bigshyft
VVimeo
Vimeo
Sr. Application Security Engineer
Series E
Start-up
1001-5000 employees
6y - 8y
₹18 - ₹22.5 LPA
Bengaluru/ Bangalore
Application Security, Python, AWS, DevOps, Burp Suite

Role

Company

Job Description

What you’ll do:

  • Depending on your preferences and the current needs of the team, you may either focus on just one or two of the following areas, or you may choose to become involved with many of them.
  • Penetration testing — either hunt for security issues on our production or staged applications during an open-box internal pen test or help coordinate an engagement with an external firm
  • Writing code for internal automated security tools — write some code, usually in Python, Bash, or Go, to support any of our team's various initiatives. Often, we strive to facilitate a culture of “paved roads” for our developers, such that it is easy for any developer to incorporate security into their designs and implementations
  • Threat modeling — consider how malicious attackers may compromise our systems, and advise developers and product managers on what defenses are needed
  • Code reviews — discover weaknesses in our source code before it reaches production
  • Bug bounty program — help triage new incoming reports on a daily basis, plus launch creative initiatives to increase researcher engagement in our programs
  • Web Application Firewall and Rate Limiting — expand coverage and tune new rules while coordinating with developers, support team members, and the site reliability team
  • Remediation — enable and encourage developers to correctly fix recently discovered security issues in a timely manner, ultimately reducing our Mean Time To Remediate
  • Secure Software Development Lifecycle — configure automated tooling (eg. static and dynamic code analysis, IAST) in our SDLC to detect security issues in our source code before it reaches production
  • Developer Education, Security Culture — create fun ways to spread technical security awareness throughout the engineering department
  • Incident response — lead or assist in running the various phases of incident response, including initial detection, triage, containment, recovery, root cause analysis, retrospective, etc.
  • Collaboration with the infrastructure security team — pair with members of the infrastructure security team on various projects to secure our cloud instances and employee workstations
  • Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards
  • Process improvements — help strengthen our own internal processes and procedures

What makes you a great fit:

  • 6+ total years of relevant experience in Engineering, Application Security, or a similar technical field.
  • Required: 4+ years of prior experience in either software development, devops, or site reliability engineering with hands-on coding experience.
  • Preferred: prior experience in Application Security
  • Strong knowledge of modern web, mobile, and network security
  • Strong programming skills with at least one of the following languages, and the ability to read all of them: Python, Go, PHP, Javascript, and Ruby
  • Expertise with application pen testing, using tools like Burp or Zap
  • Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment.
  • Confident with shell scripting
  • Confident with common SDLC components, like git, Jira, Jenkins, etc
  • Confident ability to communicate technical security concepts to developers
  • At least an upper-intermediate level of English
  • Link to a Github repo with security tools/scripts you’ve developed or help maintain
  • Full-stack web development experience creating RESTful applications (in any language) is a big plus
  • Open-source vulnerability research or blog posts is a big plus
  • Experience with system security hardening guidelines and SDLC principles
All about us
Vimeo

  • Vimeo is the world's most innovative video experience platform. We enable anyone to create high-quality video experiences to connect better and bring ideas to life. We proudly serve our growing community of nearly 300 million users — from creative storytellers to globally distributed teams at the world's largest companies.

Employee count
1001-5000 employees
Employment Type
Full Time Job
Company Type
Start-up
Headquarters
New York City, New York, United States

Apply to Similar Jobs

  • VVimeo
    Vimeo
    Senior Site Reliability Engineer
    Series E
    Start-up
    1001-5000 employees
    5y - 7y
    ₹15 - ₹20 LPA
    Bengaluru/ Bangalore
    Python, Linux, AWS, Algorithms, Jenkins
  • PPhonepe
    Phonepe
    Site Reliability Engineer - Azure
    Acquired
    Start-up
    5001-10
    000 employees
    5y - 8y
    ₹15 - ₹22.5 LPA
    Bengaluru/ Bangalore
    Linux, Azure, Golang, Python, MySQL