Nuvo Logo

Nuvo

Lead Security Engineer

Posted One Month Ago
Be an Early Applicant
In-Office
New York, NY, USA
200K-300K Annually
Senior level
In-Office
New York, NY, USA
200K-300K Annually
Senior level
Lead the security function end-to-end at an early-stage B2B fintech: drive application and product security, threat modeling, secure design and code review, vulnerability remediation, cloud and Kubernetes hardening, logging and detection, incident response, and SOC 2 foundations. Define roadmap, embed security into engineering, and partner with teams to build secure-by-default products.
The summary above was generated by AI
About Nuvo

We’re Redefining the $11T B2B Commerce and Payments Market

Nuvo is bringing B2B commerce online.

While technology has reshaped consumer commerce, the business-to-business (B2B) economy — three times larger— has lagged behind.

From coffee to lumber, every product we use has been traded through a complex supply chain of suppliers, manufacturers, wholesalers, and retailers. Despite the massive scale of this market, most businesses manage their trading relationships and commerce activities using outdated methods like paper forms, PDFs, emails, faxes, phone calls, and spreadsheets, making processes slow and inefficient.

Much like how Shopify, Stripe and Square have transformed how consumer companies transact, we aim to do the same for B2B companies.


About the Role

We are looking for a lead security engineer to stand up and own security at a company building category-defining products. Our problems span safe deployment of AI agents, multi-party workflow automation, identity, risk, and large-scale data, and because we handle sensitive financial information for businesses across the economy, trust is the product. As our first dedicated security hire, you'll define what good looks like: shaping the roadmap, embedding security into how we build, and protecting our customers and their data from day one. Since we’re an early startup, you’ll have to be prepared to wear many hats; most of your time will be spent on application and product security, but you'll also reach into cloud infrastructure, detection and response, and compliance as the work demands. Your impact will be felt across team culture, our customers, and the economy.

What You’ll Do:

  • Own application and product security end to end — threat modeling, secure design and code review, and partnering with engineers to ship features that are secure by default rather than secured after the fact.
  • Build the security function from the ground up: set the roadmap, establish best practices, choose the tooling, and define the standards the rest of engineering will build on.
  • Find, prioritize, and drive remediation of vulnerabilities across the product and our infrastructure and build the guardrails that keep them from coming back.
  • Reach across the stack as needed — cloud and infrastructure hardening (IAM, secrets, network, Kubernetes), logging, detection and incident response, and the security foundations behind compliance efforts like SOC 2.
  • Make security a part of engineering culture, to help the whole team move fast but securely. Write and review high-quality code, contribute to the systems you protect, and level up the team around you.
  • Use the best tools for the job. We've used technologies like Vue, GraphQL, and even built our own DSL for defining roles and permissions. What matters most is the impact you create and the risk you reduce, not the specific tools you use.

What You Bring:

  • 5+ years in security engineering, with deep application/product security expertise and the range to operate across cloud, infrastructure, and detection when needed.
  • A track record of building or substantially shaping a security program. You should be comfortable being the one who decides what to do first and why.
  • Strong engineering fundamentals: you read and write production code, and you can earn the trust of the engineers you partner with.
  • Strong problem-solving skills and the ability to communicate technical risk clearly to engineers, to leadership, and to customers.
  • A passion for internet technologies and a sharp instinct for how modern systems get attacked and defended.
  • Experience working in an early-stage engineering team or a fast-growing company, solving hard, ambiguous problems with a strong bias for action.

Expected Compensation Range $200,000-$300,000

Nuvo New York, New York, USA Office

45 Main St, New York, New York, United States, 11201 1000

Nuvo New York, New York, USA Office

New York, United States

Similar Jobs

5 Days Ago
Hybrid
2 Locations
Senior level
Senior level
Financial Services
Leads software engineering for secure, stable, and scalable technology platforms. Designs, develops, tests, debugs, and reviews production code; improves application resiliency and operational stability; automates recurring remediation; and promotes secure AI-assisted development practices. Evaluates vendor and internal technical solutions, coaches engineers on responsible AI use, and applies cloud-native technologies, agile methodologies, and CI/CD across the software development lifecycle.
Top Skills: Ai-Assisted Software DevelopmentAutomated TestingCi/CdCloud NativeSoftware Development Life Cycle (Sdlc)
6 Days Ago
Hybrid
2 Locations
Senior level
Senior level
Financial Services
Leads enterprise cybersecurity engineering and secure-design reviews across applications, cloud platforms, APIs, integrations, and third-party solutions. Conducts threat modeling, risk assessments, vulnerability remediation, and architecture evaluations; advises senior stakeholders on mitigations, compensating controls, and secure implementation. Promotes automation and AI-assisted security validation throughout the software development lifecycle, while ensuring data sensitivity, auditability, and resiliency. Partners with product, engineering, business, vendor, and technology teams and leads cybersecurity communities of practice.
Top Skills: Api GatewaysApplication Programming Interfaces (Apis)Application SecurityArtificial Intelligence And Machine Learning (Ai/Ml)Cloud Access Security Broker (Casb)Identity And Access Management (Iam)Infrastructure SecurityMobile TechnologiesOauthProxy TechnologiesPublic CloudSAMLSecrets ManagementSecurity Information And Event Management (Siem)Security Monitoring PlatformsSecurity Service Edge (Sse)Service-To-Service AuthenticationTraffic InspectionZero Trust
One Month Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-180K Annually
Senior level
140K-180K Annually
Senior level
AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Lead application security engineering across the SDLC using AI-assisted threat modeling, automated security testing, vulnerability prioritization, and secure-by-default controls. Partner with Engineering, Product, QA, DevOps, and AI platform teams to secure applications, APIs, cloud infrastructure, data, and AI/ML systems. Build security automation, CI/CD controls, policy-as-code guardrails, developer enablement, and proactive defenses against emerging threats such as prompt injection and data poisoning.
Top Skills: AIAi/MlAWSAzureBurp SuiteCi/CdContainer ScanningDastDjangoDockerFastapiGCPGithub Advanced SecurityIac ScanningInfrastructure-As-CodeJwtKubernetesNode.jsOauth2OidcOwasp ZapPolicy-As-CodeReactSastScaSemgrepSnykSonarqubeTrivy

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account