Lead Application Security Engineer: Build Secure SaaS
Ivo Inc.
San Francisco (CA)
On-site
USD 225,000 - 400,000
Full time
14 days+
Get more replies from employers
Send a job-specific resume in minutes.
Start fresh or import an existing resume
Benefits offered by this job
Comprehensive medical, dental and vision plans
401(k) Program
Unlimited PTO
Vibrant office with catered lunch
Commuter benefits
Job summary
Ivo Inc. in San Francisco is seeking a Lead Application Security Engineer to own the security of its platform, ensuring the protection of sensitive contracts for enterprise clients. This hands-on role involves vulnerability testing, threat modeling, and mentoring engineering teams on secure coding practices. The ideal candidate has 4+ years of experience in application security and skills in TypeScript/Node, Python, and Cloud Security. The position includes competitive compensation, medical benefits, unlimited PTO, and a vibrant office environment.
Qualifications
4+ years in application security, product security, or offensive security at a SaaS company.
Strong hands-on web application pen testing skills.
Deep experience reviewing code in TypeScript / Node and Python.
Strong background in web application security: OWASP Top 10, auth and authorization design.
Practical experience with cloud security in GCP and Azure.
Own application security across Ivo's web app, API surface, and systems.
Find and fix bugs. Hunt for vulnerabilities in our product through testing.
Lead manual code review for security-sensitive changes.
Run threat modeling with engineering for new features.
Manage our pen test program and ad-hoc engagements.
Run our responsible disclosure program for researcher communications.
Skills
Application security expertise
Web application pen testing
Deep experience in TypeScript/Node and Python
Web application security knowledge: OWASP Top 10
Cloud security in GCP and Azure
Managing pen tests and responsible disclosure programs
Strong internal sense of urgency
Excellent written communication
Job description
Ivo Inc. in San Francisco is seeking a Lead Application Security Engineer to own the security of its platform, ensuring the protection of sensitive contracts for enterprise clients. This hands-on role involves vulnerability testing, threat modeling, and mentoring engineering teams on secure coding practices. The ideal candidate has 4+ years of experience in application security and skills in TypeScript/Node, Python, and Cloud Security. The position includes competitive compensation, medical benefits, unlimited PTO, and a vibrant office environment.