FreshRemote.Work

Principal Security Operations Engineer

US-Remote

As a Principal Security Operations Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our 300+ million users who entrust Vimeo with their content every day.

You’ll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from infiltration and cyber-attacks.

You will likely collaborate frequently with and support developers, as well as members of the infrastructure security team, the compliance team, IT, Product, and other teams throughout the organization.

You love to solve puzzles, and are a great team player.

This role is remote.

What you'll do:

Depending on your preferences and the current needs of the team, you may either focus on just some of the following areas, or you may choose to become involved with all of them.

  • As a Principal SecOps Engineer, you will be responsible for ensuring the security of our systems and infrastructure. You will work closely with our development, DevOps teams to identify and remediate vulnerabilities, implement security best practices, and automate security processes. You will also monitor and respond to security incidents and maintain compliance with industry and regulatory standards.
  • Conduct security assessments of our systems and infrastructure to identify vulnerabilities and risks, identify risk owners and implement mitigating controls.
  • Implement and maintain security controls, including access controls, Zero trust network access (ZTNA), network segmentation, and security monitoring tools.
  • Design and operate identity management, lifecycle, governance and SSO.
  • Implement and operate cloud security hardening and cloud security posture management across Google cloud and AWS.
  • Develop and maintain security policies and procedures, and ensure compliance with industry and regulatory standards.
  • Collaborate with SRE, AppSec and Information technology around vulnerability management, endpoint hardening, detection and response.
  • Participate in incident response activities, including investigating security incidents and responding to security alerts.
  • Collaborate with development and DevOps teams to implement security best practices throughout the software development and infrastructure lifecycle.
  • Automate security processes using scripting and other automation tools.
  • Stay up-to-date with the latest security threats, vulnerabilities, and technologies.
  • Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards
  • Process improvements — help strengthen our own internal processes and procedures

Skills and knowledge you should possess:

This job isn't fresh anymore!
Search Fresh Jobs