← CarreiraAI
Indeed
Remoto
Security Engineer
Zoom · Flexible / Remote
Publicada em 02/06/2026
Candidatar-se com o CarreiraAI →
What you can expectThe Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you'll collaborate with engineering teams to design, implement, and validate secure solutions. You'll serve as a trusted security advisor, guiding architecture and reviewing implementation, particularly for new features or security enhancements. This is a unique opportunity to work with cutting-edge cloud and security technologies while making a direct impact on Zoom's platform.About the TeamThe Security Architecture team is dedicated to ensuring Zoom releases and deploys secure products. We work with diverse engineering, compliance and DevOps teams across the organization to meet security goals and maintain compliance with established SLAs.ResponsibilitiesBeing a security subject-matter expert, guide engineering teams in end-to-end secure system design and implementation.Conducting threat modeling, architecture review, security code review, security assessment, and security testing (web application, native application, web services, cloud-based services, and infrastructure assessments).Performing cloud infrastructure reviews from a security perspective; the primary focus will be on AWS permissions and configuration issues within components like IAM and S3.Performing an in-depth security review of new Zoom features and functionalities. This includes identifying security vulnerabilities such as those in the OWASP Top Ten, common issues from the NVD, and risks like RCE. It also involves reviewing Java or Python code and verifying security posture through manual and automated testing using tools like Burp Suite and Coverity.Identifying gaps in existing cloud security architecture design/configuration, recommend changes or enhancements (authentication, authorization, network segmentation, container configuration, bastion host set
Candidatar-se com o CarreiraAI →