Senior Security Engineer (Offensive Security)

Posted:
10/15/2024, 4:18:24 PM

Location(s):
Bavaria, Germany ⋅ Regensburg, Bavaria, Germany

Experience Level(s):
Senior

Field(s):
IT & Security ⋅ Software Engineering

Workplace Type:
Hybrid

Workvivo is a digital experience platform that brings workplace culture to life and empowers employees to be heard and feel included, no matter where they work. We are committed to our customers, obsessed with improving employees’ working lives, and driven by results. From automotive, technology, manufacturing, logistics, finance, and everything in between, we roll out the Workvivo platform to diverse organizations across the globe to enhance their employee experience. 

Workvivo is part of Zoom, an all-in-one intelligent collaboration platform that makes connecting easier, more immersive, and more dynamic for businesses and individuals. Zoom technology puts people at the center, enabling meaningful connections, facilitating modern collaboration, and driving human innovation.

About the role:

This role is all about breaking & hacking things. Finding the vulnerabilities in the Workvivo platform, including the Web App, Mobile App and AWS Infrastructure. Individuals should be looking at existing and new features trying to break the security posture and controls of the feature, particularly focused on escaping the Organisation Sandbox. Basically they look for all the malicious things they can do with the Platform.

Responsibility:

  • Discover vulnerabilities associated with the Workvivo Platform, including AWS Infrastructure and the Workvivo Application (Web App, Mobile App)

  • The responsibilities at the core of this role are about discovering vulnerabilities associated with the Workvivo platform and associated infrastructure

  • You will work within Workvivo’s / Zoom’s internal security team

  • Working daily with the Security, AWS Infrastructure & Application engineering teams

  • Overall the team has responsibilities for Security, Scalability and Stability. You will work within the security responsibility of the team

  • Contribute to improving the SDLC such as advising on DAST, SAST, SCA, i.e., securing the Pipeline etc.

  • Introduce and code automated security solutions

  • Contribute to improving security across Workvivo & Zoom, including feeding into the Engineering Security training program.

  • The role has scope to work cross functionally within Zoom Security, e.g. Bug Bounty, Incident Response, SOC, Vulnerability Management etc.

Key Skills:

  • Have experience in completing penetration test (focused on Web Applications, API and Mobile)

  • Have experience (and are comfortable) with coding in PHP (preferably Laravel Framework) and/or Golang and have good knowledge of AWS

  • Can go beyond highlighting Security Headers and low hanging fruit as a vulnerability

  • Are very comfortable using Burpsuite / Invicti (Netsparker) and similar tooling

  • Are able to critically analyse Vulnerability & Penetration test reports from external partners and customers

  • Are comfortable discussing the latest security technology

  • Critically challenge security vulnerabilities

Ways of Working
Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

Benefits
As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn for more information.

About Us
Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars.
We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Here, you’ll work across teams to deliver impactful projects that are changing the way people communicate and enjoy opportunities to advance your career in a diverse, inclusive environment.


Our Commitment​
We believe that the unique contributions of all Zoomies is the driver of our success. To make sure that our products and culture continue to incorporate everyone's perspectives and experience we never discriminate on the basis of race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran, or disability status. Zoom is proud to be an equal opportunity workplace and is an affirmative action employer. All your information will be kept confidential according to EEO guidelines.

We welcome people of different backgrounds, experiences, abilities and perspectives including qualified applicants with arrest and conviction records and any qualified applicants requiring reasonable accommodations in accordance with the law.

If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed.

#LI-Remote

Maven Ventures

Website: https://mavenventures.com/

Headquarter Location: Palo Alto, California, United States

Employee Count: 1-10

Year Founded: 2013

Last Funding Type: Venture - Series Unknown

Industries: Consumer Lending ⋅ Consumer Software ⋅ Financial Services ⋅ FinTech ⋅ Software ⋅ Venture Capital