1,212,140open jobs
68,209companies
216,200added this week
Browse all
Salary
$150k – $245k per year
Location
Remote (United States)
Visa
green card filings: 1
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Oct 1, 2026. Deepgram scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Deepgram is an AI speech platform that provides real-time and asynchronous automated speech recognition (ASR) and text-to-speech (TTS) APIs. Built on custom deep learning models, its technology delivers fast, accurate, and cost-effective voice transcription, language understanding, and audio synthesis for developers and enterprise businesses. Headquartered in San Francisco, California, the company enables organizations to integrate advanced voice capabilities and intelligence directly into their applications and conversational AI workflows.

Company Overview

Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words. There is no organization in the world that understands voice better than Deepgram.

Company Operating Rhythm

At Deepgram, we expect an AI-first mindset-AI use and comfort aren’t optional, they’re core to how we operate, innovate, and measure performance.

Every team member who works at Deepgram is expected to actively use and experiment with advanced AI tools, and even build your own into your everyday work. We measure how effectively AI is applied to deliver results, and consistent, creative use of the latest AI capabilities is key to success here. Candidates should be comfortable adopting new models and modes quickly, integrating AI into their workflows, and continuously pushing the boundaries of what these technologies can do.

Additionally, we move at the pace of AI. Change is rapid, and you can expect your day-to-day work to evolve just as quickly. This may not be the right role if you’re not excited to experiment, adapt, think on your feet, and learn constantly, or if you’re seeking something highly prescriptive with a traditional 9-to-5.

The Opportunity

Deepgram is looking for a Security Engineer to build and automate the technical controls behind our security program. Most of our infrastructure is bare metal in colocation datacenters - GPU-intensive, running containerized workloads on Docker, managed with Ansible, and shipped through CI/CD on GitHub Actions - with AWS used for overflow capacity and a small set of services. Our engineering culture is high-trust and fast-moving. That means controls have to be delivered as code, be reproducible, and produce their own audit evidence - anything that depends on someone remembering to do it manually will not survive.

You will own real surface area: host hardening and configuration management across the fleet, vulnerability and patch management, penetration testing, container security, detection and response, CI/CD and supply chain security, and the engineering work behind our SOC 2, PCI DSS, and ISO 27001 obligations. You will also be expected to use AI and agentic tooling aggressively to punch above your weight on a small team, and to help us secure the AI systems we build and the AI tools we adopt internally.

This is the hands-on technical seat. A GRC and Security Compliance Lead owns policy authorship, security questionnaires, and the auditor relationship; you own the controls themselves and the evidence they generate, and you give that role the technical answers it needs.

This role reports to the Director of Information Security.

Note: as reflected on our published compensation ranges, we are open on level. Strong mid-level and senior candidates are both in scope, and we will calibrate title, scope, and compensation to demonstrated experience.

About Deepgram

Deepgram builds foundational voice AI - speech-to-text, text-to-speech, and voice agent infrastructure - used by enterprises and developers to build production voice applications at scale. Our models are trained and served on our own infrastructure, and we offer hosted, dedicated single-tenant, and self-hosted deployment options so customers can meet their own data residency and retention requirements. Learn more at deepgram.com.

Responsibilities

  • Build, deploy, and maintain security controls across our bare-metal fleet and AWS footprint - access management, network segmentation and firewalling, encryption and secrets management, logging and detection coverage, endpoint security, and vulnerability management.

  • Own configuration management and host hardening as code with Ansible, so baselines are reproducible across hundreds of Linux hosts and drift is detectable rather than merely documented.

  • Secure containerized workloads: Docker image build pipelines, registry scanning, runtime hardening and detection, and secrets management.

  • Run vulnerability management end to end - discovery, prioritization by real exploitability rather than raw CVSS, driving remediation with engineering teams, and reporting on it.

  • Own patch and update management as a program: the server fleet, the endpoint fleet, base images, OS and package updates, firmware where it matters, and dependency upgrades. Set and hold patch SLAs, track exceptions, and automate the routine cases so they do not depend on anyone remembering.

