Principal Engineer, Security Operations

1 Month ago • 4 Years +

Job Summary

Job Description

As a Principal Engineer, Security Operations at Vimeo, you will lead and implement security strategies to protect over 300 million users and their content. This includes identifying vulnerabilities, implementing security best practices, and automating security processes. You will also participate in incident response, conduct investigations, and collaborate with various teams. The ideal candidate should possess strong security knowledge, problem-solving skills, and excellent communication abilities. This remote role requires overlap with US (EST) business hours.
Must have:
  • 4+ years of experience in a security or operations role.
  • 2+ years experience with container and container orchestration systems
  • Strong knowledge of security best practices and industry standards.
  • Excellent problem-solving and communication skills.
Good to have:
  • Familiarity with common security tools and technologies.
  • Experience implementing zero trust network access.
  • Experience implementing identity lifecycle.
  • Experience with Crowdstrike and Wiz.
  • Experience with system security hardening guidelines and SDLC principles.

Job Details

Principal Engineer, Security Operations

The Principal Engineer, Security Operations at Vimeo will play a pivotal role in leading and implementing security strategies and initiatives designed to protect our vast user base of over 300 million users and their valuable content. This role requires close collaboration with multiple teams across the organization, including Development, DevOps, Infrastructure Security, Compliance, IT, and Product, to ensure a holistic and effective security posture.

You will be at the forefront of safeguarding sensitive user data and critical systems from a constantly evolving threat landscape. This includes proactively identifying and addressing vulnerabilities, implementing industry-standard security best practices, and driving the automation of security processes to enhance efficiency and scalability. Additionally, you will participate in incident response activities, conducting thorough investigations and implementing corrective actions to minimize the impact of security breaches.

The ideal candidate for this position is a highly motivated and skilled security professional with a proven ability to solve complex problems and work effectively in a team environment. You should have a strong understanding of security principles and technologies, as well as a passion for staying ahead of emerging threats. Excellent communication and interpersonal skills are also essential, as you will need to clearly articulate security risks and recommendations to both technical and non-technical stakeholders.

This role is remote and should be expected to overlap with US (EST) Business hours.. 

What you'll do: 

Incident Response

  • Act as the primary point of contact for security incidents detected by the MDR solution.
  • Analyze and triage alerts generated by the MDR platform, prioritizing based on severity and potential impact.
  • Coordinate and manage the incident response process, working closely with the MDR provider and internal teams.
  • Escalate incidents to appropriate internal teams or external parties as needed, following established procedures.
  • Develop and maintain incident response playbooks specific to MDR-related incidents.
  • Track and report on incident response metrics, including detection time, containment time, and resolution time.
  • Collaborate with the MDR provider to optimize detection rules and improve the overall effectiveness of the solution.

Security Engineering 

  • Conduct security assessments of our systems and infrastructure to identify vulnerabilities and risks, identify risk owners and implement mitigating controls. 
  • Implement and maintain security controls, including access controls, Zero trust network access (ZTNA), network segmentation, and security monitoring tools. 
  • Design and operate identity management, lifecycle, governance and SSO.
  • Implement and operate cloud security hardening and cloud security posture management across Google cloud and AWS. 
  • Develop and maintain security policies and procedures, and ensure compliance with industry and regulatory standards. 
  • Collaborate with SRE, AppSec and Information technology around vulnerability management, endpoint hardening, detection and response. 
  • Participate in incident response activities, including investigating security incidents and responding to security alerts. 
  • Collaborate with development and DevOps teams to implement security best practices throughout the software development and infrastructure lifecycle. 
  • Automate security processes using scripting and other automation tools.
  • Stay up-to-date with the latest security threats, vulnerabilities, and technologies. 
  • Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards 
  • Process improvements — help strengthen our own internal processes and procedures.

Skills and knowledge you should possess: 

  • 4+ years of experience in a security or operations role, preferably in a cloud-based Linux environment. 
  • 2+ years experience with container and container orchestration systems
  • Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience. 
  • Strong knowledge of security best practices and industry standards, such as NIST, CIS, and ISO. 
  • Relevant certifications such as CISSP, CCSP, GCP, or AWS Certified Security Specialty are a plus. 
  • Experience with security tools such as IDS/IPS, SIEM, vulnerability scanners, and endpoint protection. 
  • Experience with automation tools such as Terraform, Ansible, or Chef. 
  • Strong scripting skills using Python, shell, or other scripting languages. 
  • Excellent problem-solving skills and the ability to work well under pressure. 
  • Good communication and interpersonal skills.Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment. Confident with common SDLC components, like git, Jira, Jenkins, etc ● At least an upper-intermediate level of English 

Bonus points (nice skills to have, but not needed): 

  • Familiarity with common security tools and technologies, such as SIEM, EDR, and threat intelligence platforms.

