Skip to jobs
Unlisted
All jobs

Deepgram · Engineering

GRC and Security Compliance Lead

Where
USA - RemoteRemote · United States only
Experience
5+ yrsguessed from the title
Pay
$165K–$223.3Kbase, as stated on the posting
Posted
First seen by Unlisted 8 Oct, 22:28 UTC
Apply on AshbyOpens the employer's own posting

Checking Ashby for this posting…

Company Overview

Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words. There is no organization in the world that understands voice better than Deepgram.

Company Operating Rhythm

At Deepgram, we expect an AI-first mindset—AI use and comfort aren’t optional, they’re core to how we operate, innovate, and measure performance.

Every team member who works at Deepgram is expected to actively use and experiment with advanced AI tools, and even build your own into your everyday work. We measure how effectively AI is applied to deliver results, and consistent, creative use of the latest AI capabilities is key to success here. Candidates should be comfortable adopting new models and modes quickly, integrating AI into their workflows, and continuously pushing the boundaries of what these technologies can do.

Additionally, we move at the pace of AI. Change is rapid, and you can expect your day-to-day work to evolve just as quickly. This may not be the right role if you’re not excited to experiment, adapt, think on your feet, and learn constantly, or if you’re seeking something highly prescriptive with a traditional 9-to-5.

The Opportunity

Deepgram is looking for a GRC and Security Compliance Lead to own the written and evidentiary backbone of our security and privacy program — the documents and evidence that auditors, enterprise customers, and our own engineers rely on to know what we actually do.

We hold SOC 2, ISO 27001, and PCI DSS obligations, we answer a steady stream of enterprise security questionnaires, and we publish public commitments about how we handle data and how our models are built. Today that work is spread across too few people. You will own it: the evidence, the policies, the public posture documents, and the system that keeps all three consistent with each other.

Context matters here, because the claims you will be writing are unusually specific. Most of our infrastructure is bare metal in colocation datacenters — containerized on Docker, managed with Ansible, and deployed through GitHub Actions — with AWS used for overflow capacity and a small set of services. That means our control environment spans physical and colocation controls, on-premise hosts, and cloud, not a single cloud provider's shared-responsibility model. Deepgram also processes audio — often some of the most sensitive data our customers hold — across several deployment models: hosted with model-improvement opted in, hosted with model-improvement opted out (effectively zero data retention), single-tenant Deepgram Dedicated deployments with regional data residency, and fully self-hosted deployments running in the customer's own environment. Getting a public statement right means understanding which of those a given claim applies to.

Writing is the core skill in this role, and we mean writing that survives a skeptical reader — an auditor, a Fortune 500 security reviewer, an engineer who knows the system better than you do. Where a claim needs technical verification, you define what has to be proven and partner with Security Engineering to prove it; you are not expected to do that engineering work yourself.

This role reports to the Director of Information Security and works closely with Security Engineering, Legal, Research, and Solutions/Sales Engineering.

We are open on level. Strong analyst-level and senior candidates are both in scope, and we will calibrate title, scope, and compensation to demonstrated experience.

Responsibilities

Skills Needed

Nice to Have

Notice: We're aware of individuals impersonating Deepgram recruiters. All legitimate Deepgram recruiting communication comes from an @deepgram.com email address. If you've received a message claiming to be Deepgram, please forward it to careers@deepgram.com.