Ivo Inc.

Ivo Inc.

Lead Application Security Engineer

San Francisco

Sponsorship not specified$220k-$300kDetected 48 days ago
TypeScriptNode.jsCode ReviewGCPAzureKubernetesOAuthLLMsA/B TestingCybersecurityPenetration TestingIncident ResponseComplianceCanvaResearchCommunication

About the role

  • The security stakes are real, and so is the impact.

Responsibilities

  • Own application security across Ivo's web app, API surface, and the systems behind them.
  • Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive-minded experimentation, and partner with engineers to ship the fix.
  • Lead manual code review for security-sensitive changes: authentication, authorization, multi-tenancy, integrations, and customer data handling.
  • Run threat modeling with engineering as new features and products are designed, across the full product surface including LLM and agent components.
  • Manage our pen test program and ad-hoc engagements end to end. Scope work, manage vendors, triage findings, and drive remediation to closure with engineering.
  • Build and maintain our application security tooling: SAST, DAST, SCA, secrets detection, and IaC scanning, with a strong bias toward signal over noise.
  • Embed security into the SDLC: PR-time checks, security champions, design review gates, and secure-by-default patterns engineers actually want to use.
  • Conduct deep reviews of identity and access surfaces (Firebase Auth, WorkOS, SSO, SAML, SCIM, RBAC) and partner with product on customer-facing security features.
  • Investigate suspected security issues and lead application-layer incident response alongside engineering.
  • hunting bugs in our web app and APIs, reviewing security-sensitive code, running our pen test and responsible disclosure programs, threat modeling new features, and shaping how we build secure software at Ivo from the ground up.

Requirements

  • 4+ years in application security, product security, or offensive security at a SaaS company, including time owning security for a production platform.
  • You can find real bugs in real code, not just run scanners.
  • Deep experience reviewing code in TypeScript / Node and Python.
  • Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end.
  • Track record of partnering with engineering rather than blocking them.
  • You can write a Slack post that engineers actually want to read, a finding writeup that's genuinely actionable, and a security review that an enterprise prospect respects.

Nice to have

  • Experience securing AI / LLM features in production: prompt injection defenses, agent guardrails, and AI-specific threat modeling.
  • Series B or earlier experience where you built or scaled a security function from limited scaffolding.
  • OSCP, OSWE, or comparable hands-on offensive security credentials.
  • CVE credit, published research, or contributions to open-source security tooling.
  • Experience designing security as customer-facing product (SSO domain verification, SCIM, IP allowlisting, audit logging, RBAC).
  • As we move further upmarket and into more regulated industries, the strength of our application security program is becoming a direct driver of enterprise revenue and a key differentiator at the deal table.
  • The person who fills it will shape what "secure by default" means at Ivo for years to come.
  • Final offer details are determined based on experience, expertise, and overall fit.

Skills

  • Mentor engineers on secure coding and be the go-to expert when teams have a security question.

Compensation

  • The USD base range for this role is $220,000 - $300,000 (+equity would be on top of this).
  • Final offer details are determined based on experience, expertise, and overall fit.
  • Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.

Benefits

  • We provide commuter benefits to help make getting to and from the office easier and more convenient.
  • Enjoy a vibrant Downtown San Francisco office with catered lunch provided five days a week, premium snacks and coffee, a gym located in the building, and a dog-friendly environment!
  • Comprehensive medical, dental and vision plans to suit the needs of you and your family.
  • Unlimited PTO: So you can take the time you need to recharge, stay healthy, and bring your best self to work.

Company info

  • Background supporting enterprise customers in regulated industries.
  • Ivo's customers entrust us with their most sensitive contracts.
  • This role owns the technical security of the product itself.
  • Plan for your future with access to our company-sponsored 401(k) program.
  • You'll partner directly with our Head of IT & Security and embed deeply with engineering to harden the product our customers trust with their most sensitive contracts.

Visa & Work Authorization

  • Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.

This listing is sourced directly from Ivo Inc.'s careers page and normalized into a canonical job model.