Senior Security Engineer (Vulnerability Management) - Workvivo
We're looking for a vulnerability management engineer to strengthen our vulnerability lifecycle for the Workvivo SaaS platform. You'll triage and drive remediation of technical vulnerabilities, with a focus on risk, prioritization, and working closely with developers. You'll partner with engineering and DevOps to make sure security issues are not just found, but fixed. This isn't a red teaming role, or end point remediation, rather, the focus is application security vulnerabilities, i.e, the Workvivo employee experience SaaS platform. You'll work closely with red-teamers (both internal and external) in addition to bug bounty researchers to turn their insights into action. The focus is on visibility, clear priorities, and delivering fixes — together with engineering.
Workvivo is an employee experience platform designed to amplify workplace culture and foster employee engagement, regardless of location. Committed to customer satisfaction, Workvivo focuses on enhancing employees' working lives across diverse industries globally. As part of Zoom, an intelligent collaboration platform, Workvivo aligns with Zoom's mission to prioritize people, enabling meaningful connections, modern collaboration, and driving innovation in businesses and individual interactions. In this position, you'll have the opportunity to make a meaningful impact on the security of both Workvivo and Zoom.
Responsibilities
- Managing vulnerability intake and triage by serving as a central point for reports from internal offensive security teams, external researchers, bug bounty platforms, and automated scanning tools. Removing noise and prioritizing based on risk and business context.
- Collaborating with offensive security and engineering teams to validate findings, align on risk prioritization, and ensure attack simulations translate into meaningful, real-world fixes.
- Translating offensive security insights into actionable remediation plans across development and infrastructure teams to drive secure practices.
- Coordinating and tracking remediation efforts across engineering teams, providing context, defining realistic timelines, and reporting on risk posture through dashboards and SLA metrics.
- Partnering with development teams to interpret findings, reduce false positives, and recommend remediations that fit naturally into existing workflows.
What We're Looking For
- 5+ years of experience in application vulnerability management within SaaS or cloud-first environments.
- Have experience presenting overall vulnerabilities to leadership.
- Possess advanced communication skills and an individual who can seamlessly communicate across engineering teams.
- Have knowledge of vulnerability scoring frameworks and sources, including CVSS, CVE, and CWE. An ability to understand and apply Zoom's Vulnerability Impact Scoring System (VISS).
- Have the ability to collaborate closely with developers, aligning on fixes, integrating security into workflows, and fostering a security-first culture.
- Have experience translating complex vulnerability data into clear, prioritized remediation plans for technical and non-technical stakeholders.
- Have solid understanding of secure development principles, CI/CD pipelines, and the software development lifecycle (SDLC).
- Be comfortable working with offensive security teams, using attack simulations and red team insights to drive defensive improvements.
- Have a risk-based mindset, with a focus on reducing actual risk over merely detecting and reporting vulnerabilities.
Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.