This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Security team at Zip is responsible for protecting the confidentiality and integrity of our customers’ data. As our first Application Security Engineer, you will take on a dynamic and high impact role. You will lead our efforts to build foundational security guardrails, launch key security initiatives, and solidify trust customers place in us. Your contributions will be pivotal to the success of Zip’s rapid growth as we launch new products, such as AI Agents and an App Marketplace, and enter into new markets, including EMEA and the Federal government space. We move quickly to solve a wide range of complex technical and product challenges. While we are an experienced team that can provide constant guidance and mentorship, we value engineers who can autonomously scope and solve complex technical challenges.
Job Responsibility:
Design and implement technical controls to eliminate or mitigate classes of security vulnerabilities
Support the development of secure products through design reviews, threat models, static/dynamic scans, and hands-on security assessments
Validate, triage, and coordinate security findings from bug bounty and third party pentests
Mentor security analysts and security champions on security best practices and techniques
Requirements:
Experience writing production-quality code for security tooling and services
Strong written and verbal communication with internal and external stakeholders
A solid understanding of security risks and the ability to balance security with business requirements
Experience with web applications, APIs, and cloud environments. At Zip, our stack includes Python, React, GraphQL, Kubernetes, and AWS
Nice to have:
Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP
Hands-on experience in offensive security (eg, through bug bounty programs or CTFs)