368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$220k – $300k per year
Location
In office (San Francisco)
Seniority
Staff · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
IVO Inc. is an Illinois-based digital services and software development agency specializing in custom website design, content management solutions, and internet marketing for small-to-medium businesses. Founded in 2005, the company provides bespoke web development, e-commerce solutions, domain management, and search engine optimization (SEO).

Why Join Ivo?

Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. Romans carved them into stone. We bury them in 80-page PDFs.

The way those agreements are reviewed hasn't changed in four thousand years - a human reads the whole thing and tries not to miss anything. We're building the AI that finally changes that. Ivo is the contract intelligence platform of choice for companies like Uber, Meta, Canva, IBM, and Shopify. We recently raised our Series B and have grown 800% over the last 12 months.

The Opportunity

We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed deeply with engineering to harden the product our customers trust with their most sensitive contracts. This is a hands-on senior IC role with broad scope: hunting bugs in our web app and APIs, reviewing security-sensitive code, running our pen test and responsible disclosure programs, threat modeling new features, and shaping how we build secure software at Ivo from the ground up.

Our platform handles legally privileged documents for some of the largest companies in the world. The security stakes are real, and so is the impact.

What You'll Do

  • Own application security across Ivo's web app, API surface, and the systems behind them.

  • Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive-minded experimentation, and partner with engineers to ship the fix.

  • Lead manual code review for security-sensitive changes: authentication, authorization, multi-tenancy, integrations, and customer data handling.

  • Run threat modeling with engineering as new features and products are designed, across the full product surface including LLM and agent components.

  • Manage our pen test program and ad-hoc engagements end to end. Scope work, manage vendors, triage findings, and drive remediation to closure with engineering.

  • Run our responsible disclosure program, including researcher communications, validation, payments, and ongoing relationships with trusted external researchers.

  • Build and maintain our application security tooling: SAST, DAST, SCA, secrets detection, and IaC scanning, with a strong bias toward signal over noise.

  • Embed security into the SDLC: PR-time checks, security champions, design review gates, and secure-by-default patterns engineers actually want to use.

  • Conduct deep reviews of identity and access surfaces (Firebase Auth, WorkOS, SSO, SAML, SCIM, RBAC) and partner with product on customer-facing security features.

  • Investigate suspected security issues and lead application-layer incident response alongside engineering.

  • Contribute application security input to enterprise security reviews, SOC 2 Type II, ISO 27001, ISO 42001, and customer-facing trust documentation.

  • Mentor engineers on secure coding and be the go-to expert when teams have a security question.

What We're Looking For

  • 4+ years in application security, product security, or offensive security at a SaaS company, including time owning security for a production platform.

  • Strong hands-on web application pen testing skills. You can find real bugs in real code, not just run scanners.

  • Deep experience reviewing code in TypeScript / Node and Python. You're comfortable reading and writing code, not just reviewing it.

  • Strong background in web application security: OWASP Top 10, auth and authorization design (OAuth, OIDC, SAML, SSO), multi-tenant isolation, and modern API security.

  • Practical experience with cloud security in GCP and Azure, plus container and Kubernetes security (AKS or similar).

  • Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end.

  • Track record of partnering with engineering rather than blocking them. You ship paved roads, not tickets.

  • Excellent written communication. You can write a Slack post that engineers actually want to read, a finding writeup that's genuinely actionable, and a security review that an enterprise prospect respects.

  • A strong internal sense of urgency and a bias toward shipping today rather than tomorrow.

Nice to Have

  • Experience securing AI / LLM features in production: prompt injection defenses, agent guardrails, and AI-specific threat modeling.

  • Series B or earlier experience where you built or scaled a security function from limited scaffolding.

  • OSCP, OSWE, or comparable hands-on offensive security credentials.

  • CVE credit, published research, or contributions to open-source security tooling.

  • Experience designing security as customer-facing product (SSO domain verification, SCIM, IP allowlisting, audit logging, RBAC).

  • Background supporting enterprise customers in regulated industries.

Why This Role Matters

Ivo's customers entrust us with their most sensitive contracts. As we move further upmarket and into more regulated industries, the strength of our application security program is becoming a direct driver of enterprise revenue and a key differentiator at the deal table. This role owns the technical security of the product itself. The person who fills it will shape what "secure by default" means at Ivo for years to come.

Ivo might be a good fit for you if you:

  • Would describe yourself as being relentlessly resourceful.

  • You have a strong internal sense of urgency. You have a bias towards doing things today, rather than tomorrow.

  • Experience working in a startup environment is preferred but not required.

  • Are excited about the adventure of building a company!

What We Offer

  • Competitive Compensation: Final offer details are determined based on experience, expertise, and overall fit.

  • Equity: Meaningful ownership in a company that's scaling fast

  • Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.

  • Health & Wellness: Comprehensive medical, dental, and vision plans to suit the needs of you and your family.

  • Flexible Spending & Insurance: Access to HSA and FSA accounts, plus life insurance coverage.

  • 401(k) Program: Save for the future with our 401(k) program.

