Full-Time

Senior Application Security Engineer

Multiple Teams

Posted on 11/7/2025

Ivalua

Ivalua

1,001-5,000 employees

SaaS procurement platform for sourcing

Compensation Overview

$130k - $190k/yr

+ Annual target bonus

Fremont, CA, USA + 2 more

More locations: Pittsburgh, PA, USA | New York, NY, USA

Hybrid

Hybrid work model; 3 days in-office per week.

Category
IT & Security (1)
Requirements
  • Bachelor’s degree in relevant field preferred with a minimum of 7 years of relevant professional experience, OR Master’s degree in relevant field with a minimum of 5 years of relevant professional experience, OR Equivalent combination of education and experience
  • Proven practical experience in integrating security as part of SDLC (security by design, security code reviews, security tests etc.)
  • Highly proficient in scripting, client-side programming and query languages (such as Python, JavaScript, SQL)
  • Experience with the industry-recognized application security tools (BurpSuite, SQLMap, Invicti, Checkmarx etc.)
  • An Offensive Security qualification or evidence of starting to work towards e.g. OSCP, OSWE, GPEN, GWAPT, CPTS, Hack-the-Box labs or root-me challenges or similar is preferred but not required
  • Ability to handle multiple tasks, prioritize and meet deadlines
Responsibilities
  • Perform manual web application penetration testing on the Ivalua SaaS application product, web services as well as the corporate critical or internet-facing web applications
  • Enhance/Optimize the application security tooling scanning configurations (SAST, DAST, SCA) to reduce false positives/negatives
  • Write and maintain in-house automated scripts to complement the scanning tool gaps and industrialize the manual security tests
  • Act as the main POC for analyzing, discussing and reviewing the technical audits findings from US customers
  • Advocate and support the implementation of security best practices as part of the development lifecycle within the R&D department including security design reviews and security testing of major product changes or enhancements
  • Support the analysis, reporting, tracking and retesting of security vulnerabilities reported through multiple sources (customer, internal and external audits) and provide guidance to developers to fix these in a manner consistent with Ivalua standards
  • Contribute to develop, enhance, maintain and deliver a developer security training program and maintain secure development guidelines
  • Act as one of the SME on application security and stay apprised on new vulnerabilities, threats, risks, tools and techniques

Ivalua provides a SaaS procurement platform that helps businesses manage the entire procurement process from sourcing to payment. The core offering, the Procurement Empowerment Platform, includes modules for strategic sourcing, supplier management, contract management, and procure-to-pay, all delivered through a configurable, industry-tailored interface. The product is quickly deployable and mobile-friendly, enabling broad user adoption across organizations such as healthcare providers, schools, and large enterprises. Unlike generic solutions, Ivalua emphasizes industry-specific configurations and flexibility to fit diverse business needs. The goal is to digitize and optimize procurement to drive cost savings and stronger supplier relationships.

Company Size

1,001-5,000

Company Stage

Growth Equity (Non-Venture Capital)

Total Funding

$250M

Headquarters

Massy, France

Founded

2000

Simplify Jobs

Simplify's Take

What believers are saying

  • 24% organic subscription revenue growth in 2025 drives expansion to over 1,000 employees across 15 offices.
  • Singapore office opening supports 29% APAC consultant growth, serving BAE Systems and Air New Zealand.
  • Pernod Ricard and CNP Assicura wins harmonize global procurement with DORA-compliant features.

What critics are saying

  • SAP Ariba's S/4HANA bundling locks in enterprises, eroding Ivalua's Source-to-Pay share by 2027.
  • Coupa's Thoma Bravo acquisition undercuts mid-market pricing, stalling Ivalua's subscription growth in 2026.
  • FedRAMP High failure by Q4 2026 blocks DoD IL4/IL5 contracts, ceding $2B defense market to Jaggaer.

What makes Ivalua unique

  • Ivalua's unified AI-powered platform covers sourcing to procure-to-pay with industry-specific configurations.
  • GovCloud deployment centralizes supplier collaboration for General Atomics, meeting DoD compliance needs.
  • IVA Studio enables agentic AI for autonomous RFP launches and contract analysis at scale.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

401(k) Company Match

Hybrid Work Options

Meal Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Procurement Magazine
Mar 31st, 2026
David Khuat-Duy: leading the AI orchestration era.

