
Meriplex
Cybersecurity engineer
The Cyber Security Engineer provides hands‑on cybersecurity engineering and advisory services to Meriplex clients. This role works directly with client environments to design, deploy, configure, and...

Deepgram
·6 days agoDeepgram
·6 days agoLocation
remote, United States
Commitment
Full Time
Level
Senior (5+ years)
Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words. There is no organization in the world that understands voice better than Deepgram.
At Deepgram, we expect an AI-first mindset—AI use and comfort aren’t optional, they’re core to how we operate, innovate, and measure performance. Every team member who works at Deepgram is expected to actively use and experiment with advanced AI tools, and even build your own into your everyday work. We measure how effectively AI is applied to deliver results, and consistent, creative use of the latest AI capabilities is key to success here. Candidates should be comfortable adopting new models and modes quickly, integrating AI into their workflows, and continuously pushing the boundaries of what these technologies can do.
Additionally, we move at the pace of AI. Change is rapid, and you can expect your day-to-day work to evolve just as quickly. This may not be the right role if you’re not excited to experiment, adapt, think on your feet, and learn constantly, or if you’re seeking something highly prescriptive with a traditional 9-to-5.
Deepgram is looking for a Security Engineer to build and automate the technical controls behind our security program. Most of our infrastructure is bare metal in colocation datacenters — GPU-intensive, running containerized workloads on Docker, managed with Ansible, and shipped through CI/CD on GitHub Actions — with AWS used for overflow capacity and a small set of services. Our engineering culture is high-trust and fast-moving. That means controls have to be delivered as code, be reproducible, and produce their own audit evidence — anything that depends on someone remembering to do it manually will not survive.
You will own real surface area: host hardening and configuration management across the fleet, vulnerability and patch management, penetration testing, container security, detection and response, CI/CD and supply chain security, and the engineering work behind our SOC 2, PCI DSS, and ISO 27001 obligations. You will also be expected to use AI and agentic tooling aggressively to punch above your weight on a small team, and to help us secure the AI systems we build and the AI tools we adopt internally.
This is the hands-on technical seat. A GRC and Security Compliance Lead owns policy authorship, security questionnaires, and the auditor relationship; you own the controls themselves and the evidence they generate, and you give that role the technical answers it needs.
This role reports to the Director of Information Security.
Deepgram builds foundational voice AI — speech-to-text, text-to-speech, and voice agent infrastructure — used by enterprises and developers to build production voice applications at scale. Our models are trained and served on our own infrastructure, and we offer hosted, dedicated single-tenant, and self-hosted deployment options so customers can meet their own data residency and retention requirements. Learn more at deepgram.com.
Solid experience in security engineering or infrastructure engineering with a security focus — enough that you have owned controls in production, not just recommended them.
Deep Linux. You should be comfortable hardening, debugging, and reasoning about a large fleet of physical Linux hosts — users and sudo, SSH, systemd, kernel and package updates, host firewalls, and what a host-based agent is actually doing.
Ansible at fleet scale is required. You automate first and document second.
Strong scripting. Python and/or Go, plus real shell competence.
Production experience securing Docker containers and the pipelines that build them.
Hands-on experience securing GitHub and GitHub Actions: branch protection, CODEOWNERS, workflow permissions, secrets, and third-party action risk.
Experience running vulnerability and patch management as an ongoing program — including the unglamorous part, which is getting other teams to actually ship the fix.
Experience managing third-party penetration tests from the inside: scoping them well, and turning a report into closed engineering work rather than a PDF in a folder.
Hands-on involvement in at least one formal audit — ISO 27001, PCI DSS, or SOC 2 — as the engineer producing and defending evidence, not only as a reader of the report.
Comfortable using AI coding and agentic tools in daily work, and clear-eyed about their risks: prompt injection, secret leakage, and supply chain exposure.
Pragmatic. Controls that block shipping without a proportionate risk reduction get routed around, and we would rather you name the trade-off than pretend it does not exist.
Datacenter or colocation experience: network segmentation, out-of-band management (IPMI/BMC), physical and vendor controls.
Detection engineering or SIEM/HIDS ownership at scale (for example Wazuh, OSSEC, Elastic).
Secrets management with HashiCorp Vault.
AWS security (IAM, SCPs, VPC) and Terraform.
Kubernetes security.
Offensive security background: penetration testing or red teaming.
PCI DSS work inside a cardholder data environment.
Ownership of a secure SDLC program.
Experience with GPU infrastructure, ML platforms, or multi-tenant inference workloads.
Certifications such as OSCP, GIAC, CISSP, or AWS Security Specialty.
Notice: We're aware of individuals impersonating Deepgram recruiters. All legitimate Deepgram recruiting communication comes from an @deepgram.com email address. If you've received a message claiming to be Deepgram, please forward it to careers@deepgram.com.

Meriplex
The Cyber Security Engineer provides hands‑on cybersecurity engineering and advisory services to Meriplex clients. This role works directly with client environments to design, deploy, configure, and...

Inspira Financial
Position Summary: The Sr. Security Engineer will report to the Technology Department. This role will build and examine reports, data, and analytics to improve and troubleshoot security systems. The...

Meta
Meta Security is looking for an experienced Security Engineer to join our Nation State leadership team. You will be working across security and engineering teams to drive strategy, influence...

Buckland
Who we are For over 70 years Buckland has been working to help companies across the world experience global trade in a better way. Buckland employs a unique approach to global trade that focuses on...

Jobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principle Security Engineer based in United States. The Principle...

Microsoft
Overview The Microsoft Windows Security team is looking for a learn-it-all security engineer that will help secure Microsoft Windows products and services, with focus on offensive security, security...

Meta
Meta's Security Engineering team is looking for a security engineer to help protect the billions of people who use Meta's products and services. In this role, you will identify security...