> Markdown version of [/jobs/ext/539574-security-engineer](https://www.wearedevelopers.com/jobs/ext/539574-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Zoom Video Communications, Inc. - **Location:** Phoenix, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $98,900.0 - $228,700.0 - **Contract:** Permanent contract - **Skills:** Testing (Software), Java (Programming Language), Amazon Web Services, Amazon S3, Application Layers, User Authentication, Burp Suite, Mobile Application Development, Cloud Computing, Code Review, Cyber Security, Database Security, DevOps, Distributed Systems, Web Servers, Identity and Access Management, Information Sciences, Python (Programming Language), Network Segmentation, Open Web Application Security, Systems Development Life Cycle, Cloud Services, Secure Coding, Web Applications, Web Services, Software Security, Information Technology, CIS Benchmarks, Programming Languages - **Published:** June 14, 2026 - **Apply:** https://www.juju.com/job/00000000g7wtsx ## About the Role + Have obtained a Bachelor's degree in Computer Science, Information Science, Cyber Security, Computer or Electrical Engineering (or similar field), and 5+ years in security. + Have extensive experience in security testing in various environments, including assessing the security posture of web applications, native applications, distributed systems, and cloud infrastructure such as AWS. Focus on securing web services, infrastructure, deployment, and platform core services. + Possess a solid understanding of software security architecture, design, threat modeling, secure code review, cryptography, and the SDLC. Ability to clearly communicate best practices and effective mitigations for application security, particularly SDLC exceptions. + Have hands on security experience working with AWS and common service components within AWS. Ability to identify security gaps in the overall design as well as configuration issues in individual components. + Have in-depth knowledge of network based, system level, and application layer attacks and mitigation methods. + Have good knowledge of technology and security topics including network and application security (Owasp), infrastructure hardening, security baselines, web server, database security and applied cryptography. + Have good development experience in one or more of the programming languages and platforms such as Java is required. ## Description The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you'll collaborate with engineering teams to design, implement, and validate secure solutions. You'll serve as a trusted security advisor, guiding architecture and reviewing implementation, particularly for new features or security enhancements. This is a unique opportunity to work with cutting-edge cloud and security technologies while making a direct impact on Zoom's platform. About the Team The Security Architecture team is dedicated to ensuring Zoom releases and deploys secure products. We work with diverse engineering, compliance and DevOps teams across the organization to meet security goals and maintain compliance with established SLAs. Responsibilities + Being a security subject-matter expert, guide engineering teams in end-to-end secure system design and implementation. + Conducting threat modeling, architecture review, security code review, security assessment, and security testing (web application, native application, web services, cloud-based services, and infrastructure assessments). + Performing cloud infrastructure reviews from a security perspective; the primary focus will be on AWS permissions and configuration issues within components like IAM and S3. + Performing an in-depth security review of new Zoom features and functionalities. This includes identifying security vulnerabilities such as those in the Owasp Top Ten, common issues from the NVD, and risks like RCE. It also involves reviewing Java or Python code and verifying security posture through manual and automated testing using tools like Burp Suite and Coverity. + Identifying gaps in existing cloud security architecture design/configuration, recommend changes or enhancements (authentication, authorization, network segmentation, container configuration, bastion host setup, etc.). + Providing hands on security training and secure coding best practices to engineering teams. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Hate organising your photos? Try it with 5 Terabytes](https://www.wearedevelopers.com/videos/79-hate-organising-your-photos-try-it-with-5-terabytes) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)