David Khuat-Duy: leading the AI orchestration era. March 31, 2026 Ivalua's Founder and CAIO David Khuat-Duy explains why 2026 marks the shift from AI experimentation to autonomous enterprise reality While 2025 was defined by AI experimentation, 2026 has emerged as the year of true disruption. David Khuat-Duy, Founder and Chief AI Officer at Ivalua, spoke at Ivalua NOW 2026, where he explored the strategic transition from traditional procurement software to AI-driven orchestration. David looks at the shift from simple process optimisation to agentic AI, detailing how autonomous systems are breaking human bandwidth constraints and providing a scalable blueprint for the future of the autonomous enterprise. You recently transitioned from CEO to Chief AI Officer after 25 years. What inspired this shift, and what has this first year in the role shown you about the pace of change? I've been CEO for 25 years, but as an engineer by trade, I felt Procurement Mag were reaching a tipping point where AI becomes truly transformative. I felt it was going to disrupt the software industry, its operations, and most importantly, its customers. Procurement Mag needed to provide a solution, whether integrated with platforms like SAP S/4HANA or its own, that helps them thrive through this change. This past year has shown me that things are not slowing down; they are accelerating. While 2025 was for experimentation, 2026 is where disruption happens in real life for enterprises. Procurement Mag has moved from the "first version" of AI, which merely optimised processes, to a new era where AI can operate for people. With the maturity of agentic approaches, AI is now capable of doing the work, not just assisting it. Many leaders struggle to see measurable ROI from AI. What tangible benefits are your customers seeing, and how does AI help them go beyond their previous manual limits? ROI is already a reality. Procurement Mag has over 50% of its customers live in production, using AI daily to achieve tangible gains in efficiency and cash. The most significant shift is in capacity. Previously, teams were constrained by their physical bandwidth; they could only do as much as their human resources allowed. With AI, they can go beyond those limits. For example, a team can now launch more RFPs with a much broader supplier base, capturing savings that were previously left on the table. They can conduct deep contract analysis at a scale that was once impossible. It allows organisations to manage risk better and be more efficient by removing the "bandwidth ceiling" that has historically limited procurement's impact. What is the one major takeaway for procurement leaders looking to stay ahead in this rapidly evolving landscape? My advice is simple: jump onto the train now. Do not miss this window. Procurement Mag is releasing its new IVA Studio agentic platform in the coming months, which represents a massive leap in power and capability. I invite everyone to test these tools and move into deployment as soon as possible. The era of waiting to see what happens is over; the era of AI execution is here. Executives. * David Khuat-Duy Founder, chairman & CAIO. Company portals.

PR Newswire
Mar 20th, 2026
Ivalua wins three Comparably awards after 24% subscription revenue growth

Ivalua, an AI-powered spend management platform, has received three Comparably awards: Best Company for Outlook, for Women, and for Diversity. The recognition is based on anonymous employee feedback collected over 12 months. The company reported 24% organic growth in subscription revenue in 2025 and expanded its workforce to over 1,000 employees across 15 offices globally. Ninety-one per cent of employees expressed confidence in the company's future success. Ivalua has championed women in procurement through various initiatives including meetings, webinars and panels, supported by an internal Women Committee. The company serves over 500 clients and is recognised as a leader in spend management by Gartner. The awards required minimum participation of 75 employees for companies with over 500 staff.

TechInformed
Feb 5th, 2026
General Atomics picks Ivalua to centralize supplier collaboration on GovCloud

