SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer

Assembled - New York, NY, United States - In-office - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Assembled helps companies scale customer support operations by providing tools for managing AI agents and support teams across time zones and products. The company serves 400+ customers including DoorDash, Salesforce, Stripe, and Sephora, and has raised $71M from top-tier investors. You will lead application security across Assembled's SaaS and AI products as part of the infrastructure team within Engineering. This is a high-ownership role reporting to engineering leadership with broad scope to establish and reshape security practices at the company. Key responsibilities include: - Product and application security: Lead threat modeling, secure design reviews, and vulnerability management across SaaS and AI products and underlying infrastructure. - Tooling and automation: Integrate and automate controls for secrets, access, and dependency security within engineering workflows and CI/CD pipelines. - Application security testing: Establish code, dependency, and secrets scanning, alongside dynamic application security testing. Partner with third-party penetration testers and manage external vulnerability reporting and triage. - Secure practices: Develop secure design and coding training for engineers. Establish processes for routing security issues to engineering owners and following through on fixes. - Incident response: Respond to security incidents involving application vulnerabilities, coordinate remediation efforts, and drive post-incident improvements. - Security assurance: Bring technical depth to customer security conversations and partner with Finance/Ops on SOC 2 and assurance work. Turn recurring customer needs into product and engineering decisions. Example projects include shipping adversarial detection for customer-facing voice agents, building an automated dependency-patching pipeline connected to AI code generation tools, and securing workforce actions initiated through Slack, calendar, and HRIS integrations. Tech stack: TypeScript/React (frontend), Go/Python (backend), PostgreSQL/Redis/Snowflake (data), AWS/Kubernetes/Karpenter (cloud/infrastructure), Claude/GPT/Gemini Flash/open-source models (LLMs). REQUIREMENTS: - 5+ years of hands-on application security experience, including threat modeling, security code reviews, and vulnerability remediation - Strong software engineering fundamentals with experience writing and reviewing production code in complex codebases - Good risk judgment; understand tradeoffs between security and shipping velocity; engineers trust you as a partner - Active use of AI tools for security investigation, testing, or remediation; ability to evaluate their limitations and point of view on how this changes product threat models NICE TO HAVE: - Background with large-scale, multi-tenant SaaS applications handling sensitive customer data - Experience securing AI/ML applications, including prompt injection, unauthorized tool use, and adversarial input protections - Familiarity with the stated tech stack - Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS) - Experience as a first or early security hire, or building security practices without a large team or established playbook

Similar roles