  • Own the penetration testing lifecycle: scoping and vendor selection, scheduling, triaging findings into engineering work with real owners and dates, verifying fixes on retest, and producing the summary we can share with customers.

  • Write detections, tune out noise, and take part in incident response. Improve log, telemetry, and security-agent coverage where we are blind.

  • Run periodic log and access reviews as a standing control, and automate the collection so each cycle produces its own evidence rather than a scramble.

  • Automate compliance evidence collection for SOC 2, PCI DSS, and ISO 27001, and support audit fieldwork on technical questions - the GRC lead owns the auditor relationship and the narrative; you own the systems that make the evidence true and repeatable.

  • Harden GitHub Actions CI/CD and the software supply chain: dependency and secret scanning, action pinning, SBOM, artifact and image signing, least-privilege OIDC in place of long-lived credentials.

  • Apply AI and agentic tooling to security work - triage, evidence gathering, code review, detection engineering - and help secure how the rest of the company uses AI.

  • Provide the technical input behind customer-facing security work: questionnaire and architecture answers, penetration test summaries, and hardening guidance for customers running Deepgram self-hosted.

Skills Needed

  • Solid experience in security engineering or infrastructure engineering with a security focus - enough that you have owned controls in production, not just recommended them.

  • Deep Linux. You should be comfortable hardening, debugging, and reasoning about a large fleet of physical Linux hosts - users and sudo, SSH, systemd, kernel and package updates, host firewalls, and what a host-based agent is actually doing.

  • Ansible at fleet scale is required. You automate first and document second.

  • Strong scripting. Python and/or Go, plus real shell competence.

  • Production experience securing Docker containers and the pipelines that build them.

  • Hands-on experience securing GitHub and GitHub Actions: branch protection, CODEOWNERS, workflow permissions, secrets, and third-party action risk.

  • Experience running vulnerability and patch management as an ongoing program - including the unglamorous part, which is getting other teams to actually ship the fix.

  • Experience managing third-party penetration tests from the inside: scoping them well, and turning a report into closed engineering work rather than a PDF in a folder.

  • Hands-on involvement in at least one formal audit - ISO 27001, PCI DSS, or SOC 2 - as the engineer producing and defending evidence, not only as a reader of the report.

  • Comfortable using AI coding and agentic tools in daily work, and clear-eyed about their risks: prompt injection, secret leakage, and supply chain exposure.

  • Pragmatic. Controls that block shipping without a proportionate risk reduction get routed around, and we would rather you name the trade-off than pretend it does not exist.

Nice to Have

  • Datacenter or colocation experience: network segmentation, out-of-band management (IPMI/BMC), physical and vendor controls.

  • Detection engineering or SIEM/HIDS ownership at scale (for example Wazuh, OSSEC, Elastic).

  • Secrets management with HashiCorp Vault.

  • AWS security (IAM, SCPs, VPC) and Terraform.

  • Kubernetes security.

  • Offensive security background: penetration testing or red teaming.

  • PCI DSS work inside a cardholder data environment.

  • Ownership of a secure SDLC program.

  • Experience with GPU infrastructure, ML platforms, or multi-tenant inference workloads.

  • Certifications such as OSCP, GIAC, CISSP, or AWS Security Specialty.

Notice: We're aware of individuals impersonating Deepgram recruiters. All legitimate Deepgram recruiting communication comes from an @ deepgram.com email address. If you've received a message claiming to be Deepgram, please forward it to [email protected].

