Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Vulnerability Management Security Engineer

Zoom
Greater London
3 weeks ago
Create job alert

Senior Security Engineer (Vulnerability Management) - Workvivo
 

What you can expect

We’re looking for a vulnerability management engineer to strengthen our vulnerability lifecycle for theWorkvivoSaaS platform. You’ll triage and drive remediation of technical vulnerabilities, with a focus on risk, prioritization, and working closely with developers. You’ll partner with engineering and DevOps to make sure security issues are not just found, but fixed.

This isn’t a red teaming role, or end point remediation, rather, the focus is application security vulnerabilities, , theWorkvivoemployee experience SaaS platform. You'll work closely withred-teamers(both internal and external) in addition to bug bounty researchers to turn their insights into action. The focus is on visibility, clear priorities, and delivering fixes — together with engineering.

About the Team

Workvivois an employee experience platform designed to amplify workplace culture and foster employee engagement, regardless of location. Committed to customer satisfaction,Workvivofocuses on enhancing employees' working lives across diverse industries globally. As part of Zoom, an intelligent collaboration platform.Workvivoaligns with Zoom's mission to prioritize people, enabling meaningful connections, modern collaboration, and driving innovation in businesses and individual interactions.

In this position, you’ll have the opportunity to make a meaningful impact on the security of bothWorkvivoand Zoom.

Responsibilities

Managing vulnerability intake and triage by serving as a central point for reports from internal offensive security teams, external researchers, bug bounty platforms, and automated scanning tools.Removing noise and prioritizing based on risk and business context. Collaborating with offensive security and engineering teams to validate findings, align on risk prioritization, and ensure attack simulations translate into meaningful, real-world fixes. Translating offensive security insights into actionable remediation plans across development and infrastructure teams to drive secure practices. Coordinating and tracking remediation efforts across engineering teams, providing context, defining realistic timelines, and reporting on risk posture through dashboards and SLA metrics. Partnering with development teams to interpret findings, reduce false positives, and recommendremediationsthat fit naturally into existing workflows.

What we’re looking for

Have experience presenting overall vulnerabilities to leadership. Possess advanced communication skills and an individual who can seamlessly communicate across engineering teams. Have knowledge of vulnerability scoring frameworks and sources, including CVSS, CVE, and CWE. An ability to understand and apply Zoom's Vulnerability Impact Scoring System (VISS). Have the ability to collaborate closely with developers, aligning on fixes, integrating security into workflows, and fostering a security-first culture. Have experience translating complex vulnerability data into clear, prioritized remediation plans for technical and non-technical stakeholders. Have solid understanding of secure development principles, CI/CD pipelines, and the software development lifecycle (SDLC). Be comfortable working with offensive security teams, using attack simulations and red team insights to drive defensive improvements. Have a risk-based mindset, with a focus on reducing actual risk over merely detecting and reporting vulnerabilities.

Ways of Working
Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

Benefits
As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click for more information.

About Us
Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars.
We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment.


Our Commitment​

At Zoom, we believe great work happens when people feel supported and empowered. We’re committed to fair hiring practices that ensure every candidate is evaluated based on skills, experience, and potential. If you require an accommodation during the hiring process, let us know—we’re here to support you at every step.

If you need assistance navigating the interview process due to a medical disability, please submit an and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed.

#LI-Remote

Related Jobs

View all jobs

Vulnerability Management Security Engineer

Cyber Security Engineer

Cyber Security Engineer

Security Engineer

Cyber Security Engineer

Information Security Engineer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Top 10 Skills in Cyber sScurity According to LinkedIn & Indeed Job Postings

In today’s digital age, cyber security is no longer optional—it’s mission-critical. From financial institutions to healthcare providers, government departments to tech startups, every sector in the UK is under rising cyber threats. As a result, employers are constantly on the hunt for skilled professionals who can defend, detect, and respond effectively. But with cyber threats evolving at pace, what exactly are employers seeking? By analysing job postings on LinkedIn and Indeed, this article reveals the Top 10 cyber security skills UK organisations are demanding in 2025. Read on to discover how to present these skills effectively on your CV, in interviews, and through practical proof of experience.

The Future of Cybersecurity Jobs: Careers That Don’t Exist Yet

Cyber security has become one of the most critical issues of our age. Once regarded as a technical problem confined to IT departments, it is now a board-level priority, a government mandate, and a daily necessity for individuals. The shift towards cloud services, remote working, connected devices, and artificial intelligence has dramatically increased the risks of digital attacks. In the UK, cyber security is central to national resilience. The government has identified cyber as a “tier one” threat to national security, alongside terrorism and pandemics. The private sector, from banks to retailers, now sees data breaches and ransomware as existential risks. Global spending on cyber security is projected to exceed $250 billion by 2030, with the UK already home to a thriving cyber industry employing tens of thousands. Yet, as powerful as the industry already is, we are only at the beginning. The technologies shaping the next two decades—AI, quantum computing, edge computing, extended reality, and biotechnology—will radically reshape cyber security. Many of the most vital cyber security jobs of the future don’t exist yet. This article explores why new roles will emerge, the careers likely to appear, how today’s jobs will evolve, why the UK is well-positioned, and how professionals can prepare now.

Seasonal Hiring Peaks for Cybersecurity Jobs: The Best Months to Apply & Why

The UK's cybersecurity sector has emerged as one of the most critical and lucrative technology markets, with roles spanning from security analysts to penetration testers and chief information security officers. With cybersecurity positions commanding salaries from £28,000 for junior security analysts to £140,000+ for senior security architects, understanding when organisations actively recruit can dramatically impact your career trajectory in this essential field. Unlike traditional IT sectors, cybersecurity hiring follows distinct patterns influenced by threat landscapes, regulatory compliance cycles, and incident response requirements. The sector's unique combination of perpetual threat evolution, regulatory pressures, and skills shortages creates predictable hiring windows that strategic professionals can leverage to advance their careers in protecting Britain's digital infrastructure. This comprehensive guide explores the optimal timing for cybersecurity job applications in the UK, examining how cyber threat cycles, compliance deadlines, and government initiatives influence recruitment patterns, and why strategic timing can determine whether you join a cutting-edge security consultancy or miss the opportunity to defend against tomorrow's cyber threats.