  • Commuter Benefits: We help make getting to and from the office easier and more convenient.

  • Unlimited PTO: So you can take the time you need to recharge, stay healthy, and bring your best self to work.

  • Office Perks: Enjoy a vibrant Downtown San Francisco office with catered lunch five days a week, premium snacks and coffee, an in-building gym, and a dog-friendly environment.

FAQ

  • What stage of growth is Ivo at?: We launched in early access in 2023. Since then, we’ve had an incredible response from the market and are growing rapidly. We 6x'd in ARR in the last 12 months. Our clients include companies like Uber, Reddit, IBM, Canva, Pinterest, DoorDash, and more. We're happy to share more details with candidates who go through our interview process.

  • Is this a chill gig?: Startups are very hard, especially if they’re growing fast. You’ll have a ton of responsibility, and there’s always an enormous amount of stuff to do. It’s hard work but the payoff is uncapped.

Ivo is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
SOC Senior Analyst 2 days ago
In office • Full-Time • Bachelor's Degree • Riyadh
DevOps
AWS
Azure
GCP
Cybersecurity
MITRE ATT&CK
Apply
SOC Analyst L1 1 day ago
In office • Full-Time • Bachelor's Degree • Riyadh
DevOps
AWS
Azure
GCP
SLI/SLO/SLA
Cybersecurity
MITRE ATT&CK
Apply
$20k – $49k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
Python
Ruby
SQL
Databases
Amazon Neptune
Neo4j
AI/ML
Hallucination
LangChain
LangGraph
LLM
Model Context Protocol
Spark
AI Agents
LLM Guardrails
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
GitHub Actions
GitLab CI
Jenkins
Kubernetes
Rest API
Terraform
GitHub
GitLab
QA
Playwright
Postman
Selenium
Swagger
Apply
$20k – $51k per year (Estimated) • Remote • Full-Time • 3+ years exp
DevOps
AWS
Azure
GCP
IAM
Apply
Remote • Full-Time • 3+ years exp • Cairo
C#
JavaScript
TypeScript
C#
.NET
AI/ML
Copilot
DevOps
Azure
Azure DevOps
CI/CD
Rest API
Analytics
ETL/ELT
Management
Power Apps
Power Automate
Apply
$158k – $235k per year • In office • Full-Time • San Francisco
Go
PHP
PHP
WordPress
AI/ML
AI Agents
Embeddings
LLM
RAG
Time Series Forecasting
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub Actions
Kubernetes
Pulumi
Terraform
GitHub
Apply
$249k – $405k per year • In office • Full-Time • San Francisco
Go
PHP
PHP
WordPress
AI/ML
AI Agents
Embeddings
LLM
RAG
Time Series Forecasting
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub Actions
Kubernetes
Pulumi
Terraform
GitHub
Apply
$287k – $485k per year • In office • Full-Time • San Francisco
Go
PHP
PHP
WordPress
AI/ML
AI Agents
Embeddings
LLM
RAG
Time Series Forecasting
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub Actions
Kubernetes
Pulumi
Terraform
GitHub
Apply
Sr. Product Manager 28 days ago
$180k – $245k per year • In office • Full-Time • 5+ years exp • San Francisco
AI/ML
LLM
Apply
Senior AI Researcher 1 month ago
$200k – $325k per year • In office • Full-Time • PhD • San Francisco
PHP
PHP
WordPress
AI/ML
AI Agents
Embeddings
Fine-tuning
Hallucination
JAX
Knowledge Distillation
LLM
PEFT
PyTorch
Quantization
RAG
TensorFlow
Time Series Forecasting
Transformers
Apply
$223k – $424k per year (Estimated) • In office • Bachelor's Degree • San Francisco
AI/ML
AI Agents
LLM
Recommender Systems
Apply
$83k – $188k per year (Estimated) • In office • 2+ years exp • San Francisco
Python
AI/ML
AI Agents
LLM Guardrails
Model Context Protocol
DevOps
Terraform
Cybersecurity
Crowdstrike
GDPR
Least Privilege
Okta
SentinelOne
Management
Google Workspace
Slack
Apply
$171k – $273k per year • In office • Full-Time • 8+ years exp • PhD • San Francisco • Washington
AI/ML
A2A
Agentforce
AI Agents
Model Context Protocol
DevOps
AWS
GCP
Marketing
Salesforce
Apply
Security GRC Analyst 2 hours ago
$119k – $268k per year (Estimated) • Remote/Hybrid • 4+ years exp • Bachelor's Degree • San Francisco
AI/ML
Ignite
PyTorch
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Apply
$173k – $260k per year • In office • Full-Time • PhD • San Francisco
JavaScript
Node JS
Python
Python
Celery
Django
Flask
Databases
RabbitMQ
Redis
AI/ML
Agentforce
AI Agents
DevOps
Akamai
AWS
CI/CD
Cloudflare
CloudFormation
Helm
Jenkins
Kubernetes
Spinnaker
Terraform
Marketing
Salesforce
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.