SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Deepgram is the leading platform for Voice AI, providing real-time APIs for speech-to-text, text-to-speech, and voice agents at scale. The company has processed over 50,000 years of audio and serves 1,300+ organizations including Twilio, Cloudflare, and Jack in the Box.
You will own the hands-on technical security engineering function, building and automating controls across Deepgram's infrastructure. The company runs primarily bare-metal GPU-intensive workloads in colocation datacenters with Docker containers managed by Ansible and CI/CD via GitHub Actions, supplemented by AWS for overflow and select services.
Key responsibilities include:
- Build and maintain security controls across bare-metal and AWS infrastructure: access management, network segmentation, encryption, secrets management, logging, detection, endpoint security, and vulnerability management
- Own configuration management and host hardening as code using Ansible across hundreds of Linux hosts, ensuring reproducibility and drift detection
- Secure containerized workloads: Docker image pipelines, registry scanning, runtime hardening, and secrets management
- Run vulnerability management end-to-end: discovery, exploitability prioritization, remediation coordination, and reporting
- Own patch and update management as a program with defined SLAs, automation, and exception tracking
- Manage the penetration testing lifecycle: vendor selection, scoping, finding triage, remediation verification, and customer-facing summaries
- Write detections, tune alerts, and participate in incident response; improve logging and telemetry coverage
- Automate compliance evidence collection for SOC 2, PCI DSS, and ISO 27001; support audit fieldwork
- Harden GitHub Actions CI/CD and software supply chain: dependency scanning, secret scanning, action pinning, SBOM, artifact signing, and least-privilege OIDC
- Apply AI and agentic tooling to security work (triage, evidence gathering, code review, detection engineering) and help secure the company's AI adoption
- Provide technical input on customer-facing security: questionnaire answers, penetration test summaries, and hardening guidance for self-hosted deployments
This role reports to the Director of Information Security. You will work in a high-trust, fast-moving engineering culture where controls must be delivered as code, reproducible, and self-auditing. The company operates with an AI-first mindset and expects all team members to actively use and experiment with advanced AI tools in daily work.
REQUIREMENTS:
- Solid experience in security engineering or infrastructure engineering with security focus; must have owned controls in production, not merely recommended them
- Deep Linux expertise: hardening, debugging, and reasoning about large fleets of physical Linux hosts (users/sudo, SSH, systemd, kernel/package updates, host firewalls, host-based agents)
- Ansible at fleet scale (required)
- Strong scripting in Python and/or Go, plus real shell competence
- Production experience securing Docker containers and build pipelines
- Hands-on experience securing GitHub and GitHub Actions (branch protection, CODEOWNERS, workflow permissions, secrets, third-party action risk)
- Experience running vulnerability and patch management as an ongoing program, including driving remediation across teams
- Experience managing third-party penetration tests: scoping and converting reports into closed engineering work
- Hands-on involvement in at least one formal audit (ISO 27001, PCI DSS, or SOC 2) as the engineer producing and defending evidence
- Comfortable using AI coding and agentic tools daily with clear-eyed understanding of risks (prompt injection, secret leakage, supply chain exposure)
- Pragmatic approach to security trade-offs; willing to name risks rather than pretend controls have no cost
NICE TO HAVE:
- Datacenter or colocation experience (network segmentation, IPMI/BMC, physical/vendor controls)
- Detection engineering or SIEM/HIDS ownership at scale (Wazuh, OSSEC, Elastic)
- HashiCorp Vault secrets management
- AWS security (IAM, SCPs, VPC) and Terraform
- Kubernetes security
- Offensive security background (penetration testing, red teaming)
- PCI DSS work in cardholder data environments
- Secure SDLC program ownership
- GPU infrastructure, ML platforms, or multi-tenant inference workload experience
- Certifications: OSCP, GIAC, CISSP, or AWS Security Specialty