Ivo Inc.
Lead Application Security Engineer
San Francisco
Sponsorship not specified$220k-$300kDetected 48 days ago
TypeScriptNode.jsCode ReviewGCPAzureKubernetesOAuthLLMsA/B TestingCybersecurityPenetration TestingIncident ResponseComplianceCanvaResearchCommunication
About the role
- The security stakes are real, and so is the impact.
Responsibilities
- Own application security across Ivo's web app, API surface, and the systems behind them.
- Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive-minded experimentation, and partner with engineers to ship the fix.
- Lead manual code review for security-sensitive changes: authentication, authorization, multi-tenancy, integrations, and customer data handling.
- Run threat modeling with engineering as new features and products are designed, across the full product surface including LLM and agent components.
- Manage our pen test program and ad-hoc engagements end to end. Scope work, manage vendors, triage findings, and drive remediation to closure with engineering.
- Build and maintain our application security tooling: SAST, DAST, SCA, secrets detection, and IaC scanning, with a strong bias toward signal over noise.
- Embed security into the SDLC: PR-time checks, security champions, design review gates, and secure-by-default patterns engineers actually want to use.
- Conduct deep reviews of identity and access surfaces (Firebase Auth, WorkOS, SSO, SAML, SCIM, RBAC) and partner with product on customer-facing security features.
- Investigate suspected security issues and lead application-layer incident response alongside engineering.
- hunting bugs in our web app and APIs, reviewing security-sensitive code, running our pen test and responsible disclosure programs, threat modeling new features, and shaping how we build secure software at Ivo from the ground up.
Requirements
- 4+ years in application security, product security, or offensive security at a SaaS company, including time owning security for a production platform.
- You can find real bugs in real code, not just run scanners.
- Deep experience reviewing code in TypeScript / Node and Python.
- Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end.
- Track record of partnering with engineering rather than blocking them.
- You can write a Slack post that engineers actually want to read, a finding writeup that's genuinely actionable, and a security review that an enterprise prospect respects.
Nice to have
- Experience securing AI / LLM features in production: prompt injection defenses, agent guardrails, and AI-specific threat modeling.
- Series B or earlier experience where you built or scaled a security function from limited scaffolding.
- OSCP, OSWE, or comparable hands-on offensive security credentials.
- CVE credit, published research, or contributions to open-source security tooling.
- Experience designing security as customer-facing product (SSO domain verification, SCIM, IP allowlisting, audit logging, RBAC).
- As we move further upmarket and into more regulated industries, the strength of our application security program is becoming a direct driver of enterprise revenue and a key differentiator at the deal table.
- The person who fills it will shape what "secure by default" means at Ivo for years to come.
- Final offer details are determined based on experience, expertise, and overall fit.
Skills
- Mentor engineers on secure coding and be the go-to expert when teams have a security question.
Compensation
- The USD base range for this role is $220,000 - $300,000 (+equity would be on top of this).
- Final offer details are determined based on experience, expertise, and overall fit.
- Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.
Benefits
- We provide commuter benefits to help make getting to and from the office easier and more convenient.
- Enjoy a vibrant Downtown San Francisco office with catered lunch provided five days a week, premium snacks and coffee, a gym located in the building, and a dog-friendly environment!
- Comprehensive medical, dental and vision plans to suit the needs of you and your family.
- Unlimited PTO: So you can take the time you need to recharge, stay healthy, and bring your best self to work.
Company info
- Background supporting enterprise customers in regulated industries.
- Ivo's customers entrust us with their most sensitive contracts.
- This role owns the technical security of the product itself.
- Plan for your future with access to our company-sponsored 401(k) program.
- You'll partner directly with our Head of IT & Security and embed deeply with engineering to harden the product our customers trust with their most sensitive contracts.
Visa & Work Authorization
- Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.
Apply directly at Ivo Inc. →Create a free account for alerts like thisView Ivo Inc. immigration profile
This listing is sourced directly from Ivo Inc.'s careers page and normalized into a canonical job model.