Ivo

SaaS

LeadApplicationSecurityEngineer

$225–400k San Francisco, California, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Lead candidates.

The Brief

“Lead Application Security Engineer at Ivo. Skills: Application security, Pen testing, Code review, Threat modeling. Own application security. Find and fix bugs”

Industry & Context.

SaaS
Problems you'll solve

Root cause analysis; Troubleshooting

What They're Looking For.

Must Have

4+ years application security, Production platform security ownership, Hands-on web application pen testing, Deep code review experience, Web application security background, Practical cloud security experience, Container and Kubernetes security experience, Manage pen tests end to end, Partner with engineering

Nice to Have

Securing AI/LLM features, Build/scale security function, OSCP or OSWE, CVE credit or research, Design security as product, Support enterprise customers

What You'll Do.

Own application security

Hunt for vulnerabilities

Partner with engineers

Lead manual code review

Manage pen test program

Manage pen test vendors

Triage pen test findings

Run responsible disclosure program

Build application security tooling

Embed security into SDLC

Conduct reviews of identity

Investigate security issues

Lead incident response

Contribute security input

How You'll Work.

Team & Collaboration

Embed with engineering; Partner with product; Cross-functional teams

Communication Scope

Written communication; Finding writeup; Security review

Process & Methodology

Pen test management, Responsible disclosure program

Full Job Description

WHY JOIN IVO? Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. Romans carved them into stone. We bury them in 80-page PDFs.   The way those agreements are reviewed hasn't changed in four thousand years - a human reads the whole thing and tries not to miss anything. We're building the AI that finally changes that. Ivo is the contract intelligence platform of choice for companies like Uber, Meta, Canva, IBM, and Shopify. We recently raised our Series B and have grown 800% over the last 12 months. THE ROLE We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed deeply with engineering to harden the product our customers trust with their most sensitive contracts. This is a hands-on senior IC role with broad scope: hunting bugs in our web app and APIs, reviewing security-sensitive code, running our pen test and responsible disclosure programs, threat modeling new features, and shaping how we build secure software at Ivo from the ground up. Our platform handles legally privileged documents for some of the largest companies in the world. The security stakes are real, and so is the impact. RESPONSIBILITIES - Own application security across Ivo's web app, API surface, and the systems behind them. - Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive-minded experimentation, and partner with engineers to ship the fix. - Lead manual code review for security-sensitive changes: authentication, authorization, multi-tenancy, integrations, and customer data handling. - Run threat modeling with engineering as new features and products are designed, across the full product surface including LLM and agent components. - Manage our pen test program and ad-hoc engagements end to end. Scope work, manage v

Free ATS check

Applying for this Lead Application Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Ivo?

Real rants from real employees. Read before you apply.

Read Company Rants →