Vulnerability Management Security Engineer
Vulnerability Management Security Engineer

Vulnerability Management Security Engineer

London Full-Time 36000 - 60000 £ / year (est.) No home office possible
Z

At a Glance

  • Tasks: Join us as a Vulnerability Management Engineer to enhance security for our SaaS platform.
  • Company: Workvivo, part of Zoom, focuses on improving workplace culture and employee engagement globally.
  • Benefits: Enjoy a hybrid work model, wellness perks, and a supportive workplace culture.
  • Why this job: Make a real impact on security while collaborating with innovative teams in a dynamic environment.
  • Qualifications: 3+ years in vulnerability management or DevSecOps; strong knowledge of security tools and practices required.
  • Other info: We value diversity and are committed to creating an inclusive workplace for all.

The predicted salary is between 36000 - 60000 £ per year.

We’re looking for a Vulnerability Management Engineer to strengthen our vulnerability lifecycle for the Workvivo SaaS platform. You’ll triage and drive remediation of technical vulnerabilities, with a focus on risk, prioritization, and working closely with developers. You’ll partner with engineering and DevOps to make sure security issues are not just found, but fixed. This isn’t a red teaming role, but you’ll work closely with red teamers and bug bounty researchers to turn their insights into action. The focus is on visibility, clear priorities, and delivering fixes — together with engineering.

About the Team

Workvivo is an employee experience platform designed to amplify workplace culture and foster employee engagement, regardless of location. Committed to customer satisfaction, Workvivo focuses on enhancing employees' working lives across diverse industries globally. As part of Zoom, an intelligent collaboration platform, Workvivo aligns with Zoom's mission to prioritise people, enabling meaningful connections, modern collaboration, and driving innovation in businesses and individual interactions. In this position, you’ll have the opportunity to make a meaningful impact on the security of both Workvivo and Zoom.

Responsibilities

  • Managing vulnerability intake and triage by serving as a central point for reports from internal offensive security teams, external researchers, bug bounty platforms, and automated scanning tools. Removing noise and prioritising based on risk and business context.
  • Collaborating with offensive security and engineering teams to validate findings, align on risk prioritisation, and ensure attack simulations translate into meaningful, real-world fixes.
  • Translating offensive security insights into actionable remediation plans across development and infrastructure teams to drive secure practices.
  • Coordinating and tracking remediation efforts across engineering teams, providing context, defining realistic timelines, and reporting on risk posture through dashboards and SLA metrics.
  • Partnering with development teams to interpret findings, reduce false positives, and recommend remediation that fit naturally into existing workflows.
  • Operating and fine-tuning vulnerability scanning tools (e.g., SCA, SAST, DAST) across cloud infrastructure, containers, and endpoints to ensure coverage and accuracy.
  • Managing and integrating AppSec tooling into CI/CD pipelines, including SCA (e.g., Snyk, Dependabot), SAST (e.g., GitHub Advanced Security, SonarQube), and DAST (e.g., OWASP ZAP, Burp Suite Pro).
  • Improving automation and secure-by-default practices to shift security detection and resolution earlier in the development lifecycle.

What we’re looking for

  • 3+ years of experience in vulnerability management, application security, or DevSecOps within SaaS or cloud-first environments.
  • Knowledge of vulnerability scoring frameworks and sources, including CVSS, CVE, CWE, and OWASP Top 10.
  • Proficiency with security scanning tools for both infrastructure and application layers, with hands-on experience driving remediation alongside engineering teams.
  • Solid understanding of secure development principles, CI/CD pipelines, and the software development lifecycle (SDLC).
  • Ability to collaborate closely with developers, aligning on fixes, integrating security into workflows, and fostering a security-first culture.
  • Experience translating complex vulnerability data into clear, prioritised remediation plans for technical and non-technical stakeholders.
  • Comfortable working with offensive security teams, using attack simulations and red team insights to drive defensive improvements.
  • A risk-based mindset, with a focus on reducing actual risk over merely detecting and reporting vulnerabilities.

Ways of Working

Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

Benefits

As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways.

About Us

Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Here, you’ll work across teams to deliver impactful projects that are changing the way people communicate and enjoy opportunities to advance your career in a diverse, inclusive environment.

