nuvo3mo ago
New
New
Lead Security Engineer
San Francisco / New Yorkfull-timelead
EngineeringSecurity Engineer
0 views0 saves0 applied
Quick Summary
Key Responsibilities
Own application and product security end to end — threat modeling, secure design and code review,
Technical Tools
EngineeringSecurity Engineer
We’re Redefining the $11T B2B Commerce and Payments Market
Nuvo is bringing B2B commerce online.
While technology has reshaped consumer commerce, the business-to-business (B2B) economy — three times larger— has lagged behind.
From coffee to lumber, every product we use has been traded through a complex supply chain of suppliers, manufacturers, wholesalers, and retailers. Despite the massive scale of this market, most businesses manage their trading relationships and commerce activities using outdated methods like paper forms, PDFs, emails, faxes, phone calls, and spreadsheets, making processes slow and inefficient.
Much like how Shopify, Stripe and Square have transformed how consumer companies transact, we aim to do the same for B2B companies.
About the Role
~1 min readWe are looking for a lead security engineer to stand up and own security at a company building category-defining products. Our problems span safe deployment of AI agents, multi-party workflow automation, identity, risk, and large-scale data, and because we handle sensitive financial information for businesses across the economy, trust is the product. As our first dedicated security hire, you'll define what good looks like: shaping the roadmap, embedding security into how we build, and protecting our customers and their data from day one. Since we’re an early startup, you’ll have to be prepared to wear many hats; most of your time will be spent on application and product security, but you'll also reach into cloud infrastructure, detection and response, and compliance as the work demands. Your impact will be felt across team culture, our customers, and the economy.
Responsibilities
~1 min read- →Own application and product security end to end — threat modeling, secure design and code review, and partnering with engineers to ship features that are secure by default rather than secured after the fact.
- →Build the security function from the ground up: set the roadmap, establish best practices, choose the tooling, and define the standards the rest of engineering will build on.
- →Find, prioritize, and drive remediation of vulnerabilities across the product and our infrastructure and build the guardrails that keep them from coming back.
- →Reach across the stack as needed — cloud and infrastructure hardening (IAM, secrets, network, Kubernetes), logging, detection and incident response, and the security foundations behind compliance efforts like SOC 2.
- →Make security a part of engineering culture, to help the whole team move fast but securely. Write and review high-quality code, contribute to the systems you protect, and level up the team around you.
- →Use the best tools for the job. We've used technologies like Vue, GraphQL, and even built our own DSL for defining roles and permissions. What matters most is the impact you create and the risk you reduce, not the specific tools you use.
- 5+ years in security engineering, with deep application/product security expertise and the range to operate across cloud, infrastructure, and detection when needed.
- A track record of building or substantially shaping a security program. You should be comfortable being the one who decides what to do first and why.
- Strong engineering fundamentals: you read and write production code, and you can earn the trust of the engineers you partner with.
- Strong problem-solving skills and the ability to communicate technical risk clearly to engineers, to leadership, and to customers.
- A passion for internet technologies and a sharp instinct for how modern systems get attacked and defended.
- Experience working in an early-stage engineering team or a fast-growing company, solving hard, ambiguous problems with a strong bias for action.
Expected Compensation Range $200,000-$300,000
Location & Eligibility
Where is the job
San Francisco / New York
On-site at the office
Who can apply
Same as job location
Listing Details
- Posted
- June 24, 2026
- First seen
- September 26, 2026
- Last seen
- September 27, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 19%
- Scored at
- September 27, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application
Similar Security Engineer jobs
View all →Cybersecurity Engineer Sr
Security Engineer – Produktsicherheit (m/w/d)
Cloud Security Engineer - OCI (Oracle Cloud Infrastructure)
Remote
Cloud Security Engineer (Oracle Cloud Infrastructure - OCI)
Remote
Cloud Security Engineer (Oracle Cloud Infrastructure - OCI)
Remote
Staff Infrastructure & Security Engineer
Browse Similar Jobs
Devops Engineer3.2kFullstack Developer1.9kEngineering Manager1.9kSecurity1.7kSoftware Architect1.6kQa Engineer1.6kMechanical Engineer1.5kElectrical Engineer1.4kBackend Developer1.3kProject Engineer1.3kDevOps & Infrastructure1.2kFrontend Developer989Design Engineer955Process Engineer683Quality Engineer668Mobile Developer661Product Engineer652Backend Engineering599Data Engineering544Embedded Engineer503
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.