> Markdown version of [/jobs/ext/2706273-lead-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2706273-lead-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer - **Company:** IVS Customz LLC - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Audit Trail, Microsoft Azure, Software as a Service, Cloud Computing Security, Code Review, Customer Data Management, Python (Programming Language), Node.Js, OAuth, Open Source Technology, OpenID, Open Web Application Security, Systems Development Life Cycle, Role-Based Access Control, Security Assertion Markup Language (SAML), Secure Coding, Web Application Security, Single Sign-On, Systems Integration, TypeScript, Web Applications, Large Language Models, Software Security, Firebase, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/lead-application-security-engineer-ivo-inc-8342763 ## About the Role * 4+ years in application security, product security, or offensive security at a SaaS company, including time owning security for a production platform. * Strong hands-on web application pen testing skills. You can find real bugs in real code, not just run scanners. * Deep experience reviewing code in TypeScript / Node and Python. You're comfortable reading and writing code, not just reviewing it. * Strong background in web application security: OWASP Top 10, auth and authorization design (OAuth, OIDC, SAML, SSO), multi-tenant isolation, and modern API security. * Practical experience with cloud security in GCP and Azure, plus container and Kubernetes security (AKS or similar). * Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end. * Track record of partnering with engineering rather than blocking them. You ship paved roads, not tickets. * Excellent written communication. You can write a Slack post that engineers actually want to read, a finding writeup that's genuinely actionable, and a security review that an enterprise prospect respects. * A strong internal sense of urgency and a bias toward shipping today rather than tomorrow., * Experience securing AI / LLM features in production: prompt injection defenses, agent guardrails, and AI-specific threat modeling. * Series B or earlier experience where you built or scaled a security function from limited scaffolding. * OSCP, OSWE, or comparable hands-on offensive security credentials. * CVE credit, published research, or contributions to open-source security tooling. * Experience designing security as customer-facing product (SSO domain verification, SCIM, IP allowlisting, audit logging, RBAC). * Background supporting enterprise customers in regulated industries., * Would describe yourself as being relentlessly resourceful. * You have a strong internal sense of urgency. You have a bias towards doing things today, rather than tomorrow. * Experience working in a startup environment is preferred but not required. * Are excited about the adventure of building a company! ## Description We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed deeply with engineering to harden the product our customers trust with their most sensitive contracts. This is a hands-on senior IC role with broad scope: hunting bugs in our web app and APIs, reviewing security-sensitive code, running our pen test and responsible disclosure programs, threat modeling new features, and shaping how we build secure software at Ivo from the ground up. Our platform handles legally privileged documents for some of the largest companies in the world. The security stakes are real, and so is the impact., * Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive-minded experimentation, and partner with engineers to ship the fix. * Lead manual code review for security-sensitive changes: authentication, authorization, multi-tenancy, integrations, and customer data handling. * Run threat modeling with engineering as new features and products are designed, across the full product surface including LLM and agent components. * Manage our pen test program and ad-hoc engagements end to end. Scope work, manage vendors, triage findings, and drive remediation to closure with engineering. * Run our responsible disclosure program, including researcher communications, validation, payments, and ongoing relationships with trusted external researchers. * Build and maintain our application security tooling: SAST, DAST, SCA, secrets detection, and IaC scanning, with a strong bias toward signal over noise. * Embed security into the SDLC: PR-time checks, security champions, design review gates, and secure-by-default patterns engineers actually want to use. * Conduct deep reviews of identity and access surfaces (Firebase Auth, WorkOS, SSO, SAML, SCIM, RBAC) and partner with product on customer-facing security features. * Investigate suspected security issues and lead application-layer incident response alongside engineering. * Contribute application security input to enterprise security reviews, SOC 2 Type II, ISO 27001, ISO 42001, and customer-facing trust documentation. * Mentor engineers on secure coding and be the go-to expert when teams have a security question. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)