Assort Health logo
Assort Health
Posted 39 days agoVerified live 2d ago

Security Engineer, Detection & Response

Brief overview

Remote
$160k–$185k/yrStated range
2+ yrsMinimum
Detection EngineeringIncident ResponseSecurity OperationsSecurity MonitoringSIEMEndpoint Detection and Response (EDR)Cloud TelemetrySecurity LoggingAdversary Tradecraft (TTPs)Security Scripting and AutomationCloud Security

About the company

Assort Health logo
Assort Healthassorthealth.com

A healthcare technology company delivering AI-powered patient experience solutions.

Visa sponsorship history

1 year sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
$200,000median wage / yr
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20263
Top sponsored roles
Founding DesignerAgent Software Engineer

Job description

Summary

Assort Health is building AI-powered healthcare systems that support continuous patient conversations and administrative care workflows. The company is seeking a Security Engineer to build and operate detection and response capabilities, strengthen monitoring and incident readiness, improve telemetry and detection coverage, and automate security operations in a growing startup environment.

Responsibilities

  • Help build and operate the company's detection and response capabilities, including continuous monitoring, triage, investigation, containment, and remediation of security events across a diverse set of networks and infrastructure
  • Support operational rigor and incident readiness by helping build and maintain incident playbooks, on-call and escalation paths, tabletop exercises, and continuous improvement of response quality and speed
  • Improve detection quality and coverage by partnering with engineering teams to help ensure critical telemetry is available, reliable, and actionable across cloud, corporate, and production environments
  • Partner with Engineering, Product, and Infrastructure to help embed detection and response into the company's systems by design rather than as an afterthought
  • Collaborate with internal stakeholders across the organization to implement detection and response projects, improve coverage, and drive progress on high-priority initiatives
  • Assist with security efforts related to SOC 2 and help translate immediate audit-driven needs into longer-term, sustainable detection and response practices
  • Evaluate and help implement detection and response tooling, with the flexibility to explore a range of approaches, including modern platforms, open-source options, and AI-enabled tools where appropriate
  • Take ownership of hands-on technical work, scripting, and automation tasks that help the team move quickly and reduce manual effort

Skills

  • • A security profile with strong exposure to detection and response, rather than a narrow specialization elsewhere
  • • Strong interest in security monitoring, incident response, and modern observability stacks, with the ability to understand technical environments and identify meaningful security improvements
  • • Comfort working in a fast-paced startup environment where priorities can shift and the workload can be intense
  • • A high degree of ownership, autonomy, and initiative, with the ability to make progress in environments that are still being built
  • • Willingness to learn quickly, stay open-minded, and adapt to new projects or unfamiliar problem spaces as business needs evolve
  • • Ability to work cross-functionally and build productive relationships with teams across the company
  • • Good judgment when balancing immediate detection and response needs with longer-term program development
  • • Strong written and verbal communication skills, with the ability to stay calm under pressure and help support security incidents involving stakeholders across a diverse range of teams and expertise
  • • A practical, hands-on approach to security work, with interest in solving real operational problems rather than working only at a policy level
  • • Seeking 2 to 4 years of relevant experience
  • • Experience in detection engineering, incident response, and/or security operations
  • • Background in modern observability stacks (e.g., SIEM, EDR, cloud telemetry, logging) and detection primitives is important
  • • Growing understanding of modern adversary tradecraft (TTPs), with interest in translating it into practical detection strategies and response actions
  • • Ability to perform technical security work such as reviewing telemetry, assessing infrastructure for detection gaps, and supporting security automation through scripting
  • • Familiarity with environments that rely on modern cloud and SaaS tooling
  • • Experience in a startup or similarly fast-growth environment is highly valuable

Qualifications

Must Haves

  • • A security profile with strong exposure to detection and response, rather than a narrow specialization elsewhere
  • • Strong interest in security monitoring, incident response, and modern observability stacks, with the ability to understand technical environments and identify meaningful security improvements
  • • Comfort working in a fast-paced startup environment where priorities can shift and the workload can be intense
  • • A high degree of ownership, autonomy, and initiative, with the ability to make progress in environments that are still being built
  • • Willingness to learn quickly, stay open-minded, and adapt to new projects or unfamiliar problem spaces as business needs evolve
  • • Ability to work cross-functionally and build productive relationships with teams across the company
  • • Good judgment when balancing immediate detection and response needs with longer-term program development
  • • Strong written and verbal communication skills, with the ability to stay calm under pressure and help support security incidents involving stakeholders across a diverse range of teams and expertise
  • • A practical, hands-on approach to security work, with interest in solving real operational problems rather than working only at a policy level
  • • Seeking 2 to 4 years of relevant experience
  • • Experience in detection engineering, incident response, and/or security operations
  • • Background in modern observability stacks (e.g., SIEM, EDR, cloud telemetry, logging) and detection primitives is important
  • • Growing understanding of modern adversary tradecraft (TTPs), with interest in translating it into practical detection strategies and response actions
  • • Ability to perform technical security work such as reviewing telemetry, assessing infrastructure for detection gaps, and supporting security automation through scripting
  • • Familiarity with environments that rely on modern cloud and SaaS tooling
  • • Experience in a startup or similarly fast-growth environment is highly valuable

Benefits

  • Employee stock options so you share in our success.
  • Annual budget for professional development, plus training opportunities to help you grow.
  • Office setup stipend to outfit your in-office workspace.
  • Medical, dental, and vision insurance.
  • Flexible PTO.
  • Lunch, dinner, and snack breaks.
  • Fitness stipend reimbursing monthly membership costs.
  • Commuter benefits covering eligible transportation costs.
  • 401(k) retirement savings plan.
  • The role follows a 4-day in-office working model, with flexibility to hire remotely for the right candidate in the US.

More jobs like this