Principal Security Operations Engineer

4 weeks ago


New York, United States Vimeo Full time
Job DescriptionJob Description

As a Principal Security Operations Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our 300+ million users who entrust Vimeo with their content every day.

You'll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from infiltration and cyber-attacks.

You will likely collaborate frequently with and support developers, as well as members of the infrastructure security team, the compliance team, IT, Product, and other teams throughout the organization.

You love to solve puzzles, and are a great team player.

This role is remote.

What you'll do:

Depending on your preferences and the current needs of the team, you may either focus on just some of the following areas, or you may choose to become involved with all of them.

  • As a Principal SecOps Engineer, you will be responsible for ensuring the security of our systems and infrastructure. You will work closely with our development, DevOps teams to identify and remediate vulnerabilities, implement security best practices, and automate security processes. You will also monitor and respond to security incidents and maintain compliance with industry and regulatory standards.
  • Conduct security assessments of our systems and infrastructure to identify vulnerabilities and risks, identify risk owners and implement mitigating controls.
  • Implement and maintain security controls, including access controls, Zero trust network access (ZTNA), network segmentation, and security monitoring tools.
  • Design and operate identity management, lifecycle, governance and SSO.
  • Implement and operate cloud security hardening and cloud security posture management across Google cloud and AWS.
  • Develop and maintain security policies and procedures, and ensure compliance with industry and regulatory standards.
  • Collaborate with SRE, AppSec and Information technology around vulnerability management, endpoint hardening, detection and response.
  • Participate in incident response activities, including investigating security incidents and responding to security alerts.
  • Collaborate with development and DevOps teams to implement security best practices throughout the software development and infrastructure lifecycle.
  • Automate security processes using scripting and other automation tools.
  • Stay up-to-date with the latest security threats, vulnerabilities, and technologies.
  • Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards
  • Process improvements — help strengthen our own internal processes and procedures

Skills and knowledge you should possess:

  • 6+ years of experience in a security or operations role, preferably in a cloud-based Linux environment.
  • 3+ years experience with container and container orchestration systems
  • Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
  • Strong knowledge of security best practices and industry standards, such as NIST, CIS, and ISO.
  • Relevant certifications such as CISSP, CCSP, or AWS Certified Security Specialty are a plus.
  • Experience with security tools such as IDS/IPS, SIEM, vulnerability scanners, and endpoint protection.
  • Experience with automation tools such as Terraform, Ansible, or Chef.
  • Strong scripting skills using Python, shell, or other scripting languages.
  • Excellent problem-solving skills and the ability to work well under pressure.
  • Good communication and interpersonal skills.Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment.
  • Confident with common SDLC components, like git, Jira, Jenkins, etc
  • At least an upper-intermediate level of English

Bonus points (nice skills to have, but not needed):

  • Experience implementing zero trust network access such as Z-Scaler, Warp, Google beyondCorp etc.
  • Experience implementing identity lifecycle including provisioning, quarterly access reviews, role management and deprovisioning.
  • Understanding of FIDO2 and machine certificate authentication flows.
  • Experience with Crowdstrike and OKTA.
  • Experience with system security hardening guidelines and SDLC principles
  • Experience with implementing Fedramp and/or HIPAA.

Targeted Base Salary Range: $149,400 to $227,500

The base salary range listed above is for candidates located in the U.S., including the New York City metro area.

At Vimeo, we strive to hire and nurture amazing talent across the globe. Actual salaries will vary depending on factors including but not limited to experience, specialized skills, internal alignment and a candidate's home base.

Base salary is just one component of Vimeo's total rewards philosophy. We offer a wide range of benefits and perks that appeal to the variety of needs across our diverse employee base Other rewards may include bonus or commission, Restricted Stock Units (RSUs), paid time off, generous 401k match, wellbeing resources, and more.

#LI-MM1

About Us:

Vimeo (NASDAQ: VMEO) is the world's most innovative video experience platform. We enable anyone to create high-quality video experiences to better connect and bring ideas to life. We proudly serve our community of millions of users – from creative storytellers to globally distributed teams at the world's largest companies – whose videos receive billions of views each month. Learn more at www.vimeo.com.

Vimeo is headquartered in New York City with offices around the world. At Vimeo, we believe our impact is greatest when our workforce of passionate, dedicated people, represents our diverse and global community. We're proud to be an equal opportunity employer where diversity, equity, and inclusion is championed in how we build our products, develop our leaders, and strengthen our culture.



  • New York, United States NYSERNet Full time

    The Principal Security Engineer is responsible for the design, implementation, and management of comprehensive security measures that protect NYSERNet’s network infrastructure, data, and systems from cyber threats and vulnerabilities.ResponsibilitiesSecurity Architecture and Strategy:In collaboration with the CISO, oversee and manage the day-to-day...


