Security Engineer

Sorry, this job was removed at 9:56 a.m. (CST) on Tuesday, December 28, 2021
Find out who's hiring in Colorado, CO.
See all Cybersecurity + IT jobs in Colorado, CO
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Security Engineer

Remote U.S. / Full Time

Zoom is looking for a Security Engineer to join our Security Architecture team, reporting to our Head of Security Architecture. You will work with our engineering and operations teams to review and validate the security postures of new Zoom features prior to product release. This includes architecture guidance for common vulnerabilities, such as Remote Code Execution (RCE), Privilege Escalation, misconfiguration, and other OWASP top 10 vulnerabilities (SQL injection, XSS, broken access control, etc).

Responsibilities:

  • You will conduct threat modeling, architecture review, security code review, security assessment, penetration testing (web application, native application, web services, cloud-based services, and infrastructure assessments).

  • You will be asked to perform cloud infrastructure review from a security perspective; the primary focus will be on AWS and many of its common service components such as S3, IAM, EC2, VPC.

  • Perform in-depth security review of new Zoom features. This includes identifying security vulnerabilities (OWASP top ten, common issues in NVD, RCE), reviewing code in Java or C++, verifying security posture through pen-test (using manual/automated techniques with tools like Kali Linux, Burp suite, Checkmarx, WebInspect).

  • Identify gaps in existing cloud security architecture design/configuration and recommend changes (authentication, authorization, network segmentation, container configuration, bastion host setup).

  • You will partner with engineering and operation teams to integrate mitigation controls into continuous integration, delivery and deployment processes.

  • Work on essential areas to develop security baseline for cloud, container, and application and integrate it into the CI/CD pipeline.

  • Implement security architecture, methods, and controls required to meet security, compliance, and audit requirements (NIST controls, SOC2).

Qualifications:

  • Bachelor's degree in Computer Science, Information Science, Cyber Security, Computer or Electrical Engineering (or similar field), and 4+ years in security.

  • Extensive experience in penetration testing in different environments, including assessing security posture of web application, native application, distributed systems, and cloud infrastructure such as AWS.

  • Understanding of software security architecture and design, threat modeling, security code review, SDLC, and best practices and mitigations for application security.

  • Hands-on security experience working with AWS and common service components within AWS. Identify security gaps in the design and configuration issues in individual components.

  • In-depth knowledge of network-based, system level, and application layer attacks and mitigation methods.

  • Experience with a broad range of security technologies including VPC, IAM, KMS, etc. in AWS.

  • Knowledge of technology and security topics including network and application security (OWASP), infrastructure hardening, security baselines, web server, and database security.

  • Expertise in cloud automation tools such as Terraform, CloudFormation, Ansible, etc.

  • Development experience in programming languages such as Java, JavaScript, Python, or Go.

#LI-Remote

Colorado Salary Range or On Target Earnings:

Minimum:

$137,600.00 USD

Maximum :

$206,400.00 USD

In addition to the base salary and/or OTE listed, Zoom has a Total Direct Compensation philosophy that takes into consideration base salary, bonus and equity value. Information about Zoom’s benefits is here. Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience. We also have a location based compensation structure; there may be a different range for candidates in other locations.

Ensuring a diverse and inclusive workplace where we learn from each other is core to Zoom’s values. We welcome people of different backgrounds, experiences, abilities and perspectives including qualified applicants with arrest and conviction records as well as any qualified applicants requiring reasonable accommodations in accordance with the law.

We believe that the unique contributions of all Zoomies is the driver of our success. To make sure that our products and culture continue to incorporate everyone's perspectives and experience we never discriminate on the basis of race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran, or disability status.

All your information will be kept confidential according to EEO guidelines.

Explore Zoom:

  • Hear from our leadership team

  • Browse Awards and Employee Reviews on Comparably

  • Visit our Blog

  • Zoom with us!

  • Find us on social at the links below and on Instagram

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Similar Jobs

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Zoom Video CommunicationsFind similar jobs