IMPORTANT: Please be aware, scammers may try to impersonate Zello by reaching out regarding job opportunities. We will never ask you for bank account information, checks, or other sensitive information as part of our hiring process. All correspondence will come from the zello.com email domain. If you’re unsure, please email [email protected] with questions.
About ZelloZello is a voice-first communication platform, powered by our industry-leading push-to-talk technology, to improve collaboration and productivity for desk-less workers. With over 175+ million users, we’re the #1 rated push-to-talk app in the world, delivering 9 billion (yes, with a B) messages a month.
At Zello, our company values are at the heart of what we do everyday. We’re proud to serve the frontline, we’re privileged to connect people in times of crisis across the globe, and we’re honored to support first responders.
And this is where you come in.
Zello keeps frontline teams connected with instant voice, on a platform trusted by public safety, healthcare, utilities, and large retail. Our Security Engineering function has proven that AI can multiply security signal: our AI security reviewer is now our largest source of findings. The bottleneck has moved from detection to triage and remediation. You'll be the second security engineer, splitting an operate/build rotation with the Director of Security Engineering and building the automation that lets security scale without scaling headcount.
After a successful first year, you willHave completed Zello's Google Cloud hardening project, including the long-standing items that had been open for more than six months.
Have set the direction for and shipped supply chain security: SCA, SAST, and secrets scanning running in CI across our primary repos and blocking on High/Critical findings, plus package inventory and malicious-package scanning.
Have launched a vulnerability triage pipeline within six months that deduplicates, scores, and routes findings to owning teams, and auto-triages at least half of incoming findings by month twelve.
Have helped turn the vulnerability backlog net-negative and brought High/Critical findings open past SLA to zero, with the AI security agent tuned so its findings arrive already triaged.
Take your turn on interrupt duty (findings triage, access questions, incidents, and customer security assessments), then swap to protected build time.
Tune the AI security reviewer and triage agents, and decide which calls stay with a human owner.
Build the intake pipeline that routes findings from the AI reviewer, bug bounty, pen tests, and audits to the teams that own the code, with SLA clocks per severity.
Lead the Google Cloud hardening project across IAM, org policy, and workload configuration.
Choose and roll out code scanning and supply chain controls in GitHub and CI/CD, and make sure engineers can act on what the scanners find.
Review code and designs that touch authorization, identity, and tenancy, and push fixes through Platform, Web, and Backend teams.
Write the runbooks and requirements that let anyone on the team run a security process without you.
You've built and shipped security automation in code, and you can walk us through something you wrote that still runs in production.
You've applied LLMs or agents to real security work, and you have opinions about where AI output needs a human owner.
You can read application code and spot an exploitable authorization, identity, or secrets flaw, then explain it to the team that has to fix it.
You've rolled out security scanning in CI and turned the results into fixes, not just dashboards.
You've secured IAM and workloads in a major cloud. GCP is ideal; AWS or Azure is fine.
You get fixes shipped by teams you don't manage, and engineers describe working with you as straightforward.
You learn fast and go broad. You're comfortable moving between incident mode and build mode in the same week.
A people management role or the first step toward building a large security team.
A GRC or compliance role. Governance and audit programs sit with our CISO.
A 24/7 SOC role. Off-hours infrastructure monitoring stays with our MDR partner.
An IT helpdesk role. Day-to-day SaaS provisioning belongs to Ops.
We hire for potential, passion for our mission, and a knack for solving difficult problems over checking every qualification box. We have competitive pay, equity with significant upside, and intentionally design our benefits to encourage healthy and well-balanced employees, flexible schedules and time off. We even offer a sabbatical after every five years of service so you’re able to pursue and enjoy what matters most to you. And of course, we wouldn’t be a technology company without a ping-pong table and free snacks in our break room. Join us!
Zello provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
All Zello personnel are required to comply with defined security, privacy, and compliance requirements applicable to their role along with requirements that are applicable to all Zello personnel.
Skills Required
- Experience building and shipping security automation in production
- Experience applying LLMs or AI agents to security work
- Ability to review application code and identify authorization, identity, or secrets vulnerabilities
- Experience implementing security scanning in CI and driving remediation
- Experience securing IAM and workloads in a major cloud platform; GCP preferred, AWS or Azure acceptable
- Ability to influence engineering teams and communicate security fixes effectively
- Ability to work across incident response and security engineering build work
What We Do
We started as a company that turned phones into walkie-talkies. Today, we modernize instant voice communication with our industry-leading push-to-talk technology to help mobile workers meet quickly changing, urgent, real-world challenges. We have the highest-rated walkie-talkie app, with over 8 billion messages sent per month and 170 million users in industries such as transportation, retail, construction, hospitality, healthcare, and more. We’re proud to serve frontline workers, we’re privileged to connect people in times of crisis across the globe, and we’re honored to support first responders. As demand for our app continues to rise, we’ve evolved from a startup to a scale-up — and we’re still growing rapidly, which is where you come in.
Why Work With Us
If you strive to work on technology with purpose, technology that actually changes how people communicate and work, then come talk to us. We like people who take pride in their work, and deliver with consistency and quality. We're collaborative, sometimes serious, sometimes not, but we're all in 110%.
Gallery
Zello Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Zello is a hybrid workplace, where Austin employees typically work in the office on Tuesdays, Wednesdays, and Thursdays.