Security Engineer- Application & Cloud

Zello Inc

• $110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4-7 years of experience in security engineering or related fields.
  • Strong coding skills with experience in creating and shipping security automation.
  • Familiarity with AI applications in security contexts, particularly LLMs.
  • Proficiency in Google Cloud Platform security, experience with AWS or Azure acceptable.
  • Ability to read and analyze application code for security vulnerabilities.
  • Demonstrated experience in security scanning and CI/CD pipeline integration.
  • Excellent collaboration skills to work effectively with cross-functional teams.

Responsibilities

  • Conduct findings triage, address access queries, and manage customer security assessments.
  • Optimize AI security reviewers and make decisions on human intervention needed.
  • Establish an intake system for routing security findings to relevant teams.
  • Lead cloud hardening projects focusing on IAM and workload configurations.
  • Implement code scanning and supply chain controls in GitHub and CI/CD.
  • Review code related to authorization and security, ensuring necessary fixes are made.
  • Create documentation for security processes to empower team members to operate independently.

Benefits

  • Competitive pay and equity with significant upside potential.
  • Flexible work schedules and ample time off.
  • Sabbatical offered after every five years of service.
  • Supportive work environment with amenities like a ping-pong table and free snacks.
Full Job Description
IMPORTANT: Please be aware, scammers may try to impersonate Zello by reaching out regarding job opportunities. We will never ask you for bank account information, checks, or other sensitive information as part of our hiring process. All correspondence will come from the zello.com email domain. If you're unsure, please email [redacted] with questions.

After a successful first year, you will
  • Have completed Zello's Google Cloud hardening project, including the long-standing items that had been open for more than six months.
  • Have set the direction for and shipped supply chain security: SCA, SAST, and secrets scanning running in CI across our primary repos and blocking on High/Critical findings, plus package inventory and malicious-package scanning.
  • Have launched a vulnerability triage pipeline within six months that deduplicates, scores, and routes findings to owning teams, and auto-triages at least half of incoming findings by month twelve.
  • Have helped turn the vulnerability backlog net-negative and brought High/Critical findings open past SLA to zero, with the AI security agent tuned so its findings arrive already triaged.
What you'll do
  • Take your turn on interrupt duty (findings triage, access questions, incidents, and customer security assessments), then swap to protected build time.
  • Tune the AI security reviewer and triage agents, and decide which calls stay with a human owner.
  • Build the intake pipeline that routes findings from the AI reviewer, bug bounty, pen tests, and audits to the teams that own the code, with SLA clocks per severity.
  • Lead the Google Cloud hardening project across IAM, org policy, and workload configuration.
  • Choose and roll out code scanning and supply chain controls in GitHub and CI/CD, and make sure engineers can act on what the scanners find.
  • Review code and designs that touch authorization, identity, and tenancy, and push fixes through Platform, Web, and Backend teams.
  • Write the runbooks and requirements that let anyone on the team run a security process without you.
Who you are
  • You've built and shipped security automation in code, and you can walk us through something you wrote that still runs in production.
  • You've applied LLMs or agents to real security work, and you have opinions about where AI output needs a human owner.
  • You can read application code and spot an exploitable authorization, identity, or secrets flaw, then explain it to the team that has to fix it.
  • You've rolled out security scanning in CI and turned the results into fixes, not just dashboards.
  • You've secured IAM and workloads in a major cloud. GCP is ideal; AWS or Azure is fine.
  • You get fixes shipped by teams you don't manage, and engineers describe working with you as straightforward.
  • You learn fast and go broad. You're comfortable moving between incident mode and build mode in the same week.
This Role Is Not
  • A people management role or the first step toward building a large security team.
  • A GRC or compliance role. Governance and audit programs sit with our CISO.
  • A 24/7 SOC role. Off-hours infrastructure monitoring stays with our MDR partner.
  • An IT helpdesk role. Day-to-day SaaS provisioning belongs to Ops.

We hire for potential, passion for our mission, and a knack for solving difficult problems over checking every qualification box. We have competitive pay, equity with significant upside, and intentionally design our benefits to encourage healthy and well-balanced employees, flexible schedules and time off. We even offer a sabbatical after every five years of service so you're able to pursue and enjoy what matters most to you. And of course, we wouldn't be a technology company without a ping-pong table and free snacks in our break room. Join us!

Similar Jobs

More Jobs at Zello Inc

More Information Technology Jobs

Find similar Security Engineer- Application & Cloud jobs: