Product Security Engineer

Zoom

Northern (KY)

Hybrid

USD 99,000 - 229,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Zoom is seeking a Product Security Engineer to lead security design and reviews across Zoom’s products and services. You will collaborate with engineering teams to design, implement, and validate secure solutions, serving as a trusted security advisor on architecture and feature reviews.

The role requires a Bachelor's degree and 5+ years in security, with hands-on testing of web/native apps, cloud infrastructure (AWS), and secure coding practices. Hybrid/remote work options are provided.

Qualifications

  • Bachelor’s degree or equivalent experience in a technical field and 5+ years in security.
  • Experience with security testing of web/native apps, distributed systems, and cloud infrastructure (AWS).
  • Strong understanding of security architecture, threat modeling, secure code review, cryptography, and SDLC best practices.

Responsibilities

  • Serve as security SME guiding engineering teams in secure system design and implementation.
  • Conduct threat modeling, architecture review, security code review, assessments, and testing across apps and cloud services.
  • Perform cloud security reviews focusing on AWS IAM, S3, and related configurations.
  • Review new Zoom features for vulnerabilities and verify security posture via manual and automated testing (Burp Suite, Coverity).
  • Identify gaps in cloud security design/configuration and recommend improvements (auth, authorization, network segmentation, container hardening).
  • Provide hands-on security training and secure coding guidance to teams.

Skills

Security testing
Threat modelling
Architecture review
Secure coding
SDLC
AWS expertise
Java programming

Education

Bachelor's degree in Computer Science, Information Science, Cyber Security, Computer or Electrical Engineering

Tools

Burp Suite
Coverity
AWS

Job description

What you can expect

The Product Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you’ll collaborate with engineering teams to design, implement, and validate secure solutions. You’ll serve as a trusted security advisor, guiding architecture and reviewing implementation, particularly for new features or security enhancements. This is a unique opportunity to work with cutting-edge cloud and security technologies while making a direct impact on Zoom’s platform.

About the Team

The Security Architecture team is dedicated to ensuring Zoom releases and deploys secure products. We work with diverse engineering, compliance and DevOps teams across the organization to meet security goals and maintain compliance with established SLAs.

Responsibilities
  • Being a security subject-matter expert, guide engineering teams in end-to-end secure system design and implementation.
  • Conducting threat modeling, architecture review, security code review, security assessment, and security testing (web application, native application, web services, cloud-based services, and infrastructure assessments).
  • Performing cloud infrastructure reviews from a security perspective; the primary focus will be on AWS permissions and configuration issues within components like IAM and S3.
  • Performing an in-depth security review of new Zoom features and functionalities. This includes identifying security vulnerabilities such as those in the Owasp Top Ten, common issues from the NVD, and risks like RCE. It also involves reviewing Java or Python code and verifying security posture through manual and automated testing using tools like Burp Suite and Coverity.
  • Identifying gaps in existing cloud security architecture design/configuration, recommend changes or enhancements (authentication, authorization, network segmentation, container configuration, bastion host setup, etc.).
  • Providing hands on security training and secure coding best practices to engineering teams.
What we’re looking for
  • Have obtained a Bachelor's degree in Computer Science, Information Science, Cyber Security, Computer or Electrical Engineering (or similar field), or equivalent experience, and 5+ years of experience in security.
  • Have extensive experience in security testing in various environments, including assessing the security posture of web applications, native applications, distributed systems, and cloud infrastructure such as AWS. Focus on securing web services, infrastructure, deployment, and platform core services.
  • Possess a solid understanding of software security architecture, design, threat modeling, secure code review, cryptography, and the SDLC. Ability to clearly communicate best practices and effective mitigations for application security, particularly SDLC exceptions.
  • Have hands on security experience working with AWS and common service components within AWS. Ability to identify security gaps in the overall design as well as configuration issues in individual components.
  • Have in-depth knowledge of network based, system level, and application layer attacks and mitigation methods.
  • Have good knowledge of technology and security topics including network and application security (Owasp), infrastructure hardening, security baselines, web server, database security and applied cryptography.
  • Have good development experience in one or more of the programming languages and platforms such as Java is required.
Salary Range or On Target Earnings:

Minimum:

$98,900.00

Maximum:

$228,700.00

In addition to the base salary and/or OTE listed Zoom has a Total Direct Compensation philosophy that takes into consideration; base salary, bonus and equity value.

Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience.

We also have a location based compensation structure; there may be a different range for candidates in this and other locations.

Ways of Working

Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

Benefits

As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn for more information.

About Us

Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment.

Our Commitment

At Zoom, we believe great work happens when people feel supported and empowered. We’re committed to fair hiring practices that ensure every candidate is evaluated based on skills, experience, and potential. If you require an accommodation during the hiring process, let us know—we’re here to support you at every step.

We welcome people of different backgrounds, experiences, abilities and perspectives including qualified applicants with arrest and conviction records and any qualified applicants requiring reasonable accommodations in accordance with the law.

If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed.

Think of this opportunity as a marathon, not a sprint! We're building a strong team at Zoom, and we're looking for talented individuals to join us for the long haul. No need to rush your application – take your time to ensure it's a good fit for your career goals. We continuously review applications, so submit yours whenever you're ready to take the next step.

Our interviews are supported by BrightHire, a tool that helps us create a consistent and thoughtful interview experience and may include recordings. Please refer to our candidate privacy statement for more information of how we use your data.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Socket.dev • United States

Hybrid
USD 99,000 - 229,000
Security Engineer
Security Engineer

Zoom • Reno (NV)

On-site
USD 98,900 - 228,700
Security Engineer
Security Engineer

Zoom • Columbus (OH)

On-site
USD 98,900 - 228,700
Comprehensive benefits program
Support for work-life balance
Opportunities for career advancement
Security DevOps Engineer
Security DevOps Engineer

Zoom • San Jose (CA)

Hybrid
USD 87,600 - 186,000
Security DevOps Engineer
Security DevOps Engineer

Socket.dev • San Jose (CA)

Hybrid
USD 88,000 - 186,000
Security Engineer
Security Engineer

Zoom • Jackson (MS)

On-site
USD 87,600 - 186,000
Health and wellness benefits
Work-life balance initiatives
Career development opportunities
Security DevOps Engineer
Security DevOps Engineer

Zoom • United States

Hybrid
USD 88,000 - 186,000
Senior Security Analyst
Senior Security Analyst

Visa Hunt • United States

Hybrid
USD 88,000 - 186,000
Security Engineer
Security Engineer

Zoom • New York (NY)

On-site
USD 98,900 - 228,700
Comprehensive health benefits
Flexible work arrangements
Employee wellness programs
Senior Security Analyst
Senior Security Analyst

Zoom • United States

Hybrid
USD 88,000 - 186,000