> Markdown version of [/jobs/ext/2706098-security-engineer](https://www.wearedevelopers.com/jobs/ext/2706098-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Assort Health - **Location:** San Francisco, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing, Cloud Engineering, Cyber Security, Intrusion Detection and Prevention, Open Source Technology, Security Information and Event Management, Working Model 2D, Data Logging, Scripting, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-detection-response-assort-health-9779754 ## About the Role * A security profile with strong exposure to detection and response, rather than a narrow specialization elsewhere. * Strong interest in security monitoring, incident response, and modern observability stacks, with the ability to understand technical environments and identify meaningful security improvements. * Comfort working in a fast-paced startup environment where priorities can shift and the workload can be intense. * A high degree of ownership, autonomy, and initiative, with the ability to make progress in environments that are still being built. * Willingness to learn quickly, stay open-minded, and adapt to new projects or unfamiliar problem spaces as business needs evolve. * Ability to work cross-functionally and build productive relationships with teams across the company. * Good judgment when balancing immediate detection and response needs with longer-term program development. * Strong written and verbal communication skills, with the ability to stay calm under pressure and help support security incidents involving stakeholders across a diverse range of teams and expertise. * A practical, hands-on approach to security work, with interest in solving real operational problems rather than working only at a policy level. What you'll Need * Seeking 2 to 4 years of relevant experience. * Experience in detection engineering, incident response, and/or security operations. * Background in modern observability stacks (e.g., SIEM, EDR, cloud telemetry, logging) and detection primitives is important. * Growing understanding of modern adversary tradecraft (TTPs), with interest in translating it into practical detection strategies and response actions. * Ability to perform technical security work such as reviewing telemetry, assessing infrastructure for detection gaps, and supporting security automation through scripting. * Familiarity with environments that rely on modern cloud and SaaS tooling. * Experience in a startup or similarly fast-growth environment is highly valuable., Our team at Assort Health moves fast, stays focused, and is fueled by a desire to serve our customers and patients. Our company values guide how we work-they are present in how we show up, make decisions and work together to move our mission forward. We bring a Day One Drive, relentlessly striving to improve, keep a 5-Star Focus, as our customers are our lifeblood, always Answer the Call, remembering that ownership and accountability are paramount, and show up with One Pulse, because we are one team, with one rhythm and one result. Our team is growing and we are looking for motivated, hardworking, and passionate talent. If you want to make healthcare accessible for everyone, we'd love to hear from you! ## Description We are looking for a Security Engineer to help build and strengthen security foundations from the ground up in a fast-moving startup environment, with a primary focus on detection and response. This is a strong opportunity for someone early in their career who brings a strong interest in security monitoring, incident response, and detection engineering and is excited to work across these areas as the company scales. The role is designed for someone who wants meaningful ownership, broad exposure within detection and response, and the chance to help shape how security operates as the company matures. You will partner closely with teams across the organization, help close foundational gaps, and contribute to building a more robust, continuous detection and response program over time. This role is based in San Francisco and follows a 4-day in-office working model. Flexible to hire remotely for the right candidate in the US. What you'll be doing * Help build and operate the company's detection and response capabilities, including continuous monitoring, triage, investigation, containment, and remediation of security events across a diverse set of networks and infrastructure. * Support operational rigor and incident readiness by helping build and maintain incident playbooks, on-call and escalation paths, tabletop exercises, and continuous improvement of response quality and speed. * Improve detection quality and coverage by partnering with engineering teams to help ensure critical telemetry is available, reliable, and actionable across cloud, corporate, and production environments. * Partner with Engineering, Product, and Infrastructure to help embed detection and response into the company's systems by design rather than as an afterthought. * Collaborate with internal stakeholders across the organization to implement detection and response projects, improve coverage, and drive progress on high-priority initiatives. * Assist with security efforts related to SOC 2 and help translate immediate audit-driven needs into longer-term, sustainable detection and response practices. * Evaluate and help implement detection and response tooling, with the flexibility to explore a range of approaches, including modern platforms, open-source options, and AI-enabled tools where appropriate. * Take ownership of hands-on technical work, scripting, and automation tasks that help the team move quickly and reduce manual effort. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How to Answer the Interview Question: “Why Do You Want to Be a Software Engineer?”](https://www.wearedevelopers.com/magazine/392-how-to-answer-the-interview-question-why-do-you-want-to-be-a-software-engineer) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)