Principal Application Security Engineer
Remote
Full Time
#Engineering
#Application Security
#Cyber Security
#Python
#Go
#PHP
#JavaScript
#Ruby
#Pen Testing
#AWS
#GCP
#Shell Scripting
#SDLC
At Vimeo, we provide the world's most innovative video experience platform. We empower everyone from creative storytellers to large global enterprises to produce high-quality video content that brings ideas to life. With millions of users and billions of monthly views, we are dedicated to building a platform that connects people through the power of video. We are currently looking for a talented individual to join our team and help us maintain the trust our users place in us every single day.
What is this role?
We are seeking a Principal Application Security Engineer to join our team on a full-time, remote basis. This is a senior-level position that requires at least seven years of relevant experience in engineering or security. While this role is remote, you will need to be available for three hours of daily overlap with the US Eastern time zone to collaborate effectively with our New York-based headquarters and global teams.
What will you do?
- Lead security initiatives by planning and executing strategies to protect our systems and sensitive user data from cyber threats and infiltration.
- Collaborate across departments by working closely with product managers, developers, and infrastructure teams to perform threat modeling, conduct code reviews, and guide the implementation of secure design practices.
- Drive technical security solutions by developing automated tools, performing penetration testing on production or staging environments, and managing our bug bounty program to identify and remediate vulnerabilities.
What makes you a great fit?
You are a puzzle solver who thrives in a team environment. To be successful in this role, you should possess the following qualifications:
- At least 5 years of hands-on experience in software development, DevOps, or site reliability engineering, with a total of 7 years of experience in technical fields like application security.
- Strong programming proficiency in at least one of the following languages, along with the ability to read them all: Python, Go, PHP, JavaScript, or Ruby.
- Expertise in application penetration testing using tools such as Burp or Zap.
- Confidence working within cloud environments like AWS or GCP, combined with strong skills in shell scripting.
- A deep understanding of the SDLC, including tools like git, Jira, and Jenkins.
- Excellent communication skills in English, allowing you to explain complex security concepts to non-security stakeholders clearly.
What's in it for you?
We are committed to supporting our employees through a flexible work environment. Benefits for this position include:
- The ability to work remotely from anywhere.
- The opportunity to work with a diverse, global team that champions inclusion and innovation.






