Vulnerability Management Security Engineer

extra holidays - extra parental leave - fully flexible
Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

3+ years of experience in vulnerability management, application security, or DevSecOps within SaaS or cloud-first environments., Knowledge of vulnerability scoring frameworks and sources, including CVSS, CVE, CWE, and OWASP Top 10., Proficiency with security scanning tools for both infrastructure and application layers, with hands-on experience driving remediation alongside engineering teams., Solid understanding of secure development principles, CI/CD pipelines, and the software development lifecycle (SDLC)..

Key responsabilities:

  • Managing vulnerability intake and triage from various sources including internal teams and external researchers.
  • Collaborating with offensive security and engineering teams to validate findings and ensure meaningful fixes.
  • Translating offensive security insights into actionable remediation plans for development and infrastructure teams.
  • Coordinating and tracking remediation efforts across engineering teams and reporting on risk posture.

Zoom  logo
Zoom Information Technology & Services Large https://www.zoom.us/
5001 - 10000 Employees
See all jobs

Job description

Senior Security Engineer (Vulnerability Management) - Workvivo
 

What you can expect

We’re looking for a Vulnerability Management Engineer to strengthen our vulnerability lifecycle for the Workvivo SaaS platform. You’ll triage and drive remediation of technical vulnerabilities, with a focus on risk, prioritization, and working closely with developers. You’ll partner with engineering and DevOps to make sure security issues are not just found, but fixed. This isn’t a red teaming role, but you’ll work closely with red teamers and bug bounty researchers to turn their insights into action. The focus is on visibility, clear priorities, and delivering fixes — together with engineering.
 

About the Team

Workvivo is an employee experience platform designed to amplify workplace culture and foster employee engagement, regardless of location. Committed to customer satisfaction, Workvivo focuses on enhancing employees' working lives across diverse industries globally. As part of Zoom, an intelligent collaboration platform, Workvivo aligns with Zoom's mission to prioritize people, enabling meaningful connections, modern collaboration, and driving innovation in businesses and individual interactions.

In this position, you’ll have the opportunity to make a meaningful impact on the security of both Workvivo and Zoom.
 

Responsibilities

  • Managing vulnerability intake and triage by serving as a central point for reports from internal offensive security teams, external researchers, bug bounty platforms, and automated scanning tools. Removing noise and prioritizing based on risk and business context.
  • Collaborating with offensive security and engineering teams to validate findings, align on risk prioritization, and ensure attack simulations translate into meaningful, real-world fixes.
  • Translating offensive security insights into actionable remediation plans across development and infrastructure teams to drive secure practices.
  • Coordinating and tracking remediation efforts across engineering teams, providing context, defining realistic timelines, and reporting on risk posture through dashboards and SLA metrics.
  • Partnering with development teams to interpret findings, reduce false positives, and recommend remediations that fit naturally into existing workflows.
  • Operating and fine-tuning vulnerability scanning tools (e.g., SCA, SAST, DAST) across cloud infrastructure, containers, and endpoints to ensure coverage and accuracy.
  • Managing and integrating AppSec tooling into CI/CD pipelines, including SCA (e.g., Snyk, Dependabot), SAST (e.g., GitHub Advanced Security, SonarQube), and DAST (e.g., OWASP ZAP, Burp Suite Pro).
  • Improving automation and secure-by-default practices to shift security detection and resolution earlier in the development lifecycle.

What we’re looking for

  • 3+ years of experience in vulnerability management, application security, or DevSecOps within SaaS or cloud-first environments.
  • Have knowledge of vulnerability scoring frameworks and sources, including CVSS, CVE, CWE, and OWASP Top 10.
  • Have proficiency with security scanning tools for both infrastructure and application layers, with hands-on experience driving remediation alongside engineering teams.
  • Have solid understanding of secure development principles, CI/CD pipelines, and the software development lifecycle (SDLC).
  • Have the ability to collaborate closely with developers, aligning on fixes, integrating security into workflows, and fostering a security-first culture.
  • Have experience translating complex vulnerability data into clear, prioritized remediation plans for technical and non-technical stakeholders.
  • Be comfortable working with offensive security teams, using attack simulations and red team insights to drive defensive improvements.
  • Have a risk-based mindset, with a focus on reducing actual risk over merely detecting and reporting vulnerabilities.

Ways of Working
Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

Benefits
As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn for more information.

About Us
Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars.
We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Here, you’ll work across teams to deliver impactful projects that are changing the way people communicate and enjoy opportunities to advance your career in a diverse, inclusive environment.


Our Commitment​
We believe that the unique contributions of all Zoomies is the driver of our success. To make sure that our products and culture continue to incorporate everyone's perspectives and experience we never discriminate on the basis of race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran, or disability status. Zoom is proud to be an equal opportunity workplace and is an affirmative action employer. All your information will be kept confidential according to EEO guidelines.

We welcome people of different backgrounds, experiences, abilities and perspectives including qualified applicants with arrest and conviction records and any qualified applicants requiring reasonable accommodations in accordance with the law.

If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed.

#LI-Remote

Required profile

Experience

Industry :
Information Technology & Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Collaboration
  • Communication
  • Problem Solving

Security Engineer Related jobs