Lead Security Engineer
Indexed description
What You Will Do
- Own the security posture of the IQWorks platform, from application code to infrastructure to on-premise deployments
- Guard the zero-trust data-isolation model — keep multi-tenant separation airtight and enforce least-privilege access end to end
- Threat-model new features and lead security reviews before they ship, working alongside the engineering team
- Build and automate security tooling — static and dynamic analysis, dependency and secret scanning, and CI security gates
- Run vulnerability management end to end: triage, prioritize, and drive fixes at the root cause
- Lead incident response — detection, containment, remediation, and blameless post-mortems
- Harden cloud and on-premise/edge environments so enterprises can process sensitive data without it leaving their infrastructure
- Support enterprise security reviews and our compliance and certification program (SOC 2, ISO 27001, and similar)
- Set secure-by-default patterns and raise the security bar across the team as the company scales
- 5+ years in security engineering, application security, or software engineering with a heavy security focus
- Strong grasp of web application security — the OWASP Top 10, authentication, authorization, and secure application design
- Hands-on experience securing multi-tenant SaaS, including database-level access controls and data isolation
- Ability to read and write production code (TypeScript, and a backend language such as Go or Python) and fix issues yourself, not just file them
- Experience with threat modeling, security reviews, and vulnerability management in a shipping product
- Working knowledge of cloud security and hardening, and comfort reasoning about on-premise and edge deployments
- Effective use of AI as a force multiplier across the security workflow — reviewing code, triaging findings, and building tooling — with sharp judgment about where human oversight is essential so security is never compromised
- Clear communication and the ability to work directly with engineering, product, and founders in a fast-moving startup
- Experience with database-enforced authorization and fine-grained access-control models
- Background in data privacy, compliance, or governance, and familiarity with regulations such as DPDPA, GDPR, or HIPAA
- Experience driving SOC 2, ISO 27001, or similar certifications
- Security certifications such as OSCP, CISSP, or GIAC
- Experience securing AI/ML systems or LLM-based features against prompt injection and data-leakage risks
- Prior experience as an early security hire at a high-growth startup
Full Name *
Email *
Phone *
LinkedIn *
Experience *Select0-1 years1-3 years3-5 years5-8 years8-12 years12+ years
Notice Period *SelectImmediate15 days30 days60 days90 days
Expected Compensation *
Resume *
Message
I consent to IQWorks collecting and processing my personal data, including my CV, for recruitment purposes, in accordance with the Privacy Policy.
Prefer email? Reach us at [email protected]
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search