Zoom

Offensive Security Engineer, Workvivo - UK

United Kingdom

Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Software, Biotechnology, Employee Experience PlatformIndustries

Employment Type

Full time

Senior Security Engineer (Offensive) - Workvivo

What you can expect

  • Focus on uncovering and addressing vulnerabilities across the Workvivo platform, including Web App, Mobile App, and AWS Infrastructure.
  • Identify and mitigate security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.
  • Work closely with application engineering teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge.
  • Provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.

About the Team

  • Workvivo is an employee experience platform designed to amplify workplace culture and foster employee engagement, regardless of location.
  • Committed to customer satisfaction, Workvivo focuses on enhancing employees' working lives across diverse industries globally.
  • As part of Zoom, an intelligent collaboration platform, Workvivo aligns with Zoom's mission to prioritize people, enabling meaningful connections, modern collaboration, and driving innovation in businesses and individual interactions.
  • Opportunity to make a meaningful impact on the security of both Workvivo and Zoom.
  • Contribute to our engineering security training program.
  • Collaborate cross-functionally within Zoom Security, including teams like Bug Bounty, Incident Response, SOC, Vulnerability Management, and Customer Security Assurance (CSA).

Responsibilities

  • Conducting regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software associated with the Workvivo Platform, including AWS Infrastructure and the Workvivo Application (Web App, Mobile App).
  • Discovering vulnerabilities associated with the Workvivo platform and associated infrastructure and working with Workvivo's/ZOOM's internal teams.
  • Working daily with the Security, AWS Infrastructure & Application engineering teams to ensure Security, Scalability, and Stability.
  • Prioritizing the threat modeling of new security features before they are deployed.
  • Conducting threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies, working with Application engineering (and other teams) as early as possible in the design phase.
  • Contributing to improving the SDLC such as advising on DAST, SAST, SCA, i.e., securing the Pipeline etc., and introducing code automated security solutions.
  • Contributing to improving security across Workvivo & Zoom, including feeding into the Engineering Security training program.
  • Working cross functionally within Zoom Security, e.g. Bug Bounty, Incident Response, SOC, Vulnerability Management, Customer Security Assurance (CSA) etc.
  • Introducing and coding automated security solutions.

What we’re looking for

  • Very good experience completing penetration tests (focused on Web Applications, API, and Mobile).
  • Able to critically analyze Vulnerability & Penetration test reports from external partners and customers.
  • Ability to go beyond highlighting Security Headers and low-hanging fruit as a vulnerability and critically challenge security vulnerabilities.
  • Ability to produce Architectural diagrams with a focus on the security control plane.
  • Experience in application security, software development, or related areas with a good understanding of secure coding practices and application security frameworks.
  • Good knowledge of AWS.
  • Comfort with using Burpsuite / Invicti (Netsparker) and similar tooling.
  • Proficiency in programming languages (such as PHP, Laravel, Go, Java, C++, etc.).
  • Knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption.

Skills

Vulnerability Assessment
Penetration Testing
Code Review
Security Assessments
AWS Infrastructure
Web Application Security
Mobile Application Security
Secure Coding Practices
Security Guidance
Bug Bounty
Incident Response
Vulnerability Management

Zoom

Video conferencing and online meeting solutions

About Zoom

Zoom provides video conferencing and online meeting solutions that allow users to conduct virtual meetings, webinars, and collaborative sessions. Its main product is video conferencing software, which enables high-quality video and audio communication, along with features like screen sharing, group messaging, and virtual backgrounds. Zoom also offers specialized products for larger events, such as Zoom Webinars and Zoom Events. The company operates on a freemium model, providing basic services for free while charging for advanced features through subscription plans tailored for various users, including businesses, educational institutions, and healthcare providers. Zoom stands out from competitors due to its user-friendly interface, reliable performance, and scalability for different needs, making it a vital tool for remote work, online education, telehealth, and social interactions.

San Jose, CaliforniaHeadquarters
2013Year Founded
$144.5MTotal Funding
IPOCompany Stage
Enterprise Software, Education, HealthcareIndustries
10,001+Employees

Benefits

Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Hybrid Work Options
Flexible Work Hours
Stock Options
Company Equity
Paid Vacation
Paid Sick Leave

Risks

Increased competition from Microsoft Teams and Google Meet threatens Zoom's market share.
Privacy concerns and regulatory scrutiny could impact Zoom's operations and reputation.
Hybrid work models may reduce demand for virtual meetings, affecting Zoom's growth.

Differentiation

Zoom offers a user-friendly interface with reliable performance for virtual meetings.
The platform supports diverse needs, including remote work, education, and telehealth.
Zoom's freemium model attracts a wide range of users with scalable subscription options.

Upsides

Zoom integrates AI tools to enhance virtual meeting effectiveness and productivity.
The expansion of 5G networks improves Zoom's video conferencing quality and accessibility.
Zoom's secure, HIPAA-compliant solutions drive demand in the telehealth sector.

Land your dream remote job 3x faster with AI