Sr. Application Security Engineer

4 Months ago • 4-6 Years • Cyber Security

Job Summary

Job Description

Vimeo seeks a Sr. Application Security Engineer to safeguard user content. You'll pen-test, write security tools, and collaborate with developers, ensuring secure development practices. Strong coding skills (Python, Go, etc.) and application security expertise are essential.
Must have:
  • Application Security
  • Web Security
  • Penetration Testing
  • Coding Skills
Good to have:
  • Cloud Security
  • Threat Modeling
  • SDLC Principles
  • Full-Stack Dev
Perks:
  • Remote Work
  • Bug Bounty

Job Details

As a Sr. Application Security Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our users who entrust Vimeo with their content every day.

You’ll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from infiltration and cyber-attacks.

You will likely collaborate frequently with and support developers, as well as members of the infrastructure security team, the compliance team, IT, Product, and other teams throughout the organization.

You love to solve puzzles and are a great team player.

This role is remote.

What you’ll do:

Depending on your preferences and the current needs of the team, you may either focus on just one or two of the following areas, or you may choose to become involved with many of them.

  • Penetration testing — either hunt for security issues on our production or staged applications during an open-box internal pen test or help coordinate an engagement with an external firm
  • Writing code for internal automated security tools — write some code, usually in Python, Bash, or Go, to support any of our team's various initiatives. Often, we strive to facilitate a culture of “paved roads” for our developers, such that it is easy for any developer to incorporate security into their designs and implementations
  • Threat modeling — consider how malicious attackers may compromise our systems, and advise developers and product managers on what defenses are needed
  • Code reviews — discover weaknesses in our source code before it reaches production
  • Bug bounty program — help triage new incoming reports on a daily basis, plus launch creative initiatives to increase researcher engagement in our programs
  • Web Application Firewall and Rate Limiting — expand coverage and tune new rules while coordinating with developers, support team members, and the site reliability team
  • Remediation — enable and encourage developers to correctly fix recently discovered security issues in a timely manner, ultimately reducing our Mean Time To Remediate
  • Secure Software Development Lifecycle — configure automated tooling (eg. static and dynamic code analysis, IAST) in our SDLC to detect security issues in our source code before it reaches production
  • Developer Education, Security Culture — create fun ways to spread technical security awareness throughout the engineering department
  • Incident response — lead or assist in running the various phases of incident response, including initial detection, triage, containment, recovery, root cause analysis, retrospective, etc.
  • Collaboration with the infrastructure security team — pair with members of the infrastructure security team on various projects to secure our cloud instances and employee workstations
  • Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards
  • Process improvements — help strengthen our own internal processes and procedures
  • A typical day will look like:
    • Engage with one or more product development teams and guide them through a threat model and data flow analysis.
    • Review the code for major new functionality to ensure security best practices are followed.  
    • Review new tickets in our bug bounty program (http://hackerone.com/vimeo) and use your system design and threat modeling knowledge to reproduce, define risk and mitigating controls and propose a fix. 
    • A call or two with Development, Product Management teams to discuss security-related issues
    • Pen test a new feature in a staging environment with Burp Pro
    • Assist the compliance team on a privacy-related project
    • Provide technical advice in response to occasional questions from developers and other members of the security team

Skills and knowledge you should possess:

  • Required: 4+ years of prior experience in either software development, devops, or site reliability engineering with hands-on coding experience.
  • Preferred: prior experience in Application Security
  • 6+ total years of relevant experience in Engineering, Application Security, or a similar technical field.
  • Strong knowledge of modern web, mobile, and network security
  • Strong programming skills with at least one of the following languages, and the ability to read all of them: Python, Go, PHP, Javascript, and Ruby
  • Expertise with application pen testing, using tools like Burp or Zap
  • Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment.
  • Confident with shell scripting
  • Confident with common SDLC components, like git, Jira, Jenkins, etc
  • Confident ability to communicate technical security concepts to developers
  • At least an upper-intermediate level of English

Bonus points (nice skills to have, but not needed): 

  • Link to a Github repo with security tools/scripts you’ve developed or help maintain
  • Full-stack web development experience creating RESTful applications (in any language) is a big plus
  • Open-source vulnerability research or blog posts is a big plus
  • Experience with system security hardening guidelines and SDLC principles

Similar Jobs

Luxoft - Regular C Developer with Requirements Engineering

Luxoft

Bucharest, Bucharest, Romania (On-Site)
3 Months ago
Nagarro - Trainee

Nagarro

(On_site)
3 Months ago
Myntra - Senior Software Engineer

Myntra

Bengaluru, Karnataka, India (On-Site)
4 Months ago
ION - Senior Security Architect