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,212,140 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $83k – $165k per year (Estimated) • Remote (United Kingdom, Ireland) • Full-Time • 5+ years exp • PhD • Belfast
Python
Go
JavaScript
Rust
TypeScript
AI/ML
Hugging Face
Frontend
GraphQL
npm
DevOps
Rest API
Terraform
Datadog
CI/CD
AWS
Docker
eBPF
GitHub
Amazon S3
IAM
Cybersecurity
Okta
Snyk
Trivy
Semgrep
ISO 27001
Wiz
OWASP Top 10
SOC 2
CVSS
Zero Trust
Threat Modeling
SLSA
Sigstore
Management
Slack
Google Docs
Apply
≈ $120k – $254k per year (Estimated) • Remote (likely Germany) • Full-Time
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
Windows
Cybersecurity
ISO 27001
Management
Agile
Apply
≈ $72k – $167k per year (Estimated) • Remote (Germany) • Full-Time • Düsseldorf
Python
PowerShell
DevOps
Azure
AWS
Cybersecurity
Nessus
Qualys Cloud Platform
ISO 27001
SOC 2
SIEM
Apply
Remote (likely Germany) • Full-Time
Databases
PostgreSQL
Redis
Memcached
MariaDB
DevOps
Ansible
Helm
Loki
cert-manager
Prometheus
GitLab CI
GitOps
Kubernetes
Grafana
Thanos
External Secrets
Helmfile
SLI/SLO/SLA
Linux
DNS
Cybersecurity
Keycloak
Least Privilege
Apply
≈ $70k – $163k per year (Estimated) • Remote (Germany) • Full-Time • Germany
DevOps
Azure
Linux
Windows
TCP/IP
DNS
Cybersecurity
Microsoft Defender
Microsoft Defender for Cloud
Sophos
Microsoft Entra ID
SIEM
Apply
≈ $13k – $32k per year (Estimated) • In office • 7+ years exp • Bengaluru
Python
SQL
DevOps
GCP
Azure DevOps
GitHub Actions
Azure
CI/CD
Jenkins
AWS
Amazon CloudWatch
Cybersecurity
OWASP Top 10
Management
ServiceNow
ITSM
QA
Selenium
JMeter
Cypress
Playwright
Postman
Rest-Assured
Locust
Apply
≈ $19k – $45k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Makati
Python
DevOps
Ansible
GCP
Azure
AWS
TCP/IP
VPN
VLAN
BGP
OSPF
MPLS
Apply
≈ $51k – $110k per year (Estimated) • In office • Full-Time • La Paz
JavaScript
SQL
C#
C#
.NET
Databases
PostgreSQL
Azure Cosmos DB
Frontend
Next.js
React.js
DevOps
Azure
CI/CD
Apply
≈ $60k – $116k per year (Estimated) • In office • 2+ years exp • Associate's Degree • United States
Python
PowerShell
Bash
DevOps
Red Hat
VMWare
Linux
Windows
Cybersecurity
Qualys Cloud Platform
Tanium
Active Directory
Management
ITIL
Apply
$82k – $108k per year • In office • 2+ years exp • Bachelor's Degree • Princeton
Python
C++
AI/ML
OpenCV
NumPy
DevOps
Linux
Apply
$85k – $95k per year • Hybrid • Full-Time • 1+ year exp • Ann Arbor
AI/ML
Text-to-Speech
Deepgram
Vapi
Voice Agents
Mobile
Twilio
DevOps
Cloudflare
Apply
≈ $99k – $231k per year (Estimated) • Remote (United States) • Full-Time
Python
TypeScript
AI/ML
Speech Recognition
LLM
Text-to-Speech
Deepgram
Vapi
Voice Agents
Mobile
Twilio
DevOps
Cloudflare
Apply
Product Designer II 2 days ago
$115k – $143k per year • Remote (United States) • Full-Time
AI/ML
Text-to-Speech
Deepgram
Vapi
Voice Agents
Mobile
Twilio
DevOps
Cloudflare
Apply
$165k – $223k per year • Hybrid • Full-Time • United States
Python
Rust
TypeScript
SQL
AI/ML
Text-to-Speech
Deepgram
Vapi
EU AI Act
Voice Agents
Mobile
Twilio
DevOps
AWS
Docker
Cloudflare
Cybersecurity
ISO 27001
PCI DSS
SOC 2
GDPR
HIPAA
Apply
$165k – $223k per year • Hybrid • Full-Time • United States
SQL
AI/ML
AI Agents
Text-to-Speech
Deepgram
Vapi
EU AI Act
NIST AI RMF
Voice Agents
Mobile
Twilio
DevOps
Cloudflare
Cybersecurity
ISO 27001
PCI DSS
SOC 2
GDPR
HIPAA
FedRAMP
Apply
See all jobs
This is one of many
1,212,140 more open roles from verified company boards, updated every day.