Enable job alerts via email!

Offensive Security Engineer - Workvivo

Zoom

London

Hybrid

GBP 60,000 - 100,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking a Senior Security Engineer to enhance security across its platforms. This role focuses on identifying vulnerabilities in web and mobile applications, conducting penetration tests, and collaborating with engineering teams to integrate secure coding practices. You will play a vital role in fostering a culture of security awareness and contribute to the organization's engineering security training. If you are passionate about security and eager to make a significant impact, this is the opportunity for you.

Benefits

Health and wellness benefits
Flexible working hours
Remote work options
Professional development opportunities

Qualifications

  • Extensive experience in penetration testing of web applications and APIs.
  • Solid understanding of secure coding practices and security frameworks.

Responsibilities

  • Conduct regular security assessments and penetration testing on applications.
  • Collaborate with teams to address vulnerabilities and enhance security practices.

Skills

Penetration Testing
AWS
Secure Coding Practices
Vulnerability Analysis
Threat Modeling

Education

Bachelor's in Computer Science or related field
Certifications in Information Security (e.g., CISSP, CEH)

Tools

Burp Suite
Invicti (Netsparker)

Job description

Senior Security Engineer (Offensive) - Workvivo

What you can expect

In this role, you’ll focus on uncovering and addressing vulnerabilities across the Workvivo platform, including our Web App, Mobile App, Mobile and AWS Infrastructure.

You will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.

We’re looking for people who will work closely with application engineering teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.

About the Team

Workvivo is an employee experience platform designed to amplify workplace culture and foster employee engagement, regardless of location. Committed to customer satisfaction, Workvivo focuses on enhancing employees' working lives across diverse industries globally. As part of Zoom, an intelligent collaboration platform, Workvivo aligns with Zoom's mission to prioritize people, enabling meaningful connections, modern collaboration, and driving innovation in businesses and individual interactions.

In this position, you’ll have the opportunity to make a meaningful impact on the security of both Workvivo and Zoom. This includes contributing to our engineering security training program and collaborating cross-functionally within Zoom Security, including teams like Bug Bounty, Incident Response, SOC, Vulnerability Management, and Customer Security Assurance (CSA).

Responsibilities

  • Conducting regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software associated with the Workvivo Platform, including AWS Infrastructure and the Web and Mobile Apps.
  • Discovering vulnerabilities associated with the Workvivo platform and infrastructure, and working with Workvivo's and Zoom's internal teams to address them. Collaborating daily with Security, AWS Infrastructure, and Application engineering teams to ensure security, scalability, and stability.
  • Prioritizing threat modeling of new security features before deployment. Conducting threat modeling and risk assessments to proactively identify risks and develop mitigation strategies, working with application engineering and other teams early in the design phase.
  • Contributing to improving the Software Development Lifecycle (SDLC) by advising on DAST, SAST, SCA, securing pipelines, and introducing automated security solutions.
  • Enhancing security practices across Workvivo and Zoom, including feeding into the engineering security training program.
  • Working cross-functionally within Zoom Security, including teams like Bug Bounty, Incident Response, SOC, Vulnerability Management, and CSA.
  • Introducing and coding automated security solutions.

What we’re looking for

  • Extensive experience in conducting penetration tests focused on Web Applications, APIs, and Mobile platforms.
  • Ability to critically analyze vulnerability and penetration test reports from external partners and customers.
  • Capability to go beyond superficial vulnerabilities like security headers and challenge security issues critically.
  • Experience in creating architectural diagrams emphasizing security controls.
  • Background in application security, software development, or related fields, with a solid understanding of secure coding practices and security frameworks.
  • Good knowledge of AWS.
  • Proficiency with tools like Burp Suite, Invicti (Netsparker), or similar.
  • Proficiency in programming languages such as PHP, Laravel, Go, Java, C++, etc., and familiarity with security tools and protocols.
  • Excellent attention to detail, curiosity, focus, and the ability to discuss security technologies with both technical and non-technical audiences.

Ways of Working

Our hybrid approach combines office and remote work, with the specific work style indicated in the job posting.

Benefits

Our benefits program supports physical, mental, emotional, and financial health, work-life balance, and community involvement. Click Learn for more information.

About Us

Zoom helps people stay connected and productive. Our products include Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We are a fast-paced problem-solving team focused on innovative solutions and growth opportunities.

Our Commitment

We value fair hiring practices and support candidates requiring accommodations during the hiring process. If needed, submit an Accommodations Request Form. We are committed to supporting all candidates through our inclusive hiring process.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Offensive Security Engineer - Workvivo

Zoom Video Communications

London

On-site

GBP 60,000 - 100,000

30+ days ago