Talent.com
Security Engineer
Security EngineerZoom Corporation • Washington, DC, United States
Security Engineer

Security Engineer

Zoom Corporation • Washington, DC, United States
3 days ago
Job type
  • Full-time
Job description

What you can expect

The Security Engineer is responsible for security design and reviews across our products and services, with a specific focus on Platform services and core infrastructure components. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security.In this role, you'll collaborate with engineering teams, primarily those focused on Platform services, to design, implement, and validate secure solutions. You'll serve as a trusted security advisor, guiding architecture and reviewing implementation, particularly for new features or security enhancements. This is a unique opportunity to work with cutting-edge cloud and security technologies while making a direct impact on Zoom's platform.

About the Team

The Security Architecture team is dedicated to ensuring Zoom releases and deploys secure products. We work with diverse engineering, compliance, and DevOps teams across the organization to meet security goals and maintain compliance with established SLAs. Focusing on platform-level security, SDLC compliance, and core services.

Responsibilities

Being a security subject-matter expert, guide engineering teams in end-to-end secure system design and implementation, with a focus on Platform services and its associated components.

Conducting threat modeling, architecture review, security code review, security assessment, and security testing (web application, native application, web services, cloud-based services, and infrastructure assessments).

Performing cloud infrastructure reviews from a security perspective; the primary focus will be on AWS permissions and configuration issues within components like IAM and S3. This is especially important in the context of Platform services.

Performing an in-depth security review of new Zoom features and functionalities. This includes identifying security vulnerabilities such as those in the OWASP Top Ten, common issues from the NVD, and risks like RCE. It also involves reviewing Java or Python code and verifying security posture through manual and automated testing using tools like Burp Suite and Coverity.

Identifying gaps in existing cloud security architecture design / configuration, recommend changes or enhancements (authentication, authorization, network segmentation, container configuration, bastion host setup, etc.).

Providing hands on security training and secure coding best practices to engineering teams.

What we're looking for

Have obtained a Bachelor's in Computer Science, Information Science, Cyber Security, Computer or Electrical Engineering (or similar field), and 5+ years in security.

Have extensive experience in security testing across various environments. This includes assessing the security posture of web applications, native applications, distributed systems, and cloud infrastructure such as AWS. It also includes a focus on securing infrastructure, deployments, and core platform services.

Possess a solid understanding of software security architecture, design, threat modeling, secure code review, cryptography, and the SDLC. Able to clearly communicate best practices and effective mitigations for application security, particularly SDLC exceptions.

Have hands on security experience working with AWS and common service components within AWS. Ability to identify security gaps in the overall design as well as configuration issues in individual components.

Have in-depth knowledge of network based, system level, and application layer attacks and mitigation methods.

Have good knowledge of technology and security topics including network and application security (OWASP), infrastructure hardening, security baselines, web server, database security and applied cryptography.

Have good development experience in one or more of the programming languages and platforms such as Java is required.

Have the ability to speak Mandarin would be an advantage, but it's not an expectation.

Salary Range or On Target Earnings :

Minimum :

$98 900,00

Maximum : $228 700,00

In addition to the base salary and / or OTE listed Zoom has a Total Direct Compensation philosophy that takes into consideration; base salary, bonus and equity value.

Note : Starting pay will be based on a number of factors and commensurate with qualifications & experience.

We also have a location based compensation structure; there may be a different range for candidates in this and other locations

At Zoom, we offer a window of at least 5 days for you to apply because we believe in giving you every opportunity. Below is the potential closing date, just in case you want to mark it on your calendar. We look forward to receiving your application!

Anticipated Position Close Date :

12 / 08 / 25

Ways of WorkingOur structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description / posting.

BenefitsAs part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn () for more information.

About UsZoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars.We're problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment.

Our Commitment?

At Zoom, we believe great work happens when people feel supported and empowered. We're committed to fair hiring practices that ensure every candidate is evaluated based on skills, experience, and potential. If you require an accommodation during the hiring process, let us know-we're here to support you at every step.

If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form () and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed.

#LI-Remote

Create a job alert for this search

Security Engineer • Washington, DC, United States

Related jobs
Compliance and Security Engineer

Compliance and Security Engineer

TCG • Washington, DC, United States
Full-time
Compliance and Security Engineer.You've stumbled upon the rare B Corp government contractor!.At TCG, we aim to prove that businesses can be good to their employees and responsible to their communit...Show more
Last updated: 7 days ago • Promoted
Security Engineer (Infrastructure), Public Sector

Security Engineer (Infrastructure), Public Sector

Scale AI, Inc. • Washington, DC, United States
Full-time
Scale is a vital part of bringing AI-enabled technologies to the world, from autonomous driving to drones, robots, and large language models. For example, Scale works with the world's top self-drivi...Show more
Last updated: 30+ days ago • Promoted
Security Engineer

