SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Operations Engineer

AssemblyAI - Remote - Remote - posted 2026-09-10

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 180,000 - 220,000 / annual

AssemblyAI is hiring a Security Operations Engineer to join its IT & Security team and own the operational backbone of a mature, multi-framework security and compliance program (SOC 2, ISO 27001, PCI 4.0). The company processes 1M+ hours of audio daily, serves 600M+ monthly inference calls, and powers 2B+ end-user experiences with its Voice AI models. With under 100 employees and ~$500K ARR per employee, AssemblyAI operates as a lean, fast-moving meritocracy where individual contributors have outsized ownership and impact. In this role, you will drive compliance audit cycles end-to-end—gathering and organizing evidence, documenting controls, coordinating with auditors, and collaborating on remediation. You'll own the compliance automation platform (Vanta), monitoring control status, chasing failing checks, and updating the risk register as the business evolves. You'll run vendor and third-party risk reviews, security assessments of new tools, and track subprocessor inventories. You'll partner with sales and legal responding to customer and vendor security questionnaires, RFPs, and trust-and-safety inquiries. You'll drive vulnerability triage and prioritization across teams, tracking remediation against SLAs and reporting metrics to stakeholders. You'll monitor and respond to alerts from endpoint, cloud, identity, and application security tools; investigate, escalate, and close the loop. You'll support incident response for security events, including evidence collection, timeline construction, and documentation. You'll maintain and improve security runbooks, process documentation, and operational playbooks. You'll also build automation via scripts, integrations, reporting, and tooling to reduce manual burden. This is a high-ownership role on a small team. You'll work closely with engineers across the company and have a direct hand in how AssemblyAI enforces security across its products, infrastructure, and internal tools—including a rapidly growing landscape of agentic AI development. **Requirements:** - 3+ years of experience in security operations, GRC, IT security, or a related role - 2+ years of experience with compliance audit cycles (evidence gathering, control documentation, auditor coordination) - One or more security certifications: CISA, Security+, AWS Security Specialty, or equivalent - Experience executing recurring security operations work: security reviews, vulnerability tracking, alert triage, or control monitoring - Strong organizational skills to run multi-week evidence collection cycles across many stakeholders - Strong written communication skills for audit documentation, security questionnaire responses, policy documents, and runbooks - Proficiency in Python and comfort reading code written by others - Experience using AI-assisted development tools (Claude Code, Copilot, or similar) to write scripts, build automations, and accelerate documentation **Nice to have:** - Application security fundamentals: threat modeling, secure code review, OWASP Top 10, CWE - Experience with security tooling across the development lifecycle: SAST, SCA, DAST, secret scanning, IaC scanning - Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security - Working knowledge of cloud infrastructure (AWS preferred), including IAM concepts and identity/SaaS administration - Experience building or maintaining SIEM detections, queries, and alerting pipelines - Familiarity with endpoint security platforms and cloud security posture tooling - Experience securing AI/ML systems or inference infrastructure - Experience at a high-growth startup in a security role

Similar roles