Senior Security Operations Engineer

AssemblyAI AssemblyAI · AI Frontier · Remote · Engineering

AssemblyAI is seeking a Senior Security Operations Engineer to join their IT & Security team. This role focuses on security engineering and operations, including threat modeling, secure code reviews, security tooling, infrastructure hardening, compliance audits (SOC 2, ISO 27001, PCI 4.0), vulnerability management, and customer questionnaires. The role involves hands-on engineering work and operational tasks to protect the company's infrastructure and customer data, supporting a mature security and compliance program.

What you'd actually do

  1. Conduct threat modeling and security design reviews for new features, services, and architectural changes—partnering with product and platform engineers early in the design phase.
  2. Perform secure code reviews and provide actionable feedback, focusing on authentication, authorization, input handling, secrets management, and data protection.
  3. Deploy and maintain security tooling across the development lifecycle—SAST, SCA, DAST, secret scanning, IaC scanning, and CI/CD security guardrails.
  4. Drive vulnerability triage and prioritization across teams, tracking remediation against targets and reporting metrics. Step in to remediate directly through patches and PRs where you identify high-impact opportunities.
  5. Partner with sales and legal responding to customer and vendor questionnaires, RFP security sections, and trust-and-safety inquiries.

Skills

Required

  • 5+ years of experience in security engineering, security operations, or a related role that combined both
  • Hands-on experience with at least one of SOC 2, ISO 27001, or PCI compliance audit cycles
  • Strong application security fundamentals: threat modeling, secure code review, and familiarity with common vulnerability classes (OWASP Top 10, CWE)
  • Experience with security tooling across the development lifecycle: SAST, SCA, DAST, secret scanning, or IaC scanning
  • Working knowledge of AWS

Nice to have

  • AI-assisted development tools

What the JD emphasized

  • SOC 2 (all trust criteria), ISO 27001, and PCI 4.0
  • company's first security engineering role
  • intersection of security engineering and security operations
  • hands-on engineering work
  • operational work
  • high-ownership role
  • direct hand in shaping how AssemblyAI secures its products, infrastructure, and internal tools
  • rapidly growing landscape of agentic AI development
  • 5+ years of experience in security engineering, security operations, or a related role that combined both
  • Hands-on experience with at least one of SOC 2, ISO 27001, or PCI compliance audit cycles