Our Commitment

We believe that the unique contributions of all Zoomies is the driver of our success. To make sure that our products and culture continue to incorporate everyone's perspectives and experience we never discriminate on the basis of race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran, or disability status. Zoom is proud to be an equal opportunity workplace and is an affirmative action employer. All your information will be kept confidential according to EEO guidelines. We welcome people of different backgrounds, experiences, abilities and perspectives including qualified applicants with arrest and conviction records and any qualified applicants requiring reasonable accommodations in accordance with the law. If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed.

Vulnerability Management Security Engineer employer: Zoom

At Workvivo, we pride ourselves on being an exceptional employer, offering a vibrant work culture that prioritises employee engagement and well-being. Our commitment to professional growth is evident through diverse career advancement opportunities, while our hybrid working model ensures flexibility and work-life balance. As part of the Zoom family, you will be at the forefront of innovation, collaborating with talented teams to make a meaningful impact in the realm of security within a supportive and inclusive environment.
Z

Contact Detail:

Zoom Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Vulnerability Management Security Engineer

✨Tip Number 1

Familiarise yourself with the specific vulnerability management tools mentioned in the job description, such as Snyk, OWASP ZAP, and Burp Suite Pro. Having hands-on experience with these tools will not only boost your confidence but also demonstrate your technical proficiency during discussions.

✨Tip Number 2

Network with professionals in the security field, especially those who work in vulnerability management or DevSecOps. Engaging with them on platforms like LinkedIn can provide you with insights into the role and may even lead to referrals.

✨Tip Number 3

Prepare to discuss real-world scenarios where you've successfully triaged vulnerabilities and collaborated with development teams. Being able to share specific examples will highlight your problem-solving skills and your ability to work cross-functionally.

✨Tip Number 4

Stay updated on the latest trends and threats in cybersecurity, particularly those related to SaaS environments. This knowledge will help you engage in meaningful conversations during interviews and show that you're proactive about your professional development.

We think you need these skills to ace Vulnerability Management Security Engineer

Vulnerability Management
Application Security
DevSecOps
Risk Assessment
Collaboration with Development Teams
Security Scanning Tools (SCA, SAST, DAST)
CI/CD Pipeline Integration
Secure Development Principles
Vulnerability Scoring Frameworks (CVSS, CVE, CWE, OWASP Top 10)
Remediation Planning
Communication Skills
Analytical Skills
Problem-Solving Skills
Understanding of Software Development Lifecycle (SDLC)
Experience with Offensive Security Teams

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in vulnerability management, application security, and DevSecOps. Use keywords from the job description to demonstrate that you meet the specific requirements.

Craft a Strong Cover Letter: In your cover letter, explain why you're passionate about vulnerability management and how your skills align with Workvivo's mission. Mention your experience collaborating with developers and translating security insights into actionable plans.

Showcase Technical Skills: Detail your proficiency with security scanning tools and frameworks like CVSS, CVE, and OWASP Top 10. Provide examples of how you've used these tools to drive remediation efforts in previous roles.

Highlight Collaboration Experience: Emphasise your ability to work closely with engineering and offensive security teams. Share specific instances where you successfully aligned on risk prioritisation and implemented security practices within development workflows.

How to prepare for a job interview at Zoom

✨Understand the Vulnerability Lifecycle

Make sure you have a solid grasp of the vulnerability lifecycle, especially how it applies to SaaS platforms. Be prepared to discuss how you would triage vulnerabilities and prioritise them based on risk and business context.

✨Familiarise Yourself with Security Tools

Brush up on your knowledge of security scanning tools like SCA, SAST, and DAST. Be ready to explain how you've used these tools in past roles and how they can be integrated into CI/CD pipelines.

✨Collaborate with Developers

Highlight your experience working closely with development teams. Discuss how you’ve successfully translated complex vulnerability data into actionable remediation plans that fit naturally into existing workflows.

✨Showcase Your Risk-Based Mindset

Demonstrate your understanding of risk management in vulnerability management. Be prepared to talk about how you focus on reducing actual risk rather than just detecting vulnerabilities, and provide examples from your previous work.

Vulnerability Management Security Engineer
Zoom
Z
  • Vulnerability Management Security Engineer

    London
    Full-Time
    36000 - 60000 £ / year (est.)

    Application deadline: 2027-04-23

  • Z

    Zoom

Similar positions in other companies
Europas größte Jobbörse für Gen-Z
discover-jobs-cta
Discover now
>