# Security Engineer

[Assembledhq](https://gurify.com/jobs?q=Assembledhq) · New York City, NY · Posted 4 days ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/assembledhq/493d9c4f-997b-442e-b1d2-776c014abbaa)

## Job description

### ABOUT ASSEMBLED

Assembled helps companies scale great customer support. As consumers, we’ve all been there. You need help, you’re stuck on hold or going in circles with an AI, and your problem still isn’t solved.

Behind great support is a complex operational problem: thousands of people and AI agents working across teams, time zones, and products as new problems emerge. Assembled gives support leaders the tools to manage that complexity, from AI agents that resolve customer issues to software that forecasts demand, builds schedules, and makes intraday adjustments.

More than 400 companies, including DoorDash, Salesforce, Stripe, and Sephora, trust Assembled https://www.assembled.com/customers. We've raised $71M from NEA, Emergence Capital, Stripe, and Basis Set Ventures and have offices in San Francisco, New York, and London.

### ABOUT THE ROLE

Assembled operates at the intersection of tens of millions of untrusted customer conversations annually, hundreds of thousands of support professionals, and the sensitive data and privileged access they need to get issues fixed.

You'll lead application security across our SaaS and AI products as part of our infrastructure team within Engineering. Working directly with product managers and other engineers, you'll establish our product security practices, influence architecture, and build tooling to manage vulnerabilities from discovery and prioritization through remediation and verification. This is a high-ownership role with broad scope to reshape security at Assembled.

### WHAT YOU'LL BE RESPONSIBLE FOR

- Product and application security. Lead threat modeling, secure design reviews, and vulnerability management across our SaaS and AI products and the underlying infrastructure.

- Tooling and automation. Integrate and automate controls for secrets, access, and dependency security within our engineering workflows and CI/CD pipelines.

- Application security testing. Establish and maintain code, dependency, and secrets scanning, alongside dynamic application security testing. Partner with third-party penetration testers and manage external vulnerability reporting and triage.

- Secure practices. Develop secure design and coding training for engineers. Establish clear processes for routing security issues to engineering owners and following through on fixes.

- Incident response. Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements.

- Partner on security assurance. Bring technical depth to customer security conversations and partner with Finance/Ops on the technical side of SOC 2 and assurance work. Turn recurring customer needs into better product and engineering decisions.

### Examples of projects you could lead:

- Ship adversarial detection for our customer-facing voice agents.

- Build an automated dependency-patching pipeline connected to our AI code generation tools (Devin, Codex, Claude Code, Cursor).

- Secure workforce actions like time off and shift swap requests initiated through Slack, calendar, and HRIS integrations.

### Our tech stack:

- Frontend: TypeScript, React

- Backend: Go, Python

- Data: PostgreSQL, Redis, Snowflake

- Cloud and infrastructure: AWS, Kubernetes, Karpenter

- LLMs: Claude, GPT, Gemini Flash, and open-source models

### ABOUT YOU

- Security engineering expertise. You have 5+ years of hands-on application security experience, including threat modeling, security code reviews, and vulnerability remediation.

- Strong software engineering fundamentals. You have experience writing and reviewing production code in a complex codebase.

- Good risk judgment. You understand the tradeoff between security and shipping velocity. You’ve operated in programs that preserved speed (or can speak to why past programs destroyed it). Engineers trust you as a partner.

- AI-pilled. You actively use AI tools for security investigation, testing, or remediation and can evaluate their limitations. You have a point of view on how this changes the product threat model and how the security role evolves.

People get to this kind of role through many paths. Your background might be in product security, application security, security engineering, DevSecOps, infrastructure, technical consulting, or something less conventional. We care most about how you think and what you have owned.

### NICE TO HAVE

- Background with large-scale, multi-tenant SaaS applications handling sensitive customer data

- Experience securing AI/ML applications, including prompt injection, unauthorized tool use, and adversarial input protections

- Familiarity with our tech stack (described above)

- Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS)

- Experience as a first or early security hire, or building security practices without a large team or established playbook

We know great candidates don’t always meet every requirement listed in a job description. If the role excites you and you believe you can make an impact at Assembled, we encourage you to apply. We value diverse perspectives and are committed to building an inclusive workplace where everyone feels like they belong and has the opportunity to do their best work. We look forward to hearing from you!

For United States Applicants:
Assembled participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the United States.

For United Kingdom Applicants:
Assembled is required to verify your right to work in the UK and will conduct a Right to Work check prior to employment in accordance with applicable law.

