About the Role
As Lead Security Engineer at IQWorks, you will own security for a platform whose entire promise is protecting sensitive data. Security is not a feature bolted on at the end here — it is the product, and you will be the person who holds the bar. You will own our zero-trust architecture and the strict data-isolation guarantees that keep every customer's data separate, and you will make sure those guarantees hold as the platform grows. You will threat-model new features, run security reviews on the code we ship, harden our cloud and on-premise deployments, and lead our response when something needs attention. You will stay hands-on — reading code, writing tooling, and fixing issues at the root — while setting the standards and secure-by-default patterns the whole engineering team builds around. This is a high-ownership role for someone who thinks like an attacker, builds like an engineer, and treats customer trust as the thing worth protecting.
What You Will Do
- Own the security posture of the IQWorks platform, from application code to infrastructure to on-premise deployments
- Guard the zero-trust data-isolation model — keep multi-tenant separation airtight and enforce least-privilege access end to end
- Threat-model new features and lead security reviews before they ship, working alongside the engineering team
- Build and automate security tooling — static and dynamic analysis, dependency and secret scanning, and CI security gates
- Run vulnerability management end to end: triage, prioritize, and drive fixes at the root cause
- Lead incident response — detection, containment, remediation, and blameless post-mortems
- Harden cloud and on-premise/edge environments so enterprises can process sensitive data without it leaving their infrastructure
- Support enterprise security reviews and our compliance and certification program (SOC 2, ISO 27001, and similar)
- Set secure-by-default patterns and raise the security bar across the team as the company scales
What We Are Looking For
- 5+ years in security engineering, application security, or software engineering with a heavy security focus
- Strong grasp of web application security — the OWASP Top 10, authentication, authorization, and secure application design
- Hands-on experience securing multi-tenant SaaS, including database-level access controls and data isolation
- Ability to read and write production code (TypeScript, and a backend language such as Go or Python) and fix issues yourself, not just file them
- Experience with threat modeling, security reviews, and vulnerability management in a shipping product
- Working knowledge of cloud security and hardening, and comfort reasoning about on-premise and edge deployments
- Effective use of AI as a force multiplier across the security workflow — reviewing code, triaging findings, and building tooling — with sharp judgment about where human oversight is essential so security is never compromised
- Clear communication and the ability to work directly with engineering, product, and founders in a fast-moving startup
Nice to Have
- Experience with database-enforced authorization and fine-grained access-control models
- Background in data privacy, compliance, or governance, and familiarity with regulations such as DPDPA, GDPR, or HIPAA
- Experience driving SOC 2, ISO 27001, or similar certifications
- Security certifications such as OSCP, CISSP, or GIAC
- Experience securing AI/ML systems or LLM-based features against prompt injection and data-leakage risks
- Prior experience as an early security hire at a high-growth startup