Ivo Inc.

Ivo Inc.

Senior Security Engineer

San Francisco · Senior

Sponsorship not specified$249k-$405kDetected 48 days ago
PythonGCPAzureLLMsCybersecurityNetwork SecuritySIEMSOARSOC OperationsDetection EngineeringIncident ResponseComplianceCanvaDNSFirewallWordPressLeadership

About the role

  • This is a hands-on senior IC role with broad scope: detection engineering, incident response, cloud and identity security operations, perimeter and network hardening, vulnerability management, and security automation.
  • The security stakes are real, and so is the impact.

Responsibilities

  • Own detection and response across Ivo's cloud, identity, and endpoint estate.
  • Build and tune detections in our SIEM (Panther). Turn noisy telemetry into high-signal alerts engineers and IT actually act on, with a strong bias toward signal over noise.
  • Lead incident response for infrastructure, identity, and corporate-layer security events. Run investigations end to end, drive containment and recovery, and write the post-incident review.
  • Own cloud security posture across GCP and Azure. Find misconfigurations, prioritize real risk, and partner with engineering to close it.
  • Own perimeter and network security. Manage Cloudflare WAF rules, DNS security, and edge controls, and harden our network and infrastructure config against real-world attack patterns.
  • Run vulnerability management for our infrastructure and assets. Triage, prioritize, and drive remediation to closure rather than just forwarding scanner output.
  • Operate and harden identity and access (Okta, SSO, SAML, SCIM, MFA, RBAC). Own provisioning and deprovisioning hygiene, access reviews, and least-privilege enforcement.
  • Manage endpoint and device security (Kandji for MDM) and email security (Material). Keep the fleet hardened and monitored.
  • Build security automation that removes toil. Script away repetitive work, wire up SOAR-style response, and make the secure path the easy path.
  • Produce and maintain operational evidence for SOC 2 Type II, ISO 27001, and ISO 42001, and support our compliance and enterprise security review programs.

Requirements

  • 5+ years in security operations, detection and response, or infrastructure and cloud security at a SaaS company, including time owning detection or IR for a production environment.
  • Track record of running vulnerability management as a program, not a queue.
  • You can write a runbook engineers follow, a detection writeup that's genuinely useful, and a post-incident review leadership trusts.

Nice to have

  • Detection-as-code experience (Panther, Sigma, or similar) and treating detections like software.
  • Experience securing AI / LLM infrastructure and the operational risks around agents and model access.
  • Series B or earlier experience where you built or scaled a security operations function from limited scaffolding.
  • GCIH, GCIA, GCFA, OSCP, or comparable hands-on credentials.
  • Experience with SOAR or security automation platforms.
  • The person who fills it will define what good detection and response looks like at Ivo for years to come.
  • How far along are we?
  • We launched in early access in 2023.

Skills

  • Where our Application
  • identity, network, workload, and posture management.

Compensation

  • The USD salary range for this role is $249K - $405K.
  • Final offer amounts are determined by multiple factors, including, experience and expertise, and may vary from the amounts listed above.

Benefits

  • Run proactive threat hunting across logs and telemetry, and develop detection coverage against the threats that actually target a company like ours.

This listing is sourced directly from Ivo Inc.'s careers page and normalized into a canonical job model.