Assembled
Security Engineer
About this role
Lead application and product security for Assembled's SaaS and AI customer support platform, establishing security practices, building vulnerability management tooling, and partnering with engineering teams to balance security with development velocity across millions of customer conversations.
What you'll do
- Lead threat modeling and secure design reviews for SaaS and AI products
- Build and automate security controls for secrets, access, and dependency scanning in CI/CD pipelines
- Establish code scanning, dependency testing, and dynamic application security testing programs
- Develop secure coding training and incident response processes for engineering teams
- Support SOC 2 compliance and security assurance conversations with customers
- Coordinate with penetration testers and manage external vulnerability reporting
What they're looking for
- Application security and threat modeling
- Security code review and vulnerability remediation
- DevSecOps and CI/CD pipeline security automation
- Go and Python code review experience
- AWS and Kubernetes security
- Incident response and security testing (DAST/SAST)
- LLM and AI security evaluation
- Risk assessment and compliance (SOC 2)
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Assembled
Assembled builds AI-driven customer support software with forecasting, scheduling, and workforce optimization capabilities designed to predict support volume and optimize agent staffing at scale. The company is hiring Software Engineers to develop its design system, frontend product experiences, ML-powered interfaces, and AI-enhanced workflows across engineering and design teams.
- Website
- assembled.com
Likely interview questions
- Walk us through a threat modeling exercise you led—what were the key risks you identified and how did you prioritize remediation with engineering?
- Describe your experience integrating security scanning into CI/CD pipelines. Which tools did you use and how did you handle false positives?