Senior Software Engineer, Security

permanent
Fully Remote

Only accepting applications from: United States

  • Conduct threat modeling and security design reviews for new features, services, and architectural changes—partnering with product and platform engineers early in the design phase.
  • Perform secure code reviews and provide actionable feedback, focusing on authentication, authorization, input handling, secrets management, and data protection.
  • Deploy and maintain security tooling across the development lifecycle—SAST, SCA, DAST, secret scanning, IaC scanning, and CI/CD security guardrails.
  • Support best practices to adopt secure-by-default libraries, frameworks, paved-road patterns, and developer guidance to reduce classes of vulnerabilities across the codebase.
  • Partner with platform engineering on infrastructure and environment security—including AWS resource hardening, Terraform-managed infrastructure reviews, network segmentation, and environment isolation improvements.
  • Contribute to incident response for security events: investigation, root cause analysis, and post-incident hardening.
  • Drive vulnerability triage and prioritization across teams, tracking remediation against targets and reporting metrics.
  • Partner with sales and legal responding to customer and vendor questionnaires, RFP security sections, and trust-and-safety inquiries.
  • Support SOC 2, ISO 27001, PCI 4.0, and other compliance audit cycles by gathering evidence, documenting controls, and coordinating with auditors.
  • Monitor and respond to alerts from endpoint, cloud, and application security tools; manage vulnerability tracking and remediation follow-up across the environment.
  • Execute recurring user access reviews, IAM hygiene tasks, and RBAC maintenance required by compliance frameworks.
  • Maintain and improve security runbooks, process documentation, and operational playbooks—building automation where possible to reduce manual burden using AI-assisted development tools.

Experience

  • 5+ years of experience in security engineering, security operations, or a related role that combined both.
  • Hands-on experience with at least one of SOC 2, ISO 27001, or PCI compliance audit cycles.
  • Strong application security fundamentals: threat modeling, secure code review, and familiarity with common vulnerability classes (OWASP Top 10, CWE).
  • Experience with security tooling across the development lifecycle: SAST, SCA, DAST, secret scanning, or IaC scanning.
  • Working knowledge of AWS infrastructure and services, including IAM, VPC networking, and security configurations.
  • Familiarity with infrastructure-as-code (Terraform preferred) and CI/CD pipeline security.
  • Proficiency in Python and comfort reading code across backend services.
  • Strong written communication skills for writing audit documentation, security questionnaire responses, policy documents, and runbooks.
  • Comfort using AI-assisted development tools (e.g., Claude Code, Copilot, or similar) to write scripts, build automations, and accelerate documentation.

Salary and Perks

Pay range: $180K - $220K

  • Competitive equity grants.
  • 100% employer-paid benefits.
  • Flexibility of being fully remote.
  • 401k match up to 4% for US-based full-time team members.

About AssemblyAI

Industry-leading Speech AI models to automatically recognize and understand speech.

Industry-leading Speech AI models to automatically recognize and understand speech.

View all devops and sysadmin jobs

Workster

Remote Jobs for US Residents

We've built a new platform specifically for US residents to find remote work.

Discover Workster

Power Search

Find the jobs that don't get advertised

We've built a tool to help you discover all of the remote jobs that never get advertised.

Discover Power Search