Security Engineer

Assembled$130K — $155K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on application security experience
  • Strong software engineering fundamentals with production code experience
  • Good risk judgment balancing security with shipping velocity
  • Proficient in using AI tools for security and understands their limitations
  • Flexible background in security roles such as product security or DevSecOps

Responsibilities

  • Lead product and application security, including threat modeling and vulnerability management
  • Integrate and automate security controls within engineering workflows and CI/CD pipelines
  • Establish application security testing protocols and manage external vulnerability reports
  • Develop secure design and coding training for engineers
  • Coordinate incident response efforts for application vulnerabilities
  • Enhance security assurance processes in collaboration with customers and stakeholders

Benefits

  • Inclusive workplace culture
  • Opportunities for professional growth and impact
  • High-ownership role with broad scope for security practices
  • Ability to shape security measures within innovative SaaS and AI products
Full Job Description
About the role

Assembled operates at the intersection of tens of millions of untrusted customer conversations annually, hundreds of thousands of support professionals, and the sensitive data and privileged access they need to get issues fixed.

You'll lead application security across our SaaS and AI products as part of our infrastructure team within Engineering. Working directly with product managers and other engineers, you'll establish our product security practices, influence architecture, and build tooling to manage vulnerabilities from discovery and prioritization through remediation and verification. This is a high-ownership role with broad scope to reshape security at Assembled.

What you'll be responsible for
  • Product and application security. Lead threat modeling, secure design reviews, and vulnerability management across our SaaS and AI products and the underlying infrastructure.
  • Tooling and automation. Integrate and automate controls for secrets, access, and dependency security within our engineering workflows and CI/CD pipelines.
  • Application security testing. Establish and maintain code, dependency, and secrets scanning, alongside dynamic application security testing. Partner with third-party penetration testers and manage external vulnerability reporting and triage.
  • Secure practices. Develop secure design and coding training for engineers. Establish clear processes for routing security issues to engineering owners and following through on fixes.
  • Incident response. Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements.
  • Partner on security assurance. Bring technical depth to customer security conversations and partner with Finance/Ops on the technical side of SOC 2 and assurance work. Turn recurring customer needs into better product and engineering decisions.


Examples of projects you could lead:
  • Ship adversarial detection for our customer-facing voice agents.
  • Build an automated dependency-patching pipeline connected to our AI code generation tools (Devin, Codex, Claude Code, Cursor).
  • Secure workforce actions like time off and shift swap requests initiated through Slack, calendar, and HRIS integrations.


Our tech stack:
  • Frontend: TypeScript, React
  • Backend: Go, Python
  • Data: PostgreSQL, Redis, Snowflake
  • Cloud and infrastructure: AWS, Kubernetes, Karpenter
  • LLMs: Claude, GPT, Gemini Flash, and open-source models


About you
  • Security engineering expertise. You have 5+ years of hands-on application security experience, including threat modeling, security code reviews, and vulnerability remediation.
  • Strong software engineering fundamentals. You have experience writing and reviewing production code in a complex codebase.
  • Good risk judgment. You understand the tradeoff between security and shipping velocity. You've operated in programs that preserved speed (or can speak to why past programs destroyed it). Engineers trust you as a partner.
  • AI-pilled. You actively use AI tools for security investigation, testing, or remediation and can evaluate their limitations. You have a point of view on how this changes the product threat model and how the security role evolves.

People get to this kind of role through many paths. Your background might be in product security, application security, security engineering, DevSecOps, infrastructure, technical consulting, or something less conventional. We care most about how you think and what you have owned.

Nice to have
  • Background with large-scale, multi-tenant SaaS applications handling sensitive customer data
  • Experience securing AI/ML applications, including prompt injection, unauthorized tool use, and adversarial input protections
  • Familiarity with our tech stack (described above)
  • Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS)
  • Experience as a first or early security hire, or building security practices without a large team or established playbook


We know great candidates don't always meet every requirement listed in a job description. If the role excites you and you believe you can make an impact at Assembled, we encourage you to apply. We value diverse perspectives and are committed to building an inclusive workplace where everyone feels like they belong and has the opportunity to do their best work. We look forward to hearing from you!

About Assembled

Assembled is a workforce management software company founded in 2018 by Ryan Denehy and is headquartered in San Francisco, California. Assembled provides a platform for customer support teams to manage their workforce, including scheduling, forecasting, and performance tracking. The software includes features such as real-time analytics, automated scheduling, and integrations with other customer support tools. Assembled is used by companies such as Stripe, Harry's, and GoFundMe.
Learn more about Assembled
Size
50 employees
Industry

Similar Jobs

More Jobs at Assembled

More Information Technology Jobs

Find similar Security Engineer jobs: