Sr. Application Security Engineer

4 Months ago • 4-6 Years • Cyber Security

Job Summary

Job Description

Vimeo seeks a Senior Application Security Engineer to protect users' content. You'll conduct pen testing, write security tools, and collaborate with development teams. Must have experience in software development, DevOps, or SRE with hands-on coding experience. Strong knowledge of web, mobile, and network security is essential.
Must have:
  • Software Development
  • DevOps or SRE
  • Web Security
  • Application Pen Testing
Good to have:
  • Full-Stack Development
  • Open-Source Research
  • System Hardening
  • SDLC Principles
Perks:
  • Remote Work
  • Collaboration Opportunities

Job Details

As a Sr. Application Security Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our users who entrust Vimeo with their content every day.

You’ll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from infiltration and cyber-attacks.

You will likely collaborate frequently with and support developers, as well as members of the infrastructure security team, the compliance team, IT, Product, and other teams throughout the organization.

You love to solve puzzles and are a great team player.

This role is remote.

What you’ll do:

Depending on your preferences and the current needs of the team, you may either focus on just one or two of the following areas, or you may choose to become involved with many of them.

  • Penetration testing — either hunt for security issues on our production or staged applications during an open-box internal pen test or help coordinate an engagement with an external firm
  • Writing code for internal automated security tools — write some code, usually in Python, Bash, or Go, to support any of our team's various initiatives. Often, we strive to facilitate a culture of “paved roads” for our developers, such that it is easy for any developer to incorporate security into their designs and implementations
  • Threat modeling — consider how malicious attackers may compromise our systems, and advise developers and product managers on what defenses are needed
  • Code reviews — discover weaknesses in our source code before it reaches production
  • Bug bounty program — help triage new incoming reports on a daily basis, plus launch creative initiatives to increase researcher engagement in our programs
  • Web Application Firewall and Rate Limiting — expand coverage and tune new rules while coordinating with developers, support team members, and the site reliability team
  • Remediation — enable and encourage developers to correctly fix recently discovered security issues in a timely manner, ultimately reducing our Mean Time To Remediate
  • Secure Software Development Lifecycle — configure automated tooling (eg. static and dynamic code analysis, IAST) in our SDLC to detect security issues in our source code before it reaches production
  • Developer Education, Security Culture — create fun ways to spread technical security awareness throughout the engineering department
  • Incident response — lead or assist in running the various phases of incident response, including initial detection, triage, containment, recovery, root cause analysis, retrospective, etc.
  • Collaboration with the infrastructure security team — pair with members of the infrastructure security team on various projects to secure our cloud instances and employee workstations
  • Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards
  • Process improvements — help strengthen our own internal processes and procedures
  • A typical day will look like:
    • Engage with one or more product development teams and guide them through a threat model and data flow analysis.
    • Review the code for major new functionality to ensure security best practices are followed.  
    • Review new tickets in our bug bounty program (http://hackerone.com/vimeo) and use your system design and threat modeling knowledge to reproduce, define risk and mitigating controls and propose a fix. 
    • A call or two with Development, Product Management teams to discuss security-related issues
    • Pen test a new feature in a staging environment with Burp Pro
    • Assist the compliance team on a privacy-related project
    • Provide technical advice in response to occasional questions from developers and other members of the security team

Skills and knowledge you should possess:

  • Required: 4+ years of prior experience in either software development, devops, or site reliability engineering with hands-on coding experience.
  • Preferred: prior experience in Application Security
  • 6+ total years of relevant experience in Engineering, Application Security, or a similar technical field.
  • Strong knowledge of modern web, mobile, and network security
  • Strong programming skills with at least one of the following languages, and the ability to read all of them: Python, Go, PHP, Javascript, and Ruby
  • Expertise with application pen testing, using tools like Burp or Zap
  • Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment.
  • Confident with shell scripting
  • Confident with common SDLC components, like git, Jira, Jenkins, etc
  • Confident ability to communicate technical security concepts to developers
  • At least an upper-intermediate level of English

Bonus points (nice skills to have, but not needed): 

  • Link to a Github repo with security tools/scripts you’ve developed or help maintain
  • Full-stack web development experience creating RESTful applications (in any language) is a big plus
  • Open-source vulnerability research or blog posts is a big plus
  • Experience with system security hardening guidelines and SDLC principles

#LI-OM1

Similar Jobs

PwC - Senior Associate_Hadoop Developer_Advisory Corporate_Advisory_Bangalore Millenia

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
HP - IT General Controls Expert – SOC Reporting

HP

Tlaquepaque, Jalisco, Mexico (On-Site)
5 Months ago
DataVisor - Senior Security Engineer

DataVisor

India (Remote)
4 Months ago
PlayStation Global - Application Security Engineer Intern - Undergraduate

PlayStation Global

Aliso Viejo, California, United States (On-Site)
4 Months ago
sigma software - Senior Machine Learning Engineer (AdTech)

sigma software

Rio De Janeiro, State Of Rio De Janeiro, Brazil (On-Site)
3 Months ago
Axinous - Senior/Staff Windows Developer

Axinous

San Jose, California, United States (On-Site)
3 Months ago
Optiv - End Game - Sr. Engineer | Onsite, Bangalore

Optiv

Bengaluru, Karnataka, India (On-Site)
7 Months ago
CloudLinux - Senior Go Developer for Imunify (worldwide remote)

CloudLinux

Vojvodina, Serbia (Remote)
3 Months ago
Gainwell Technologies - Cloud Security Engineer

Gainwell Technologies

Chennai, Tamil Nadu, India (Remote)
4 Months ago
PwC - Senior Associate IT Auditor

PwC

Zagreb, Croatia (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

HP - IT Compliance SOX ITGC Lead

HP

Tlaquepaque, Jalisco, Mexico (On-Site)
5 Months ago
KLA - Associate Technical Lead/Technical Lead, C++

KLA

Chennai, Tamil Nadu, India (On-Site)
6 Months ago
sigma software - Project Manager (AdTech)

sigma software

Warsaw, Masovian Voivodeship, Poland (On-Site)
3 Months ago
OKX - Senior IT Operational Risk Manager

OKX

Singapore, Singapore (On-Site)
4 Months ago
Google - Product Manager II, Gemini Code Assist

Google

New York, New York, United States (On-Site)
3 Months ago
GoTo Group - Lead Software Engineer (Android Flutter) - Consumer Lending

GoTo Group

Jakarta, Jakarta, Indonesia (On-Site)
4 Months ago
eBay - Software Engineer Backend (SE3)

eBay

Toronto, Ontario, Canada (Hybrid)
4 Months ago
OpenGov - Software Engineer III

OpenGov

Atlanta, Georgia, United States (On-Site)
4 Months ago
FNZ Group - Analyst Tester

FNZ Group

Gurugram, Haryana, India (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Tel Aviv-Yafo, Tel Aviv District, Israel

Playtika - Copywriter

Playtika

Israel (On-Site)
3 Months ago
PAPAYA - Senior User Acquisition Manager

PAPAYA

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
3 Months ago
seeking alpha - Senior Data Scientist

seeking alpha

Israel (On-Site)
4 Months ago
Google - Software Engineer III, Infrastructure, Google Cloud

Google

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
3 Months ago
Moon Active - Full Stack Developer

Moon Active

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
6 Months ago
SuperPlay - BUSINESS DATA ANALYST LEAD

SuperPlay

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
3 Months ago
Google - Software Engineer, CPU Performance Modeling Engineer

Google

Haifa, Haifa District, Israel (On-Site)
3 Months ago
Unity - Auctioneer Product Manager

Unity

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
4 Months ago
seeking alpha - Data Engineer

seeking alpha

Israel (On-Site)
3 Months ago
Smarsh - Implementation Technician II - Mobile Onboarding

Smarsh

Israel (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Infoblox - Senior Software Engineer - C++ AND Azure

Infoblox

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Extreme Network - Senior/Staff/Principle FIPS 140 Software Development Engineer (9264)

Extreme Network

United States (Hybrid)
4 Months ago
Marvell India - Security Vulnerability Management Professional

Marvell India

Hyderabad, Telangana, India (On-Site)
5 Months ago
PwC - Assurance- Senior Manager

PwC

Galway, County Galway, Ireland (On-Site)
4 Months ago
Anavation - Cloud Security Architect

Anavation

Fort Belvoir, Virginia, United States (On-Site)
4 Months ago
PwC - Cybersecurity Solutions Architect

PwC

Calgary, Alberta, Canada (On-Site)
4 Months ago
Balbix - Customer Success Architect - Cyber Security

Balbix

Bengaluru, Karnataka, India (On-Site)
4 Months ago
forescout - Customer Success Manager

forescout

Saudi Arabia (On-Site)
4 Months ago
Google - Technical Solutions Engineer, Security, Google Cloud

Google

Warsaw, Masovian Voivodeship, Poland (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

About The Company

New York, New York, United States (Remote)

London, England, United Kingdom (On-Site)

New York, New York, United States (Remote)

New York, New York, United States (Remote)

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

View All Jobs

Get notified when new jobs are added by Vimeo

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug