Principal Application Security Engineer at Vimeo

Vimeo logo
Vimeo

Principal Application Security Engineer

Remote

Full Time

#Engineering

#Python

#Go

#PHP

#JavaScript

#Ruby

#Pen Testing

#Cloud Environments

#Shell Scripting

#SDLC

#Security Architecture

Vimeo is looking for a Principal Application Security Engineer

Sign up to unlock quick summaries and profile fit assessments

As a Principal Application Security Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our users who entrust Vimeo with their content every day.

You’ll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from infiltration and cyber-attacks.

You will likely collaborate frequently with and support developers, as well as members of the infrastructure security team, the compliance team, IT, Product, and other teams throughout the organization.

You love to solve puzzles, and are a great team player.

This role is remote. The role requires three hours of overlap with the US Eastern time zone (i.e., New York City) daily.

What you’ll do:

Depending on your preferences and the current needs of the team, you may either focus on just one or two of the following areas, or you may choose to become involved with many of them.

  • Security architecture — create a technical plan for partitioning and consolidating our cookies; draft up a sequence diagram for a new middleware to prevent IDOR attacks; implement a POC for leveraging CAPTCHA challenges in cross-origin embedded iframes; draft some code to modify the expiration behavior of our JWTs then pair with our API team to get feedback
  • Penetration testing — either hunt for security issues on our production or staged applications during an open-box internal pen test, or help coordinate an engagement with an external firm
  • Writing code for internal automated security tools — write some code, usually in Python, Bash, or Go, to support any of our team's various initiatives. Often we strive to facilitate a culture of “paved roads” for our developers, such that it is easy for any developer to incorporate security into their designs and implementations
  • Threat modeling — consider how malicious attackers may compromise our systems, and advise developers and product managers on what defenses are needed
  • Code reviews — discover weakness in our source code before it reaches production
  • Bug bounty program — help triage new incoming reports on a daily basis, plus launch creative initiatives to increase researcher engagement on our programs
  • Web Application Firewall and Rate Limiting — expand coverage and tune new rules while coordinating with developers, support team members, and the site reliability team
  • Remediation — enable and encourage developers to correctly fix recently discovered security issues in a timely manner, ultimately reducing our Mean Time To Remediate
  • Secure Software Development Lifecycle — configure automated tooling (eg. static and dynamic code analysis,, IAST) in our SDLC to detect security issues in our source code before it reaches production
  • Developer Education, Security Culture — create fun ways to spread technical security awareness throughout the engineering department
  • Incident response — lead or assist in running the various phases of an incident response, including initial detection, triage, containment, recovery, root cause analysis, retrospective, etc.
  • Collaboration with the infrastructure security team — pair with members of the infrastructure security team on various projects to secure our cloud instances and employee workstations
  • Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards
  • Process improvements — help strengthen our own internal processes and procedures
  • A typical day will look like:
    • Engage with one or more product development teams and guide them through a threat model and data flow analysis.
    • Review the code for major new functionality to ensure security best practices are followed.  
    • Review new tickets in our bug bounty program (http://hackerone.com/vimeo) and use your system design and threat modeling knowledge to reproduce, define risk and mitigating controls and propose a fix., 
    • A call or two with Development, Product Management teams to discuss security-related issues
    • Pen test a new feature in a staging environment with Burp Pro
    • Assist the compliance team on a privacy-related project
    • Provide technical advice in response to occasional questions from developers and other members of the security team

Skills and knowledge you should possess:

  • Required: 5+ years of prior experience in either software development, devops, or site reliability engineering with hands-on coding experience.
  • Preferred: prior experience in Application Security
  • 7+ total years of relevant experience in Engineering, Application Security, or a similar technical field.
  • Strong knowledge of modern web, mobile, and network security
  • Strong programming skills with at least one of the following languages, and the ability to read all of them: Python, Go, PHP, Javascript, and Ruby
  • Expertise with application pen testing, using tools like Burp or Zap
  • Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment.
  • Confident with shell scripting
  • Confident with common SDLC components, like git, Jira, Jenkins, etc
  • Confident ability to communicate technical security concepts to developers
  • At least an upper-intermediate level of English

Bonus points:

  • Link to a Github repo with security tools/scripts you’ve developed or help maintain
  • Full-stack web development experience creating RESTful applications (in any language) is a big plus
  • Open source vulnerability research or blog posts is a big plusS
  • Experience with system security hardening guidelines and SDLC principles

About Us:

Vimeo (NASDAQ: VMEO) is the world's most innovative video experience platform. We enable anyone to create high-quality video experiences to better connect and bring ideas to life. We proudly serve our community of millions of users – from creative storytellers to globally distributed teams at the world's largest companies – whose videos receive billions of views each month. Learn more at www.vimeo.com.
 
Vimeo is headquartered in New York City with offices around the world. At Vimeo, we believe our impact is greatest when our workforce of passionate, dedicated people, represents our diverse and global community. We’re proud to be an equal opportunity employer where diversity, equity, and inclusion is championed in how we build our products, develop our leaders, and strengthen our culture.
Vimeo logo