Security Engineer

Verotis • Washington, DC, United States
Full-time
Verotis is seeking an experienced Security Engineer to support security operations, strategy, planning, architecture, vulnerability assessments and remediation, and coordination with various govern...Show more
Last updated: 3 days ago • Promoted
Security Engineer

Security Engineer

META • Washington, DC, United States
Full-time
Meta), formerly known as Facebook Inc.When Facebook launched in 2004, it changed the way people connect.Apps and services like Messenger, Instagram, and WhatsApp further empowered billions around t...Show more
Last updated: 3 days ago • Promoted
Security Engineer

Security Engineer

National Geographic Society • Washington, DC, United States
Full-time
The Technology Division creates digital experiences for and delivers information technology services to the National Geographic Society. From our staff to our constituents, Technology provides the p...Show more
Last updated: 7 days ago • Promoted
Security Engineer

Security Engineer

Piper Companies • Fulton, MD, United States
Full-time
Piper Companies is seeking an experienced.SOC analysts to support their development in security analysis and incident investigation. Responsibilities of the Security Engineer include : .Support the im...Show more
Last updated: 3 days ago • Promoted
Lead Security Engineer

Lead Security Engineer

CoStar Group • Arlington, VA, United States
Full-time
CoStar Group (NASDAQ : CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, ...Show more
Last updated: 3 days ago • Promoted
Security Engineer

Security Engineer

Merit 321 • Greenbelt, MD, United States
Full-time
Our Client is seeking a Senior Security Engineer - Cyber Threat Mitigation Lead to work in our Washington, DC office to lead a cross functional team (Cyber Threat Intelligence, Hunt, and Analytics)...Show more
Last updated: 3 days ago • Promoted
Security Engineer

Security Engineer

AnaVation LLC • Washington, DC, United States
Full-time
Be Challenged and Make a Difference.In a world of technology, people make the difference.We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched va...Show more
Last updated: 3 days ago • Promoted
Offensive Security Engineer, Agent Security

Offensive Security Engineer, Agent Security

OpenAI • Washington, DC, United States
Full-time
Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products.We are...Show more
Last updated: 7 days ago • Promoted
Security Engineer / Architect (Hybrid)

Security Engineer / Architect (Hybrid)

Huntington Ingalls Industries • Fort Belvoir, VA, United States
Full-time
Enlighten, honored as a Top Workplace from USA Today, is a leader in big data solution development and deployment, with expertise in cloud-based services, software and systems engineering, cyber ca...Show more
Last updated: 30+ days ago • Promoted
Security Engineer

Security Engineer

HireCapital • Washington, DC, United States
Full-time +1
Direct message the job poster from HireCapital.Technical Recruiter placing talent at innovative and mission-driven organizations. Our client is a rapidly growing technology firm operating at the int...Show more
Last updated: 30+ days ago • Promoted
Security Engineer

Security Engineer

BRG • Washington, DC, United States
Full-time
HAP Tech, a subgroup of BRG’s Healthcare Analytics practice (HAP), is one of the firm’s largest and fastest growing teams. This innovative group is currently looking for talented and dynamic profess...Show more
Last updated: 7 days ago • Promoted
Security Engineer

Security Engineer

Tammina • Washington, DC, United States
Full-time
The security engineering position provides support to a Security Operation Center of a federal agency.Ideal candidate will have comprehensive knowledge of Windows and UNIX-based system administrati...Show more
Last updated: 3 days ago • Promoted
Lead Security Engineer

Lead Security Engineer

CoStar Realty Information, Inc. • Arlington, VA, United States
Full-time
CoStar Group (NASDAQ : CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, ...Show more
Last updated: 3 days ago • Promoted
Security Engineer

Security Engineer

Berkeley Research Group • Washington, DC, United States
Full-time
Second Sight Solutions, a subsidiary of Berkeley Research Group (BRG), is a health technology company, and our innovative technology reimagines how drug discount data is exchanged, establishing new...Show more
Last updated: 3 days ago • Promoted
Security Engineer

Security Engineer

Scout Solutions Inc Defunct • Washington, DC, United States
Full-time
Security Clearance : TS / SCI + required and able to receive their PSD / Yankee White, or Active Yankee White Clearance.Our Client is a top-rated cyber security firm that is passionate about providing e...Show more
Last updated: 3 days ago • Promoted
Baseline Security Engineer, Lead

Baseline Security Engineer, Lead

Booz Allen Hamilton • Washington, DC, United States
Full-time +1
Baseline Security Engineer, Lead.Develop and implement security solutions in alignment with security strategy.Maintain an awareness of market and technology trends to bring best of breed solutions ...Show more
Last updated: 3 days ago • Promoted