Senior Software Engineer, Security at AssemblyAI. Location Information: United States. AssemblyAI is an applied artificial intelligence company. We use the latest deep learning technology to build practical products that bring futuristic ideas to life.. Our team includes researchers, engineers, and designers that have worked at some of the largest technology companies all over the world. Our main office is located in downtown San Francisco.. At AssemblyAI, we believe that cutting edge artificial intelligence technology should not be limited to only those with the funding or resources to invest in it.. Our goal is to help make creative, new ideas possible by making AI technology accessible to everyone through easy to use products, whether you are an independent developer, startup, or global company.. Conduct threat modeling and security design reviews for new features, services, and architectural changes—partnering with product and platform engineers early in the design phase.. Perform secure code reviews and provide actionable feedback, focusing on authentication, authorization, input handling, secrets management, and data protection.. Deploy and maintain security tooling across the development lifecycle—SAST, SCA, DAST, secret scanning, IaC scanning, and CI/CD security guardrails.. Support best practices to adopt secure-by-default libraries, frameworks, paved-road patterns, and developer guidance to reduce classes of vulnerabilities across the codebase.. Partner with platform engineering on infrastructure and environment security—including AWS resource hardening, Terraform-managed infrastructure reviews, network segmentation, and environment isolation improvements.. Contribute to incident response for security events: investigation, root cause analysis, and post-incident hardening.. Drive vulnerability triage and prioritization across teams, tracking remediation against targets and reporting metrics.. Partner with sales and legal responding to customer and vendor questionnaires, RFP security sections, and trust-and-safety inquiries.. Support SOC 2, ISO 27001, PCI 4.0, and other compliance audit cycles by gathering evidence, documenting controls, and coordinating with auditors.. Monitor and respond to alerts from endpoint, cloud, and application security tools; manage vulnerability tracking and remediation follow-up across the environment.. Execute recurring user access reviews, IAM hygiene tasks, and RBAC maintenance required by compliance frameworks.. Maintain and improve security runbooks, process documentation, and operational playbooks—building automation where possible to reduce manual burden using AI-assisted development tools.. 5+ years of experience in security engineering, security operations, or a related role that combined both.. Hands-on experience with at least one of SOC 2, ISO 27001, or PCI compliance audit cycles.. Strong application security fundamentals: threat modeling, secure code review, and familiarity with common vulnerability classes (OWASP Top 10, CWE).. Experience with security tooling across the development lifecycle: SAST, SCA, DAST, secret scanning, or IaC scanning.. Working knowledge of AWS infrastructure and services, including IAM, VPC networking, and security configurations.. Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security.. Proficiency in Python and comfort reading code across backend services.. Strong written communication skills for writing audit documentation, security questionnaire responses, policy documents, and runbooks.. Comfort using AI-assisted development tools (e.g., Claude Code, Copilot, or similar) to write scripts, build automations, and accelerate documentation.. Pay range:. $180K - $220K. Competitive equity grants.. 100% employer-paid benefits.. Flexibility of being fully remote.. 401k match up to 4% for US-based full-time team members.
Senior Software Engineer, Security at AssemblyAI