**Live in Assembledhq’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- EV [Information Security Engineer (maternity cover)](https://gurify.com/job/information-security-engineer-maternity-cover-at-evoke-8ec4a93fd8ab) Evoke · Herzliya Pituach, Israel, IL · 3 weeks ago
- WR [Security engineer, application security](https://gurify.com/job/security-engineer-application-security-at-writer-f9471c606c4a) Writer · New York City, NY · 2 weeks ago
- GO [Senior Security Engineer, Product Security](https://gurify.com/job/senior-security-engineer-product-security-at-goodleap-788ee656f8bd) Goodleap · Remote, United States · 3 weeks ago
- AD [Staff AI Security Engineer](https://gurify.com/job/staff-ai-security-engineer-at-addepar1-b9f9ad310cbf) Addepar1 · Remote, United States · 5 weeks ago
- OR [DevOps Lead (FedRAMP) - Orca Security](https://gurify.com/job/devops-lead-fedramp-orca-security-at-orcasecurity-e492844776cd) Orcasecurity · United States · 3 weeks ago
- SY [SecOps Security Engineer (Staff-level, L6)](https://gurify.com/job/secops-security-engineer-staff-level-l6-at-synthesia-ae4d3d1cff9b) Synthesia · United States · 4 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Engineer","description":"\u003Ch3\u003EABOUT ASSEMBLED\u003C/h3\u003E\u003Cp\u003EAssembled helps companies scale great customer support. As consumers, we\u2019ve all been there. You need help, you\u2019re stuck on hold or going in circles with an AI, and your problem still isn\u2019t solved.\u003C/p\u003E\u003Cp\u003EBehind great support is a complex operational problem: thousands of people and AI agents working across teams, time zones, and products as new problems emerge. Assembled gives support leaders the tools to manage that complexity, from AI agents that resolve customer issues to software that forecasts demand, builds schedules, and makes intraday adjustments.\u003C/p\u003E\u003Cp\u003EMore than 400 companies, including DoorDash, Salesforce, Stripe, and Sephora, trust Assembled https://www.assembled.com/customers. We\u0026#39;ve raised $71M from NEA, Emergence Capital, Stripe, and Basis Set Ventures and have offices in San Francisco, New York, and London.\u003C/p\u003E\u003Ch3\u003EABOUT THE ROLE\u003C/h3\u003E\u003Cp\u003EAssembled operates at the intersection of tens of millions of untrusted customer conversations annually, hundreds of thousands of support professionals, and the sensitive data and privileged access they need to get issues fixed.\u003C/p\u003E\u003Cp\u003EYou\u0026#39;ll lead application security across our SaaS and AI products as part of our infrastructure team within Engineering. Working directly with product managers and other engineers, you\u0026#39;ll establish our product security practices, influence architecture, and build tooling to manage vulnerabilities from discovery and prioritization through remediation and verification. This is a high-ownership role with broad scope to reshape security at Assembled.\u003C/p\u003E\u003Ch3\u003EWHAT YOU\u0026#39;LL BE RESPONSIBLE FOR\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EProduct and application security. Lead threat modeling, secure design reviews, and vulnerability management across our SaaS and AI products and the underlying infrastructure.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETooling and automation. Integrate and automate controls for secrets, access, and dependency security within our engineering workflows and CI/CD pipelines.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EApplication security testing. Establish and maintain code, dependency, and secrets scanning, alongside dynamic application security testing. Partner with third-party penetration testers and manage external vulnerability reporting and triage.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecure practices. Develop secure design and coding training for engineers. Establish clear processes for routing security issues to engineering owners and following through on fixes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIncident response. Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner on security assurance. Bring technical depth to customer security conversations and partner with Finance/Ops on the technical side of SOC 2 and assurance work. Turn recurring customer needs into better product and engineering decisions.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EExamples of projects you could lead:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EShip adversarial detection for our customer-facing voice agents.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild an automated dependency-patching pipeline connected to our AI code generation tools (Devin, Codex, Claude Code, Cursor).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecure workforce actions like time off and shift swap requests initiated through Slack, calendar, and HRIS integrations.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EOur tech stack:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFrontend: TypeScript, React\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBackend: Go, Python\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EData: PostgreSQL, Redis, Snowflake\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECloud and infrastructure: AWS, Kubernetes, Karpenter\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELLMs: Claude, GPT, Gemini Flash, and open-source models\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EABOUT YOU\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESecurity engineering expertise. You have 5\u002B years of hands-on application security experience, including threat modeling, security code reviews, and vulnerability remediation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong software engineering fundamentals. You have experience writing and reviewing production code in a complex codebase.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGood risk judgment. You understand the tradeoff between security and shipping velocity. You\u2019ve operated in programs that preserved speed (or can speak to why past programs destroyed it). Engineers trust you as a partner.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAI-pilled. You actively use AI tools for security investigation, testing, or remediation and can evaluate their limitations. You have a point of view on how this changes the product threat model and how the security role evolves.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EPeople get to this kind of role through many paths. Your background might be in product security, application security, security engineering, DevSecOps, infrastructure, technical consulting, or something less conventional. We care most about how you think and what you have owned.\u003C/p\u003E\u003Ch3\u003ENICE TO HAVE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EBackground with large-scale, multi-tenant SaaS applications handling sensitive customer data\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing AI/ML applications, including prompt injection, unauthorized tool use, and adversarial input protections\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with our tech stack (described above)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience as a first or early security hire, or building security practices without a large team or established playbook\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe know great candidates don\u2019t always meet every requirement listed in a job description. If the role excites you and you believe you can make an impact at Assembled, we encourage you to apply. We value diverse perspectives and are committed to building an inclusive workplace where everyone feels like they belong and has the opportunity to do their best work. We look forward to hearing from you!\u003C/p\u003E\u003Cp\u003EFor United States Applicants:\u003Cbr /\u003EAssembled participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the United States.\u003C/p\u003E\u003Cp\u003EFor United Kingdom Applicants:\u003Cbr /\u003EAssembled is required to verify your right to work in the UK and will conduct a Right to Work check prior to employment in accordance with applicable law.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-at-assembledhq-280ac1c5d778"},"url":"https://gurify.com/job/security-engineer-at-assembledhq-280ac1c5d778","datePosted":"2026-09-18","validThrough":"2026-11-06T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Assembledhq","sameAs":"https://jobs.ashbyhq.com/assembledhq"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"US","addressLocality":"New York City"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United States","item":"https://gurify.com/jobs/united-states"},{"@type":"ListItem","position":3,"name":"Security Engineer","item":"https://gurify.com/job/security-engineer-at-assembledhq-280ac1c5d778"}]}
```
