Security Engineer (VMBB) at Zoom Video Communications
In most cases, you will have the opportunity to choose your preferred working location from the following options when you join Zoom: in-person, hybrid or remote. Visit this page for more information about Zoom's Workstyles .
Zoomies help people stay connected so they can get more done together. We set out to build the best video product for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinar.
We're problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Here, you'll work across teams to deliver impactful projects that are changing the way people communicate and enjoy opportunities to advance your career in a diverse, inclusive environment.
We are looking for a Security Engineer to join our Vulnerability Management and Bug Bounty team, reporting to our Head of VMBB . You will create POCs for known vulnerabilities, provide root-cause analysis for triaged vulnerabilities, and work with engineers throughout Zoom to remediate vulnerabilities.
- Provide root cause analysis of triaged vulnerabilities
- Provide actionable security guidance to engineers to enable remediation within SLA
- Create POCs to facilitate fix verification and enable regression testing
- Help drive quality engagement on bug bounty programs
- Work with product security team to review and process external reports
- Provide guidance on effective vulnerability countermeasures
- Contribute to security policy, standards, and guidelines related to Bug Bounty and Vulnerability Management
- Engage with the security researcher community and assess incoming Bug Bounty submissions
- Hands-on experience discovering, validating and fixing common vulnerabilities
- Ability to distill complex security problems and drive towards creative solutions
- Ability to engage with teams to review security issues and recommend solutions
- Excellent written and verbal communication skills for conveying security concepts and engineering solutions
- Strong knowledge of web, mobile, and/or desktop application security vulnerabilities and countermeasures, including the OWASP Top 10
- Experience with application programming
- 5+ years of related experience with a Bachelor's degree in Computer Science/Engineering, Cybersecurity, or related field
- Prior bug hunting and/or bug triage experience
- Experience performing threat modeling, design and code reviews to assess security implications and requirements for the introduction of new systems and technologies
- Experience building out integrations with open source scanners and/or vendor products
- History of participating in Bug Bounty programs
We believe that the unique contributions of all Zoomies is the driver of our success. To make sure that our products and culture continue to incorporate everyone's perspectives and experience we never discriminate on the basis of race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran, or disability status. Zoom is proud to be an equal opportunity workplace and is an affirmative action employer. All your information will be kept confidential according to EEO guidelines.
We welcome people of different backgrounds, experiences, abilities and perspectives including qualified applicants with arrest and conviction records and any qualified applicants requiring reasonable accommodations in accordance with the law. If you need any assistance or accommodations due to a medical condition, or if you need assistance accessing our website or completing the application process, please let us know by emailing us at [email protected] .
Colorado Salary Range or On Target Earnings:
In addition to the base salary and/or OTE listed, Zoom has a Total Direct Compensation philosophy that takes into consideration base salary, bonus and equity value. Information about Zoom's benefits is here . Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience. We also have a location based compensation structure; there may be a different range for candidates in other locations.
Zoom requires all U.S. employees who will work in person at a Zoom office, attend in-person Zoom meetings or have in-person customer meetings to be fully vaccinated. Zoom will consider requests for reasonable accommodations for religious or medical reasons as required under applicable law.
- Hear from our leadership team
- Browse Awards and Employee Reviews on Comparably
- Visit our Blog
- Zoom with us!
- Find us on social at the links below and on Instagram
- View more jobs, sign up for job alerts and join our talent community. Visit the Zoom careers site .