Security Engineer
AssembledHQ · New York City, NY
About this role
**Security Engineer — Assembled** **About Assembled** Assembled helps companies scale great customer support. Behind great support is a complex operational problem: thousands of people and AI agents working across teams, time zones, and products as new problems emerge. Assembled gives support leaders tools to manage that complexity—from AI agents that resolve customer issues to software that forecasts demand, builds schedules, and makes intraday adjustments. More than 400 companies (including DoorDash, Salesforce, Stripe, and Sephora) trust Assembled: https://www.assembled.com/customers **About the Role** You’ll lead application security across Assembled’s SaaS and AI products as part of the Infrastructure team within Engineering. Working with product managers and engineers, you’ll establish product security practices, influence architecture, and build tooling to manage vulnerabilities from discovery and prioritization through remediation and verification. **What You’ll Be Responsible For** - **Product & application security:** Lead threat modeling, secure design reviews, and vulnerability management across SaaS/AI products and underlying infrastructure. - **Tooling & automation:** Integrate and automate controls for secrets, access, and dependency security in engineering workflows and CI/CD. - **Application security testing:** Maintain code/dependency/secrets scanning and dynamic application security testing. Partner with third-party penetration testers and manage external vulnerability reporting and triage. - **Secure practices:** Develop secure design/coding training. Create processes for routing security issues to engineering owners and ensuring fixes are completed. - **Incident response:** Respond to security incidents involving application vulnerabilities, coordinate remediation, and drive post-incident improvements. - **Security assurance partnership:** Bring technical depth to customer security conversations and partner with Finance/Ops on SOC 2 and assurance work. **Examples of Projects You Could Lead** - Ship adversarial detection for customer-facing voice agents. - Build an automated dependency-patching pipeline connected to AI code generation tools (Devin, Codex, Claude Code, Cursor). - Secure workforce actions (e.g., time off and shift swap requests) initiated through Slack, calendar, and HRIS integrations. **Tech Stack** - **Frontend:** TypeScript, React - **Backend:** Go, Python - **Data:** PostgreSQL, Redis, Snowflake - **Cloud & infrastructure:** AWS, Kubernetes, Karpenter - **LLMs:** Claude, GPT, Gemini Flash, and open-source models **About You** - **5+ years application security experience** (threat modeling, security code reviews, vulnerability remediation) - **Strong software engineering fundamentals**; can write/review production code in a complex codebase - **Good risk judgment** and ability to balance security with shipping velocity - **AI-pilled:** actively use AI tools for security investigation/testing/remediation and understand their limitations **Nice to Have** - Experience securing large-scale, multi-tenant SaaS handling sensitive customer data - Experience securing AI/ML applications (e.g., prompt injection, unauthorized tool use, adversarial input protections) - Familiarity with the tech stack listed above - Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS) - Experience as a first/early security hire or building security practices without an established playb
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.