ION

Collecchio, Emilia-Romagna, Italy (On-Site)
4 Months ago
OpenGov - Software Engineer III - EAM

OpenGov

Atlanta, Georgia, United States (Hybrid)
4 Months ago
ION - Platform Security Analyst

ION

Milan, Lombardy, Italy (On-Site)
4 Months ago
Dana  Inc orporated - Senior Project Engineer- Cybersecurity

Dana Inc orporated

Mulshi, Maharashtra, India (On-Site)
3 Months ago
Fortra - Professional Services Consultant - Cybersecurity

Fortra

Saudi Arabia (On-Site)
3 Months ago
Palo Alto Networks - Domain Consultant - Network Security Transformation, NGFW

Palo Alto Networks

Barcelona, Catalonia, Spain (Remote)
3 Months ago
PwC - IN_Associate_ Control Testing _Internal Audit  Services _Advisory_Chennai

PwC

Chennai, Tamil Nadu, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Clarivate - Senior Quality Assurance Engineer

Clarivate

Tamil Nadu, India (On-Site)
3 Months ago
EEE India - C++

EEE India

Bengaluru, Karnataka, India (On-Site)
5 Months ago
OKX - Senior IT Operational Risk Manager

OKX

Hong Kong (On-Site)
4 Months ago
IBM - GPSG-Senior SAP CPQ Developer: Full Stack

IBM

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Reversing Labs - Security Solutions Architect (Federal)

Reversing Labs

Washington, District Of Columbia, United States (Remote)
3 Months ago
GT - .Net Data Architect | Mercer

GT

Ukraine (Remote)
3 Months ago
InvenioLSI - SAP ABAP  Senior Associate Consultant, invenioLSI Grow

InvenioLSI

Mumbai, Maharashtra, India (On-Site)
4 Months ago
Paypal - Sr. Data Engineer

Paypal

Austin, Texas, United States (Hybrid)
4 Months ago
PwC - Salesforce Technical Lead [Level – Manager]

PwC

Gurugram, Haryana, India (On-Site)
4 Months ago
Nintendo - Manager, Software Engineering

Nintendo

Redmond, Washington, United States (Hybrid)
6 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Annalect India - Producer-Specialist

Annalect India

Bengaluru, Karnataka, India (On-Site)
4 Months ago
MAINEX ACADEMY - Genarative AI Artist

MAINEX ACADEMY

Chennai, Tamil Nadu, India (Hybrid)
5 Months ago
Luxoft - Lead Java Developer

Luxoft

New Delhi, Delhi, India (Remote)
3 Months ago
Intel Corporation - Snowflake Development Engineer

Intel Corporation

Hyderabad, Telangana, India (Hybrid)
3 Months ago
Harbinger Group - Associate QA Specialist- SDET

Harbinger Group

Pune, Maharashtra, India (Hybrid)
5 Months ago
Nisum - Account Coordinator - N5999

Nisum

Hyderabad, Telangana, India (Hybrid)
4 Months ago
AppZen - Implementation Success Manager

AppZen

Pune, Maharashtra, India (Hybrid)
4 Months ago
Saviynt - Director, Cloud Infrastructure Engineering

Saviynt

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Bazaar Voice - Senior Scrum Master

Bazaar Voice

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Eccentric - 3D Renders & Motion Artist

Eccentric

Mumbai, Maharashtra, India (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - IN- Senior Associate –   Java Developer-  Risk Analytics– Advisory – Bengaluru

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Google - Incident Response Security Consultant

Google

Kuwait City, Al Asimah Governate, Kuwait (On-Site)
3 Months ago
ION - Intermediate IT Auditor, Italy

ION

Pisa, Tuscany, Italy (On-Site)
4 Months ago
undefined - Senior Application Security Engineer

Bengaluru, Karnataka, India (On-Site)
4 Months ago
PwC - IN-Associate_IA_Internal Audit Services_Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Palo Alto Networks - Prisma Cloud Solution Architect

Palo Alto Networks

Dallas, Texas, United States (Remote)
3 Months ago
Sphere Entertainment Co - Senior Director Security

Sphere Entertainment Co

Las Vegas, Nevada, United States (On-Site)
3 Months ago
Palo Alto Networks - Systems Engineering Manager - SE Academy, India

Palo Alto Networks

Bengaluru, Karnataka, India (On_site)
3 Months ago
PwC - Enterprise systems manager

PwC

Johannesburg, Gauteng, South Africa (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

New York, New York, United States (Remote)

London, England, United Kingdom (On-Site)

New York, New York, United States (Remote)

New York, New York, United States (Remote)

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

View All Jobs

Get notified when new jobs are added by Vimeo

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug