About Iru Iru is the AI-powered security & IT platform used by the world’s fastest-growing companies to secure their users, apps, and devices. Built for the AI era, Iru unifies identity & access, endpoint security & management, and compliance automation—collapsing the stack and giving IT & security time and control back. Iru is backed by some of the smartest investors in tech—General Catalyst, Tiger Global, Felicis, Greycroft, and First Round Capital. In July 2024, Iru raised $100 million from General Catalyst, valuing the company at $850 million. Customers include Notion, Cursor, Lovable, Replit, and Mercor, and Iru partners with industry leaders such as ServiceNow and AWS. Iru was named to Forbes’ America’s Best Startup Employers 2025 list for employee engagement and satisfaction.
The Opportunity
Iru is seeking an experienced and hands-on Application Security Lead / Manager to own and mature our Application Security program. This role will serve as the operational leader for AppSec, partnering closely with Engineering, Product, and Security leadership to ensure security is embedded throughout the software development lifecycle.
The ideal candidate combines strong technical application security expertise with the ability to influence engineering teams, drive remediation accountability, and scale security processes in a fast-moving environment.
This position is critical to strengthening our security posture, reducing risk, and enabling engineering teams to deliver secure products at speed.
Обязанности
Application Security Program Ownership
Own and manage the Application Security program and secure software development lifecycle (SSDLC).
Establish, maintain, and continuously improve application security standards, policies, and procedures.
Ensure security requirements are integrated into engineering roadmaps and development processes.
Security Assessments & Threat Modeling
Conduct technical security reviews and application security assessments.
Lead threat modeling initiatives across products and platforms.
Identify architectural and design-level security risks and partner with engineering teams on mitigation strategies.
Vulnerability Management & Remediation
Drive the end-to-end vulnerability management lifecycle for applications and services.
Establish remediation priorities and accountability across engineering teams.
Track, report, and improve vulnerability remediation performance and risk reduction metrics.
Penetration Testing & Offensive Security
Manage external penetration testing engagements and red team activities.
Coordinate findings validation, remediation planning, and closure activities.
Ensure testing results are translated into actionable security improvements.
Security Tooling & CI/CD Integration
Oversee implementation and optimization of application security tooling, including:
SAST
DAST
Software Composition Analysis (SCA)
Secrets detection
Infrastructure-as-Code scanning
Integrate security controls and automated testing into CI/CD pipelines.
Continuously improve security gates while maintaining developer productivity.
Engineering Partnership & Enablement
Serve as the primary security partner to Engineering leadership.
Drive security awareness and secure coding practices across development teams.
Build scalable processes that enable engineers to identify and address security issues efficiently.
Promote a culture of shared security ownership.
Требования
7+ years of experience in Application Security, Product Security, or Security Engineering.
Strong understanding of secure software development practices and modern application architectures.
Experience performing threat modeling, security assessments, and code review activities.
Hands-on experience with vulnerability management and remediation programs.