Security Engineer - Remote
About The Company
Zoom Video Communications is a leading provider of innovative communication solutions designed to connect people seamlessly across the globe. Renowned for its user-friendly platform, Zoom offers a comprehensive suite of products including Zoom Meetings, Zoom Phone, Zoom Webinars, Zoom Rooms, and Zoom Contact Center, enabling organizations to collaborate effectively in a hybrid or remote work environment. The company is committed to fostering a dynamic, inclusive, and growth-oriented culture that values innovation, integrity, and customer-centricity. With a focus on security, reliability, and scalability, Zoom continuously invests in cutting-edge technologies to deliver secure, high-quality communication experiences for millions of users worldwide. As part of its mission, Zoom aims to empower people to achieve more together, making remote collaboration effortless and productive across diverse industries and sectors.
About The Role
The Security Engineer at Zoom plays a critical role in safeguarding the company's products and services through comprehensive security design, review, and implementation. This position requires a highly skilled security professional with extensive hands-on experience in end-to-end product security, cloud security, and secure coding practices. The Security Engineer collaborates closely with engineering teams to architect secure solutions, conduct threat modeling, perform security assessments, and review code for vulnerabilities. You will serve as a trusted security advisor, guiding the development of new features and security enhancements to ensure compliance with industry standards and best practices. This role offers a unique opportunity to work with advanced cloud and security technologies, contributing directly to the security posture of Zoom's platform and ensuring the protection of customer data and infrastructure.
Qualifications
- Bachelor's degree in Computer Science, Information Science, Cyber Security, Computer or Electrical Engineering, or a related field, or equivalent practical experience
- Minimum of 5+ years of professional experience in security, with a focus on web applications, native applications, distributed systems, and cloud infrastructure
- Extensive experience in security testing, vulnerability assessment, and security posture evaluation
- Strong understanding of software security architecture, threat modeling, secure coding, cryptography, and SDLC best practices
- Hands-on experience working with AWS services, including IAM, S3, and cloud configuration management
- In-depth knowledge of network, system, and application layer attacks and their mitigation strategies
- Proficiency in programming languages such as Java, Python, or similar platforms
- Experience with security tools like Burp Suite, Coverity, and automated testing frameworks
- Excellent communication skills with the ability to clearly articulate security concepts and best practices
Responsibilities
- Guide engineering teams in designing and implementing secure systems across the product lifecycle
- Conduct threat modeling, architecture reviews, and security assessments for new features and existing systems
- Perform security code reviews, vulnerability testing, and security testing of web applications, native apps, and cloud services
- Review cloud infrastructure configurations, focusing on AWS permissions, IAM policies, and S3 security settings
- Identify security gaps in architecture and configuration; recommend and implement improvements for authentication, authorization, network segmentation, and container security
- Perform in-depth security reviews of new product features, identifying vulnerabilities such as OWASP Top Ten issues and risks like remote code execution
- Utilize manual and automated testing tools to verify security posture and ensure compliance with security standards
- Provide security training and promote secure coding practices within engineering teams
- Stay updated on emerging security threats, industry trends, and best practices to continuously enhance security measures
Benefits
- Competitive salary package with a range of $98,900 to $228,700, including bonuses and equity options
- Comprehensive health, dental, and vision insurance plans
- Flexible work arrangements including hybrid, remote, or in-office options
- Generous paid time off and holiday leave policies
- Opportunities for professional growth and career development
- Access to wellness programs, employee assistance programs, and financial planning resources
- Inclusive and diverse workplace culture that values innovation and collaboration