CronJobs

security jobs

Security Operations Engineer

Assemblyai · United States

remoteunknown$180,000–$220,000Posted Sep 14, 2026PythonTerraformAWSVantaSOC 2ISO 27001PCI 4.0

Apply on the employer site

About this role

**Security Operations Engineer** **About the role** AssemblyAI runs a mature, multi-framework security and compliance program—including **SOC 2**, **ISO 27001**, and **PCI 4.0**—to protect the infrastructure and customer data behind our Voice AI API. We’re hiring a **Security Operations Engineer** on our IT & Security team to take day-to-day ownership of the operational backbone of that program. This role is centered on **security operations and GRC**: running compliance audit cycles end to end, gathering and organizing evidence, enforcing and verifying controls, executing access reviews, managing vulnerability triage and remediation follow-up, and responding to customer security questionnaires. You’ll also have room to grow the technical side—automation is encouraged, and you’ll build scripts, integrations, and tooling to reduce manual toil. **What you’ll do** - Drive **SOC 2, ISO 27001, PCI 4.0**, and other compliance audit cycles (evidence, controls, auditor coordination, remediation collaboration) - Own the compliance automation platform (**Vanta**): monitor control status, resolve failing checks, keep integrations healthy, and update the risk register - Run **vendor/third-party risk reviews**, security assessments for new tools, periodic re-reviews, and maintain subprocessor/vendor inventories - Partner with **Sales and Legal** on customer/vendor security questionnaires, RFP security sections, and trust-and-safety inquiries - Drive **vulnerability triage and prioritization** across teams; track remediation against SLAs and report metrics - Monitor and respond to alerts from endpoint, cloud, identity, and application security tools (investigate, escalate, close the loop) - Support **incident response** (evidence collection, timeline construction, documentation, and post-incident action items) - Maintain and improve security **runbooks**, process documentation, and operational playbooks - Build automation to reduce manual burden via scripts, integrations, reporting, and tooling **What you’ll need** - **3+ years** in security operations, GRC, IT security, or related work - **2+ years** executing compliance audit cycles (evidence gathering, control documentation, auditor collaboration) - One or more security certifications (e.g., **CISA**, **Security+**, **AWS Security Specialty**, or equivalent) - Experience with recurring security operations (security reviews, vulnerability tracking, alert triage, control monitoring) - Strong organization skills for multi-week evidence collection across stakeholders - Strong written communication (audit documentation, questionnaires, policies, runbooks) - Proficiency in **Python** and comfort reading code written by others - Experience using AI-assisted development tools (e.g., **Claude Code**, **Copilot**, or similar) to write scripts, build automations, and accelerate documentation (AI tool fluency is expected) - **US-based candidates only** **Nice to have** - Application security fundamentals (threat modeling, secure code review, OWASP Top 10 / CWE familiarity) - Security tooling across the SDLC (SAST, SCA, DAST, secret scanning, IaC scanning) and routing findings to owners - Familiarity with **Terraform** and CI/CD pipeline security - Cloud infrastructure knowledge (**AWS preferred**), including IAM and identity/SaaS administration - Experience building/maintaining SIEM detections, queries, and alerting pipelines - Familiarity with endpoint security platforms and cloud security posture tooli

Listing freshness

CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord