Ivo
SaaS
LeadApplicationSecurityEngineer
Neural analysis suggests this role is
optimal for Lead candidates.
“Lead Application Security Engineer at Ivo. Skills: Application security, Pen testing, Code review, Threat modeling. Own application security. Find and fix bugs”
Industry & Context.
Root cause analysis; Troubleshooting
What They're Looking For.
Must Have
4+ years application security, Production platform security ownership, Hands-on web application pen testing, Deep code review experience, Web application security background, Practical cloud security experience, Container and Kubernetes security experience, Manage pen tests end to end, Partner with engineering
Nice to Have
Securing AI/LLM features, Build/scale security function, OSCP or OSWE, CVE credit or research, Design security as product, Support enterprise customers
What You'll Do.
Own application security
Hunt for vulnerabilities
Partner with engineers
Lead manual code review
Manage pen test program
Manage pen test vendors
Triage pen test findings
Run responsible disclosure program
Build application security tooling
Embed security into SDLC
Conduct reviews of identity
Investigate security issues
Lead incident response
Contribute security input
How You'll Work.
Team & Collaboration
Embed with engineering; Partner with product; Cross-functional teams
Communication Scope
Written communication; Finding writeup; Security review
Process & Methodology
Pen test management, Responsible disclosure program
Full Job Description
WHY JOIN IVO? Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. Romans carved them into stone. We bury them in 80-page PDFs. The way those agreements are reviewed hasn't changed in four thousand years - a human reads the whole thing and tries not to miss anything. We're building the AI that finally changes that. Ivo is the contract intelligence platform of choice for companies like Uber, Meta, Canva, IBM, and Shopify. We recently raised our Series B and have grown 800% over the last 12 months. THE ROLE We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed deeply with engineering to harden the product our customers trust with their most sensitive contracts. This is a hands-on senior IC role with broad scope: hunting bugs in our web app and APIs, reviewing security-sensitive code, running our pen test and responsible disclosure programs, threat modeling new features, and shaping how we build secure software at Ivo from the ground up. Our platform handles legally privileged documents for some of the largest companies in the world. The security stakes are real, and so is the impact. RESPONSIBILITIES - Own application security across Ivo's web app, API surface, and the systems behind them. - Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive-minded experimentation, and partner with engineers to ship the fix. - Lead manual code review for security-sensitive changes: authentication, authorization, multi-tenancy, integrations, and customer data handling. - Run threat modeling with engineering as new features and products are designed, across the full product surface including LLM and agent components. - Manage our pen test program and ad-hoc engagements end to end. Scope work, manage v
Applying for this Lead Application Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Ivo?
Real rants from real employees. Read before you apply.