SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Security Engineer

Nuvo - New York, NY, United States - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 200,000 - 300,000 / annual

Nuvo is redefining the $11T B2B commerce and payments market by bringing B2B commerce online. While consumer commerce has been transformed by technology, the B2B economy—three times larger—still relies on outdated methods like paper forms, PDFs, emails, faxes, and spreadsheets. Nuvo aims to do for B2B what Shopify, Stripe, and Square did for consumer commerce. As the first dedicated security hire, you will own and build the security function from the ground up at this early-stage startup. Your primary focus will be application and product security, with secondary responsibilities spanning cloud infrastructure, detection and response, and compliance. Key responsibilities include: - Own application and product security end-to-end: threat modeling, secure design, code review, and partnering with engineers to build security into products from the start rather than retrofitting it. - Build the security function from scratch: define the roadmap, establish best practices, select tooling, and set standards for the engineering team. - Identify, prioritize, and drive remediation of vulnerabilities across the product and infrastructure; build guardrails to prevent recurrence. - Operate across the full stack as needed: cloud and infrastructure hardening (IAM, secrets, network, Kubernetes), logging, detection, incident response, and compliance foundations like SOC 2. - Embed security into engineering culture, helping the team move fast securely. Write and review high-quality code, contribute to systems you protect, and mentor the team. - Leverage the best tools for the job, including technologies like Vue, GraphQL, and custom DSLs for roles and permissions. The company handles sensitive financial information for businesses across the economy, so trust is central to the product. You'll also work on security challenges related to safe AI agent deployment and multi-party workflow automation. Requirements: - 5+ years in security engineering with deep application and product security expertise, plus the range to operate across cloud, infrastructure, and detection. - Track record of building or substantially shaping a security program; comfort deciding priorities and rationale. - Strong engineering fundamentals: you read and write production code and can earn the trust of engineering partners. - Strong problem-solving skills and ability to communicate technical risk clearly to engineers, leadership, and customers. - Passion for internet technologies and sharp instinct for how modern systems are attacked and defended. - Experience in early-stage engineering teams or fast-growing companies, solving hard ambiguous problems with bias for action.

Similar roles