Vimeo

2 views

0 applied

Social Media

Visit Vimeo
Share this job
Copy Permalink
Open roles at Vimeo
Vimeo logo
Vimeo

Engineering Manager

il flag
Israel

On-site

Full Time

#Engineering

#GCP

#PHP

#React

#MySQL

#Redis

Vimeo logo
Vimeo

Associate Product Manager, Video Analytics

91k - 136k USD

Remote

Full Time

#Product

#Video

#Analytics

#Product Management

#Data Analytics

#User Engagement

#Communication

#Agile

Vimeo logo
Vimeo

DevOps Engineer

il flag
Israel

On-site

Full Time

#Engineering

#AWS

#GCP

#Kubernetes

#Terraform

Vimeo logo
Vimeo

Application Security Engineer III

Remote

Full Time

#Engineering

#Penetration Testing

#Python

#BASH

#Go

#Threat Modeling

#Code Reviews

#Firewall

#Software

#Incident Response

#Compliance

Discover similar jobs
P
Prolific

Application Security Lead

Remote

Full Time

#Application Security

#Engineering

#AI

#OWASP Top 10

#Code Review

#Python

#Burp suite

#SSDLC

#SAST

#DAST

#Vulnerability Management

#ISO 27001

CKSource logo
CKSource

QA Engineer

54k - 83k USD

Remote

Full Time

#QA Engineering

#Cloud Services

#Developer Tools

#JavaScript

#TypeScript

#Cypress

#Playwright

#API Testing

#Docker

#Node.Js

#AWS

#Testing

Hemitz logo
Hemitz

Full Stack Laravel Developer

Remote

Full Time

#Technology

#Web Development

#Full Stack

#PHP

#Laravel

#CodeIgniter

#VueJS

#JavaScript

#NodeJS

#REST API

E
Equilibrium

Blockchain Engineer

Remote

Contractor

#Blockchain

#Infrastructure

#Rust

#Go

#TypeScript

#Solidity

#Move

#Cairo

#Zero Knowledge Proofs

#Cryptography

#Polkadot

#Ethereum

Constructive Dialogue Institute logo
Constructive Dialogue Institute

Senior Data Scientist

us flag
United States

135k - 145k USD

Remote

Full Time

#Data Science

#Analytics Engineering

#Nonprofit

#SQL

#Python

#Data Pipelines

#AWS

#Dashboards

#Git

#Data Quality

#BI Tools

Tebra logo
Tebra

Security Architect

179k - 204k USD

Remote

Full Time

#Security

#Cloud Security

#Healthcare

#Cloudflare

#GCP

#Kubernetes

#Terraform

#Python

#DevSecOps

#Vertex AI

#BigQuery

#Helm

#Workato

O
OracomWebSolutionsLtd

Web Developer

Remote

Full Time

#Technology

#Web Development

#HTML

#CSS

#JavaScript

S
Snackpass

Software Engineer, Fullstack

Remote

Full Time

#Engineering

#Payments

#Analytics

#Tooling

#Mobile Apps

#Scalable Systems

N
NewPage Solutions Inc

Python Developer

Remote

Contractor

#Technology

#Digital Health

#Continuous Delivery

#Python

#AWS Lambda

#AWS ECS

#Automated Testing

#Agile Methodologies

#Terraform

#Drupal

#PHP

#S3

#DynamoDB

D
Deepgram

Pre-Sales Solutions Engineer

Remote

Full Time

#AI

#Solutions Engineering

#Python

#JavaScript

#API Integration

#Speech Recognition

#NLP

#Cloud Platforms

#Docker

#Kubernetes

#Sales Methodologies

Volksbyte logo
Volksbyte

DevOps Engineer

Remote

Full Time

#Technology

#DevOps

#Software Development

#Pipelines

#Linux

#Ansible

#Terraform

#Apache

#Nginx

#PHP

#Node

#PostgreSQL

U
Unit4

Senior Cloud Infrastructure Engineer

pl flag
Poland

Remote

Full Time

#Cloud Infrastructure

#Engineering

#Microsoft Azure

#Infrastructure Engineering

saas.group logo
saas.group

Applied Research Scientist

Remote

Full Time

#AI

#Research

#SQL

#Python

#Data Analysis

#Experiment Design

#Data Pipelines

#Validation

#AI Tools

#Research Methodology

Dataiku logo
Dataiku

Fullstack Software Engineer

Remote

Full Time

#Engineering

#AI

#Solutions

#Vue.Js

#React

#Angular

#Python

#fastAPI

#Flask

#RESTful API

#Data

A
Ankorstore

Lead Data Platform

Remote

Full Time

#Data Engineering

#Platform

#Data Platform

#SQL

#Python

#BigQuery

#Airflow

#DBT

#Sigma

#Amplitude

#Terraform

#Product Analytics

E
Eight Sleep

Senior Backend Engineer

Remote

Full Time

#Software Engineering

#Distributed Systems

#Java

#Kotlin

#Scala

#C#

#Python

#NodeJS

#TypeScript

#Cloud Services

H
HTTPie

Senior Fullstack Engineer

Remote

Full Time

#Developer Tools

#Engineering

#API Testing

#TypeScript

#React

#Next.js

#TailwindCSS

#Python

#Django

#AWS

#Terraform

#WebSocket

#Electron

Adthena logo
Adthena

Anti-Bot Engineer

Remote

Full Time

#Web Scraping

#Search

#Data Engineering

#Python

#Automation

#Playwright

#Selenium

#Management

#HTTP

#Docker

#Kubernetes

Hummingbird logo
Hummingbird

Senior Software Engineer, Infrastructure

Remote

Full Time

#Infrastructure Engineering

#Fintech

#Security

#AWS

#Terraform

#PostgreSQL

#Redis

#Ruby on Rails

#Python

#Docker

#CircleCi

#GraphQL

#TypeScript

Fullscript logo
Fullscript

Lead Data Scientist

Remote

Full Time

#Data Science

#Health Tech

#Causal Inference

#Python

#Statistical Modeling

#Research

#Data

#Data Analysis

#Machine Learning

Your dream job awaits.

Explore exciting opportunities, connect with top employers, and ignite your career.