SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Detection & Response

Assort Health - San Francisco, CA, USA - Hybrid - posted 2026-08-27

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Assort Health is building AI agents that create continuous patient conversations across healthcare delivery, replacing fragmented interactions with intelligent, context-aware systems. The company has grown from 15 people in 2025 to 250+ by end of 2026, with 20x revenue growth in 15 months and $222M raised (Series C at $1.2B valuation). They operate the largest proprietary specialty dataset in healthcare: 240M patient interactions, 62K care protocols, 1.6M decision pathways. As a Security Engineer focused on Detection & Response, you'll build and operate the company's detection and response capabilities from the ground up in a fast-moving startup environment. You'll own continuous monitoring, triage, investigation, containment, and remediation of security events across diverse networks and infrastructure. Key responsibilities include building incident playbooks, on-call escalation paths, and tabletop exercises; improving detection quality by partnering with engineering teams to ensure critical telemetry is available and actionable; embedding detection and response into systems by design; and collaborating across Engineering, Product, and Infrastructure teams. You'll also support SOC 2 compliance efforts, evaluate and implement detection and response tooling (modern platforms, open-source, AI-enabled), and own hands-on technical work including scripting and automation. This role is designed for someone early in their security career who wants meaningful ownership, broad exposure across detection and response domains, and the chance to shape how security operates as the company scales. The ideal candidate brings 2-4 years of relevant experience in detection engineering, incident response, or security operations. You should have background in modern observability stacks (SIEM, EDR, cloud telemetry, logging), growing understanding of adversary tradecraft and TTPs, and ability to perform technical security work like telemetry review and infrastructure assessment. Startup or fast-growth environment experience is highly valuable. You're comfortable in intense, shifting-priority environments, work cross-functionally, communicate clearly under pressure, and take a practical, hands-on approach to solving real operational problems.

Similar roles