k–$220k/yr