Demo

Lead Application Security Engineer

Ivo
San Francisco, CA Contractor
POSTED ON 7/12/2026
AVAILABLE BEFORE 12/10/2026
Why join Ivo?

Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. Romans carved them into stone. We bury them in 80-page PDFs.

The way those agreements are reviewed hasn't changed in four thousand years - a human reads the whole thing and tries not to miss anything. We're building the AI that finally changes that. Ivo is the contract intelligence platform of choice for companies like Uber, Meta, Canva, IBM, and Shopify. We recently raised our Series B and have grown 800% over the last 12 months.

The Role

We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed deeply with engineering to harden the product our customers trust with their most sensitive contracts. This is a hands-on senior IC role with broad scope: hunting bugs in our web app and APIs, reviewing security-sensitive code, running our pen test and responsible disclosure programs, threat modeling new features, and shaping how we build secure software at Ivo from the ground up.

Our platform handles legally privileged documents for some of the largest companies in the world. The security stakes are real, and so is the impact.

Responsibilities

  • Own application security across Ivo's web app, API surface, and the systems behind them.
  • Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive-minded experimentation, and partner with engineers to ship the fix.
  • Lead manual code review for security-sensitive changes: authentication, authorization, multi-tenancy, integrations, and customer data handling.
  • Run threat modeling with engineering as new features and products are designed, across the full product surface including LLM and agent components.
  • Manage our pen test program and ad-hoc engagements end to end. Scope work, manage vendors, triage findings, and drive remediation to closure with engineering.
  • Run our responsible disclosure program, including researcher communications, validation, payments, and ongoing relationships with trusted external researchers.
  • Build and maintain our application security tooling: SAST, DAST, SCA, secrets detection, and IaC scanning, with a strong bias toward signal over noise.
  • Embed security into the SDLC: PR-time checks, security champions, design review gates, and secure-by-default patterns engineers actually want to use.
  • Conduct deep reviews of identity and access surfaces (Firebase Auth, WorkOS, SSO, SAML, SCIM, RBAC) and partner with product on customer-facing security features.
  • Investigate suspected security issues and lead application-layer incident response alongside engineering.
  • Contribute application security input to enterprise security reviews, SOC 2 Type II, ISO 27001, ISO 42001, and customer-facing trust documentation.
  • Mentor engineers on secure coding and be the go-to expert when teams have a security question.

Who You Are

  • 4 years in application security, product security, or offensive security at a SaaS company, including time owning security for a production platform.
  • Strong hands-on web application pen testing skills. You can find real bugs in real code, not just run scanners.
  • Deep experience reviewing code in TypeScript / Node and Python. You're comfortable reading and writing code, not just reviewing it.
  • Strong background in web application security: OWASP Top 10, auth and authorization design (OAuth, OIDC, SAML, SSO), multi-tenant isolation, and modern API security.
  • Practical experience with cloud security in GCP and Azure, plus container and Kubernetes security (AKS or similar).
  • Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end.
  • Track record of partnering with engineering rather than blocking them. You ship paved roads, not tickets.
  • Excellent written communication. You can write a Slack post that engineers actually want to read, a finding writeup that's genuinely actionable, and a security review that an enterprise prospect respects.
  • A strong internal sense of urgency and a bias toward shipping today rather than tomorrow.

Nice to Have

  • Experience securing AI / LLM features in production: prompt injection defenses, agent guardrails, and AI-specific threat modeling.
  • Series B or earlier experience where you built or scaled a security function from limited scaffolding.
  • OSCP, OSWE, or comparable hands-on offensive security credentials.
  • CVE credit, published research, or contributions to open-source security tooling.
  • Experience designing security as customer-facing product (SSO domain verification, SCIM, IP allowlisting, audit logging, RBAC).
  • Background supporting enterprise customers in regulated industries.

Why This Role Matters

Ivo's customers entrust us with their most sensitive contracts. As we move further upmarket and into more regulated industries, the strength of our application security program is becoming a direct driver of enterprise revenue and a key differentiator at the deal table. This role owns the technical security of the product itself. The person who fills it will shape what "secure by default" means at Ivo for years to come.

Compensation And Benefits

  • Competitive Compensation: The USD base range for this role is $220,000 - $300,000 ( equity would be on top of this). Final offer details are determined based on experience, expertise, and overall fit.
  • Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.
  • Medical benefits: Comprehensive medical, dental and vision plans to suit the needs of you and your family.
  • 401(k) Program: Plan for your future with access to our company-sponsored 401(k) program.
  • Commuter Benefits: We provide commuter benefits to help make getting to and from the office easier and more convenient.
  • Unlimited PTO: So you can take the time you need to recharge, stay healthy, and bring your best self to work.
  • Office Perks: Enjoy a vibrant Downtown San Francisco office with catered lunch provided five days a week, premium snacks and coffee, a gym located in the building, and a dog-friendly environment!

Salary : $220,000 - $300,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Lead Application Security Engineer?

Sign up to receive alerts about other jobs on the Lead Application Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$131,745 - $167,716
Income Estimation: 
$150,756 - $194,140
Income Estimation: 
$172,191 - $221,861
Income Estimation: 
$114,549 - $164,025
Income Estimation: 
$153,752 - $200,235
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Ivo

  • Ivo San Francisco, CA
  • Why Ivo? Contract negotiation is the most time-consuming, costly, and difficult component of the contract lifecycle—and it hasn’t gotten much easier since ... more
  • 13 Days Ago

  • Ivo San Francisco, CA
  • Why Ivo? Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. ... more
  • 15 Days Ago

  • Ivo San Francisco, CA
  • Why Ivo? Contract negotiation is the most time-consuming, costly, and difficult component of the contract lifecycle—and it hasn’t gotten much easier since ... more
  • 1 Day Ago

  • Ivo San Francisco, CA
  • About Ivo? Ivo is an AI-powered contract review and legal technology company transforming how organizations review, negotiate, and manage contracts. Securi... more
  • 2 Days Ago


Not the job you're looking for? Here are some other Lead Application Security Engineer jobs in the San Francisco, CA area that may be a better fit.

  • Eve San Mateo, CA
  • About Eve Eve is redefining legal technology for plaintiff law firms, and we're building the team that will take us there. We help firms handle more cases,... more
  • 14 Days Ago

  • Opal Security San Francisco, CA
  • About Opal Security At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast ... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!