Zoom

Vulnerability Management Security Engineer

United Kingdom

Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Software, SaaS, Employee Experience, Collaboration ToolsIndustries

Employment Type

Full time

Senior Security Engineer (Vulnerability Management) - Workvivo

What You Can Expect

We’re looking for a vulnerability management engineer to strengthen our vulnerability lifecycle for the Workvivo SaaS platform. You’ll triage and drive remediation of technical vulnerabilities, with a focus on risk, prioritization, and working closely with developers. You’ll partner with engineering and DevOps to make sure security issues are not just found, but fixed.

This isn’t a red teaming role, or end point remediation, rather, the focus is application security vulnerabilities, i.e, the Workvivo employee experience SaaS platform. You'll work closely with red-teamers (both internal and external) in addition to bug bounty researchers to turn their insights into action. The focus is on visibility, clear priorities, and delivering fixes — together with engineering.

About the Team

Workvivo is an employee experience platform designed to amplify workplace culture and foster employee engagement, regardless of location. Committed to customer satisfaction, Workvivo focuses on enhancing employees' working lives across diverse industries globally. As part of Zoom, an intelligent collaboration platform. Workvivo aligns with Zoom's mission to prioritize people, enabling meaningful connections, modern collaboration, and driving innovation in businesses and individual interactions.

In this position, you’ll have the opportunity to make a meaningful impact on the security of both Workvivo and Zoom.

Responsibilities

  • Managing vulnerability intake and triage by serving as a central point for reports from internal offensive security teams, external researchers, bug bounty platforms, and automated scanning tools.
  • Removing noise and prioritizing based on risk and business context.
  • Collaborating with offensive security and engineering teams to validate findings, align on risk prioritization, and ensure attack simulations translate into meaningful, real-world fixes.
  • Translating offensive security insights into actionable remediation plans across development and infrastructure teams to drive secure practices.
  • Coordinating and tracking remediation efforts across engineering teams, providing context, defining realistic timelines, and reporting on risk posture through dashboards and SLA metrics.
  • Partnering with development teams to interpret findings, reduce false positives, and recommend remediations that fit naturally into existing workflows.

What We're Looking For

  • 5+ years of experience in application vulnerability management within SaaS or cloud-first environments.
  • Experience presenting overall vulnerabilities to leadership.
  • Advanced communication skills and an individual who can seamlessly communicate across engineering teams.
  • Knowledge of vulnerability scoring frameworks and sources, including CVSS, CVE, and CWE. An ability to understand and apply Zoom's Vulnerability Impact Scoring System (VISS).
  • Ability to collaborate closely with developers, aligning on fixes, integrating security into workflows, and fostering a security-first culture.
  • Experience translating complex vulnerability data into clear, prioritized remediation plans for technical and non-technical stakeholders.
  • Solid understanding of secure development principles, CI/CD pipelines, and the software development lifecycle (SDLC).
  • Comfortable working with offensive security teams, using attack simulations and red team insights to drive defensive improvements.
  • Risk-based mindset, with a focus on reducing actual risk over merely detecting and reporting vulnerabilities.

Ways of Working

Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

Benefits

As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options.

Skills

Vulnerability Management
Security Engineering
Application Security
Risk Assessment
Prioritization
Collaboration
Bug Bounty Platforms
Automated Scanning Tools
Attack Simulations
SaaS Security

Zoom

Video conferencing and online meeting solutions

About Zoom

Zoom provides video conferencing and online meeting solutions that allow users to conduct virtual meetings, webinars, and collaborative sessions. Its main product is video conferencing software, which enables high-quality video and audio communication, along with features like screen sharing, group messaging, and virtual backgrounds. Zoom also offers specialized products for larger events, such as Zoom Webinars and Zoom Events. The company operates on a freemium model, providing basic services for free while charging for advanced features through subscription plans tailored for various users, including businesses, educational institutions, and healthcare providers. Zoom stands out from competitors due to its user-friendly interface, reliable performance, and scalability for different needs, making it a vital tool for remote work, online education, telehealth, and social interactions.

San Jose, CaliforniaHeadquarters
2013Year Founded
$144.5MTotal Funding
IPOCompany Stage
Enterprise Software, Education, HealthcareIndustries
10,001+Employees

Benefits

Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Hybrid Work Options
Flexible Work Hours
Stock Options
Company Equity
Paid Vacation
Paid Sick Leave

Risks

Increased competition from Microsoft Teams and Google Meet threatens Zoom's market share.
Privacy concerns and regulatory scrutiny could impact Zoom's operations and reputation.
Hybrid work models may reduce demand for virtual meetings, affecting Zoom's growth.

Differentiation

Zoom offers a user-friendly interface with reliable performance for virtual meetings.
The platform supports diverse needs, including remote work, education, and telehealth.
Zoom's freemium model attracts a wide range of users with scalable subscription options.

Upsides

Zoom integrates AI tools to enhance virtual meeting effectiveness and productivity.
The expansion of 5G networks improves Zoom's video conferencing quality and accessibility.
Zoom's secure, HIPAA-compliant solutions drive demand in the telehealth sector.

Land your dream remote job 3x faster with AI