Experience implementing zero trust network access such as Z-Scaler, Warp, Google beyondCorp etc. Experience implementing identity lifecycle including provisioning, quarterly access reviews, role management and deprovisioning. Understanding of FIDO2 and machine certificate authentication flowsExperience with Crowdstrike and WizExperience with system security hardening guidelines and SDLC principlesExperience with implementing Fedramp and/or HIPAA.

 
 

 

About Us:

Vimeo (NASDAQ: VMEO) is the world's most innovative video experience platform. We enable anyone to create high-quality video experiences to better connect and bring ideas to life. We proudly serve our community of millions of users – from creative storytellers to globally distributed teams at the world's largest companies – whose videos receive billions of views each month. Learn more at www.vimeo.com.
 
Vimeo is headquartered in New York City with offices around the world. At Vimeo, we believe our impact is greatest when our workforce of passionate, dedicated people, represents our diverse and global community. We’re proud to be an equal opportunity employer where diversity, equity, and inclusion is championed in how we build our products, develop our leaders, and strengthen our culture.

Similar Jobs

Opendoor - Staff SWE

Opendoor

San Francisco, California, United States (On-Site)
1 Week ago
appier - Software Engineer, Site Reliability Engineering

appier

Tokyo, Japan (On-Site)
2 Weeks ago
anavatio  - Cybersecurity Analyst

anavatio

Clarksburg, West Virginia, United States (On-Site)
2 Months ago
N-ix - Senior Cybersecurity Engineer

N-ix

(Remote)
1 Month ago
Optiv - Sr. SOAR Engineer - Phantom

Optiv

Kansas City, Missouri, United States (Remote)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

People Can Fly - Live Operations Technician

People Can Fly

Montreal, Quebec, Canada (Remote)
2 Months ago
Madison Logic - Compliance Manager

Madison Logic

Pune, Maharashtra, India (Hybrid)
1 Month ago
Two Circles - Cyber Security Operations Manager

Two Circles

London, England, United Kingdom (Hybrid)
3 Weeks ago
bytedance - Site Reliability Engineer

bytedance

San Jose, California, United States (On-Site)
2 Months ago
London stock Exchange - Network Product Owner / Tech Lead – Low Latency Data Centre

London stock Exchange

London, England, United Kingdom (On-Site)
2 Weeks ago
Saviynt - Sr. Engineer, Solutions Engineering

Saviynt

United States (Remote)
7 Months ago
Opendoor - Staff Software Engineer - Application Security (SAST, DAST, IAST)

Opendoor

Kraków, Lesser Poland Voivodeship, Poland (Hybrid)
2 Weeks ago
caliogo - Salesforce Administrator

caliogo

Hyderabad, Telangana, India (On-Site)
2 Weeks ago
Crunchyroll - Staff Site Reliability Engineer - Data Engineering, Platform

Crunchyroll

San Francisco, California, United States (Remote)
6 Months ago
Saviynt - Sr. ASP .Net developer

Saviynt

El Segundo, California, United States (Hybrid)
7 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Nagarro - Senior Staff Engineer, Java Fullstack

Nagarro

India (Remote)
7 Months ago
Zscaler - Assistant Manager, Finance Transformation (FP&A)

Zscaler

Sahibzada Ajit Singh Nagar, Punjab, India (Hybrid)
2 Weeks ago
Head Digital Works - Data Scientist - Retention

Head Digital Works

Hyderabad, Telangana, India (On-Site)
10 Months ago
CME Group - Workday Tech Analyst

CME Group

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
Paytm - CST Operations - Operation Executive

Paytm

Bengaluru, Karnataka, India (On-Site)
6 Months ago
Lakshya Digital - 3D Environment Artist

Lakshya Digital

Gurugram, Haryana, India (On-Site)
1 Month ago
Accenture - Analytics and Modeling Associate

Accenture

Bengaluru, Karnataka, India (On-Site)
1 Week ago
Treelix - Staff Software Engineer

Treelix

Bengaluru, Karnataka, India (On-Site)
5 Days ago
Sporty Group - IN Associate - Payment Operations Support

Sporty Group

Mumbai, Maharashtra, India (On-Site)
6 Months ago
cyara - Senior Software Engineer - CCaaS Integration

cyara

Hyderabad, Telangana, India (Hybrid)
11 Months ago

Get notifed when new similar jobs are uploaded

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

New York, United States (On-Site)

London, England, United Kingdom (On-Site)

London, England, United Kingdom (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (Remote)

New York, United States (Remote)

New York, United States (On-Site)

Bengaluru, Karnataka, India (Remote)

New York, United States (Hybrid)

United States (On-Site)

View All Jobs

Get notified when new jobs are added by Vimeo

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug