Ivo Inc.
Senior Security Engineer
San Francisco · Senior
Sponsorship not specified$249k-$405kDetected 48 days ago
PythonGCPAzureLLMsCybersecurityNetwork SecuritySIEMSOARSOC OperationsDetection EngineeringIncident ResponseComplianceCanvaDNSFirewallWordPressLeadership
About the role
- This is a hands-on senior IC role with broad scope: detection engineering, incident response, cloud and identity security operations, perimeter and network hardening, vulnerability management, and security automation.
- The security stakes are real, and so is the impact.
Responsibilities
- Own detection and response across Ivo's cloud, identity, and endpoint estate.
- Build and tune detections in our SIEM (Panther). Turn noisy telemetry into high-signal alerts engineers and IT actually act on, with a strong bias toward signal over noise.
- Lead incident response for infrastructure, identity, and corporate-layer security events. Run investigations end to end, drive containment and recovery, and write the post-incident review.
- Own cloud security posture across GCP and Azure. Find misconfigurations, prioritize real risk, and partner with engineering to close it.
- Own perimeter and network security. Manage Cloudflare WAF rules, DNS security, and edge controls, and harden our network and infrastructure config against real-world attack patterns.
- Run vulnerability management for our infrastructure and assets. Triage, prioritize, and drive remediation to closure rather than just forwarding scanner output.
- Operate and harden identity and access (Okta, SSO, SAML, SCIM, MFA, RBAC). Own provisioning and deprovisioning hygiene, access reviews, and least-privilege enforcement.
- Manage endpoint and device security (Kandji for MDM) and email security (Material). Keep the fleet hardened and monitored.
- Build security automation that removes toil. Script away repetitive work, wire up SOAR-style response, and make the secure path the easy path.
- Produce and maintain operational evidence for SOC 2 Type II, ISO 27001, and ISO 42001, and support our compliance and enterprise security review programs.
Requirements
- 5+ years in security operations, detection and response, or infrastructure and cloud security at a SaaS company, including time owning detection or IR for a production environment.
- Track record of running vulnerability management as a program, not a queue.
- You can write a runbook engineers follow, a detection writeup that's genuinely useful, and a post-incident review leadership trusts.
Nice to have
- Detection-as-code experience (Panther, Sigma, or similar) and treating detections like software.
- Experience securing AI / LLM infrastructure and the operational risks around agents and model access.
- Series B or earlier experience where you built or scaled a security operations function from limited scaffolding.
- GCIH, GCIA, GCFA, OSCP, or comparable hands-on credentials.
- Experience with SOAR or security automation platforms.
- The person who fills it will define what good detection and response looks like at Ivo for years to come.
- How far along are we?
- We launched in early access in 2023.
Skills
- Where our Application
- identity, network, workload, and posture management.
Compensation
- The USD salary range for this role is $249K - $405K.
- Final offer amounts are determined by multiple factors, including, experience and expertise, and may vary from the amounts listed above.
Benefits
- Run proactive threat hunting across logs and telemetry, and develop detection coverage against the threats that actually target a company like ours.
Apply directly at Ivo Inc. →Create a free account for alerts like thisView Ivo Inc. immigration profile
This listing is sourced directly from Ivo Inc.'s careers page and normalized into a canonical job model.