General Atomics picks Ivalua to centralize supplier collaboration on GovCloud. General Atomics, a leading global aerospace and defence manufacturer, has selected Ivalua as its enterprise-wide supplier collaboration platform, aiming to tighten supplier visibility, quality controls and coordination across procurement, planning, compliance and finance. Ivalua said the platform will become General Atomics' "single system of record" for supplier collaboration and will be deployed first on GovCloud. GovCloud is a restricted cloud environment used for government and contractor workloads that require tighter security controls. Ivalua said the initial GovCloud deployment spans information management, supplier risk and performance management, issue and program management, strategic sourcing, contract management, supply chain collaboration, purchase orders, receiving and accounts payable automation. General Atomics describes itself as a diversified defense and technology company founded in 1955 with operations that occupy more than 8 million square feet of facilities and employ more than 13,000 people, which helps explain why cross-functional supplier data can become hard to reconcile at scale. The supplier's workflow data is deployed in a GovCloud environment rather than a back-office IT refresh. GovCloud environments are typically used for workloads that require additional isolation and compliance controls under U.S. government cloud authorization frameworks. Ivalua has previously said it achieved "FedRAMP Ready" status for moderate impact certification and is listed on the FedRAMP Marketplace, positioning its GovCloud offer for U.S. public-sector and regulated workloads. FedRAMP sets standardized security baselines (Low, Moderate and High) using impact levels tied to confidentiality, integrity, and availability, and DoD overlays additional authorization requirements for certain mission use cases. For defense contractors, these often map to DoD Impact Levels (IL), where IL4 and IL5 cover Controlled Unclassified Information (CUI) and mission-critical data. Why General Atomics is consolidating supplier workflows The move aligns with a federal push to improve supply chain illumination, a requirement underscored by the GSA's 2025 award of the $919 million SCRIPTS contract and the Defense Business Board's 2025 recommendations for permanent sub-tier visibility. A DoD supply chain risk management guidebook describes roles and practices for identifying and mitigating supply chain risk. The same Defense Business Board report has argued that sustained illumination efforts are required to identify risks in "long-lead" components before they disrupt production.

PR Newswire
Jan 29th, 2026
Ivalua hits record 2025 with over 500 customers and 27% partner growth amid AI expansion

Ivalua, a global spend and supplier management platform, has reported record growth in 2025, with over 25% organic subscription revenue growth and strong profitability. The company expanded to over 1,000 employees across 15 offices worldwide, opening new locations in New York, Singapore and Sydney. The Redwood City-based firm signed a record number of customers, bringing its total to over 500 brands including BAE Systems, Pernod Ricard and Oman Air. Ivalua's partner ecosystem grew significantly, with certified partners and consultants reaching 3,100, a 27% increase. The company earned multiple analyst recognitions, including Leader positions in Gartner's Magic Quadrant for Source-to-Pay Suites and IDC's MarketScapes. Ivalua also achieved EcoVadis Gold Medal status and published its first sustainability report.

Ivalua
Dec 16th, 2025
Ivalua Ends Year with More "Best Company" Comparably Awards

Ivalua ends year with more "Best Company" Comparably awards. Recognized for Best Company Culture, CEO, and Compensation. Redwood City, CA, December 16, 2025. Ivalua, a global leader in spend management, today announced that it has closed the year with a trio of prestigious Comparably awards: Best Company Culture, Best CEO, and Best Company Compensation. These awards are based on 12 months of feedback from current employees who anonymously rate their employers on Comparably.com. Earlier this year, Ivalua also earned recognition for Best Company Outlook, Career Growth, Diversity, Leadership, and Employee Happiness. Employees consistently cite Ivalua's collaborative and values-driven workplace. Responding to "what is most positive about the culture and environment at Ivalua?" one member of the customer care team noted: "People genuinely support one another, share ideas freely, and work together toward common goals." A sales team member added: "The strong emphasis on the 5 core values: customer-centricity, collaboration, results-orientation, caring and growing people, and integrity; the way they shape the workplace." With more than 1,000 employees across 15 offices worldwide, Ivalua's culture remains a defining strength: 96% of employees told Comparably they are proud to work at the company. "Culture is the foundation of everything we do at Ivalua, and I am proud to see every day how our core values blend with a spirit of innovation and a drive for growth," said Franck Lheureux, CEO at Ivalua. "I am humbled by the Best CEO recognition, which reflects the achievements of our entire team. As we celebrate this success, I'm excited to build on our momentum and lead Ivalua into an even brighter future." About Ivalua. Ivalua is a leading provider of cloud-based, Spend Management software powered by AI agents. Its unified Source-to-Pay platform enables businesses to better manage all categories of spend and all suppliers, increasing profitability, improving sustainability, lowering risk and boosting employee productivity. Ivalua Inc. is trusted by hundreds of the world's most admired brands and recognized as a leader by Gartner and other analysts. Learn more at www.ivalua.com. Follow Ivalua Inc. on LinkedIn.

INACTIVE