Vulnerability Management Security Engineer at Zoom
Remote, Scotland, United Kingdom -
Full Time


Start Date

Immediate

Expiry Date

19 Nov, 25

Salary

0.0

Posted On

20 Aug, 25

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Good communication skills

Industry

Information Technology/IT

Description

WHAT YOU CAN EXPECT

We’re looking for a vulnerability management engineer to strengthen our vulnerability lifecycle for the Workvivo SaaS platform. You’ll triage and drive remediation of technical vulnerabilities, with a focus on risk, prioritization, and working closely with developers. You’ll partner with engineering and DevOps to make sure security issues are not just found, but fixed.
This isn’t a red teaming role, or end point remediation, rather, the focus is application security vulnerabilities, i.e, the Workvivo employee experience SaaS platform. You’ll work closely with red-teamers (both internal and external) in addition to bug bounty researchers to turn their insights into action. The focus is on visibility, clear priorities, and delivering fixes — together with engineering.

WAYS OF WORKING

Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

ABOUT US

Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars.
We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment.

How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities
  • Managing vulnerability intake and triage by serving as a central point for reports from internal offensive security teams, external researchers, bug bounty platforms, and automated scanning tools. Removing noise and prioritizing based on risk and business context.
  • Collaborating with offensive security and engineering teams to validate findings, align on risk prioritization, and ensure attack simulations translate into meaningful, real-world fixes.
  • Translating offensive security insights into actionable remediation plans across development and infrastructure teams to drive secure practices.
  • Coordinating and tracking remediation efforts across engineering teams, providing context, defining realistic timelines, and reporting on risk posture through dashboards and SLA metrics.
  • Partnering with development teams to interpret findings, reduce false positives, and recommend remediations that fit naturally into existing workflows.
Loading...