Application Security Engineer

New York, NY

Applications have closed
Vimeo, Inc. logo
Vimeo, Inc.

Posted 1 month ago

As an Application Security Engineer on our Security Engineering team, you will support our cloud infrastructure by developing tools, building services and providing consultative services to our engineering teams. You will be a key member safeguarding our creators who entrust Vimeo with their content every day. You will build tools, and services (We use Python, and Go). You’ll plan and carry out security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks. You love to solve puzzles, and are a great team player

What you’ll do:

  • Contribute to the infrastructure, application and security teams at Vimeo
  • Create services, tools and process to manage the security of our applications
  • Perform regular security assessments of Vimeo’s platforms and software  
  • Identify and remediate weaknesses in our processes and procedures
  • Configure systems to comply with industry best practices and hardening standards
  • Prioritize, triage and remediate vulnerabilities and findings from system scans and bug bounty programs

Skills and knowledge you should possess:

  • Solid understanding of OSI model, TCP/IP, HTTP and TLS
  • Understands the principle of least privilege and the confidentiality, integrity, and availability triad and will work to enforce those concepts in our environment
  • Experience with web application penetration testing
  • Experience with languages such as Python, Go, Ruby, PHP, Node.js
  • Experience with secure coding practices and automating security checks in pipelines 
  • Comfortable working in and across cloud environments like AWS and GCP
  • Comfortable with DevOps style tools like Ansible, Chef, Terraform, GitHub, Jenkins, Puppet, etc.

Bonus points:

  • Link to a Github repo with security tools/scripts you’ve developed or help maintain
  • Web development experience or open source vulnerability research
  • Experience with system security hardening guidelines and SDLC principles


About us:

Vimeo is the world’s leading professional video platform and community. With over 175 million members across more than 150 countries, we help anyone grow their business by making it easy to create and market high-quality, impactful videos.

We work hard to enable creators of all kinds to succeed, and to that end, we prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and creativity. We’re committed to building a company and a community where people thrive by being themselves and are inspired to do their best work every day.

Vimeo is headquartered in New York City with offices around the world, and is an operating business of IAC. Learn more at www.vimeo.com.

 

Job tags: AWS DevOps Go Node.js Open Source Penetration testing PHP Puppet Python Ruby Security assessments TCP/IP TLS Vulnerabilities