Senior Security Engineer jobs in United States
info-icon
This job has closed.
company-logo

Zoom · 2 days ago

Senior Security Engineer

Zoom is a company dedicated to building the best collaboration platform for enterprises. They are seeking a Senior Security Engineer to be responsible for security design and reviews across products and services, focusing on Platform services and core infrastructure components while collaborating with engineering teams to implement secure solutions.

CollaborationInformation TechnologyMessagingSaaSVideo Conferencing
check
H1B Sponsor Likelynote

Responsibilities

Being a security subject-matter expert, guide engineering teams in end-to-end secure system design and implementation, with a focus on Platform services and its associated components
Conducting threat modeling, architecture review, security code review, security assessment, and security testing (web application, native application, web services, cloud-based services, and infrastructure assessments)
Performing cloud infrastructure reviews from a security perspective; the primary focus will be on AWS permissions and configuration issues within components like IAM and S3. This is especially important in the context of Platform services
Performing an in-depth security review of new Zoom features and functionalities. This includes identifying security vulnerabilities such as those in the OWASP Top Ten, common issues from the NVD, and risks like RCE. It also involves reviewing Java or Python code and verifying security posture through manual and automated testing using tools like Burp Suite and Coverity
Identifying gaps in existing cloud security architecture design/configuration, recommend changes or enhancements (authentication, authorization, network segmentation, container configuration, bastion host setup, etc.)
Providing hands on security training and secure coding best practices to engineering teams

Qualification

Security TestingAWSThreat ModelingSecure Code ReviewSoftware Security ArchitectureCryptographyNetwork SecurityJavaMandarinCommunication Skills

Required

Have obtained a Bachelor's in Computer Science, Information Science, Cyber Security, Computer or Electrical Engineering (or similar field), and 8+ years in security
Have extensive experience in security testing across various environments. This includes assessing the security posture of web applications, native applications, distributed systems, and cloud infrastructure such as AWS. It also includes a focus on securing infrastructure, deployments, and core platform services
Possess a solid understanding of software security architecture, design, threat modeling, secure code review, cryptography, and the SDLC. Able to clearly communicate best practices and effective mitigations for application security, particularly SDLC exceptions
Have hands on security experience working with AWS and common service components within AWS. Ability to identify security gaps in the overall design as well as configuration issues in individual components
Have in-depth knowledge of network based, system level, and application layer attacks and mitigation methods
Have good knowledge of technology and security topics including network and application security (OWASP), infrastructure hardening, security baselines, web server, database security and applied cryptography
Have good development experience in one or more of the programming languages and platforms such as Java is required

Preferred

The ability to speak Mandarin would be an advantage, but it's not an expectation

Benefits

Our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways.

Company

Zoom

twittertwittertwitter
company-logo
Zoom is a software company that offers a communications platform that connects people through video, voice, chat, and content sharing.

H1B Sponsorship

Zoom has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (16)
2024 (178)
2023 (144)
2022 (259)
2021 (86)
2020 (34)

Funding

Current Stage
Public Company
Total Funding
$276M
Key Investors
ARK Investment ManagementSequoia CapitalEmergence Capital
2021-11-04Post Ipo Equity· $130M
2019-04-19Post Ipo Equity
2019-04-18IPO

Leadership Team

leader-logo
Eric Yuan
Founder & CEO
linkedin
leader-logo
Xuedong Huang
Chief Technology Officer
linkedin
Company data provided by crunchbase