  • New York, United States Imprint Content Full time

    Who We Are Imprint is building a next-generation co-branded credit card company to serve America's great brands. Today our partners include H-E-B, Central Market, Westgate Resorts, and Holiday Inn Club Vacations. Imprint is backed by Kleiner Perkins, Thrive Capital, and Affirm. We are focused on building a brilliant team who want to change payments and who...


  • New York, United States Northwestern Mutual Full time

    At Northwestern Mutual, we are strong, innovative and growing. We invest in our people. We care and make a positive difference. Ability to work Hybrid Model in either the Milwaukee office (Monday/Tuesday / Wednesday) or in the NYC office (Thursday+ 1 other day) What's the Role? Northwestern Mutual is seeking a hardworking Principal Architect, Data...

  • Principal Engineer

    3 weeks ago


    New Brunswick, United States Wells Fargo Full time

    Act as an advisor to leadership to develop or influence applications, network, information security, database, operating systems, or web technologies for highly complex business and technical needs across multiple groups. Lead the strategy and resolu Principal, Technical Engineer, Engineer, Leadership, Platform Engineer, Banking, Benefits


  • New York, United States Persistent Systems LLC (New York) Full time

    Job Description & Responsibilities: We are looking for a Principal Hardware Engineer who will be responsible for leading research and development of new products, leading improvements existing products and overall systems solutions. This role will play a critical role developing Wave Relay Product solutions with our DOD customers. The Principal Hardware...


  • New York, New York, United States MasterCard Full time

    Our Purpose We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our...


  • New York, United States SoHo Dragon Full time

    Job DescriptionJob DescriptionSalary: SoHo Dragon represents a large non-profit client that needs to hire a Security Operations Engineer. This role is 100% remote.Description:As a Security Operations Engineer you will be responsible for maintaining and enhancing the security posture of our digital environment with a focus on Microsoft technologies. You will...


  • New York, United States SoHo Dragon Full time

    Job DescriptionJob DescriptionSalary: SoHo Dragon represents a large non-profit client that needs to hire a Security Operations Engineer. This role is 100% remote.Description:As a Security Operations Engineer you will be responsible for maintaining and enhancing the security posture of our digital environment with a focus on Microsoft technologies. You will...

  • Operations Manager

    4 weeks ago


    New York, United States Arrow Security Full time

    Job DescriptionJob DescriptionOPERATIONS MANAGER - SECURITY OPERATIONS - ARROW SECURITY NYC REGIONAL OFFICE New York, NYPosition SummaryAs an operative of our company pledge to exceed client expectations, the Operations Manager manages staffing and scheduling of security officers for designated client contract/site location(s). The Account Manager acts as a...


  • New York, United States PRIMIS , Inc. Defunct Full time

    Principal Fullstack Engineer: Hybrid in NYC, No Sponsorship Available At This TimeOur client is a fintech SaaS startup that is looking for an experienced Principal Backend Engineer in the finance space to join their growing team.Qualifications:Autonomy and ownership of the productBackend focused role with 6+ years of experience with RoR (7)Experience with...


  • New York, United States Storm2 Full time

    A Principal Security Analyst position is available within our development team, where you will lead our cloud and application cybersecurity strategy. This role is pivotal in ensuring the security and integrity of our software, systems, and data while ensuring compliance with relevant regulations. The ideal candidate will possess strategic thinking abilities,...


  • New York, United States Storm2 Full time

    A Principal Security Analyst position is available within our development team, where you will lead our cloud and application cybersecurity strategy. This role is pivotal in ensuring the security and integrity of our software, systems, and data while ensuring compliance with relevant regulations. The ideal candidate will possess strategic thinking abilities,...


  • New York, United States Primis Full time

    Principal Fullstack Engineer: Hybrid in NYC, No Sponsorship Available At This TimeOur client is a fintech SaaS startup that is looking for an experienced Principal Backend Engineer in the finance space to join their growing team.Qualifications:Autonomy and ownership of the productBackend focused role with 6+ years of experience with RoR (7)Experience with...

  • Project Engineer

    1 month ago


    New York, United States Engineer Rec Full time

    Our client are seeking Project Engineers for multiple projects along the East Coast, USA. Are you a Project Engineer currently looking for a new challenge and experienced in supporting offshore wind projects? If so please read on. The Project Engineer has the skills and experience to take a leading role related to land and underground installation of high...

  • Project Engineer

    4 weeks ago


    New York, United States Engineer Rec Full time

    Our client are seeking Project Engineers for multiple projects along the East Coast, USA. Are you a Project Engineer currently looking for a new challenge and experienced in supporting offshore wind projects? If so please read on. The Project Engineer has the skills and experience to take a leading role related to land and underground installation of high...


  • New York, United States GMS Advisors Full time

    We are looking for a Principal Backend Engineer with a strong focus in Kubernetes to join our geographically diverse team. All resources may choose to work 100% remotely, at one of our offices in Richmond, VA or San Francisco, CA, or in whatever combination works best. OUR TECH Our core stack includes - Kotlin / Java/ PostgreSQL/ Kubernetes / GCP /JavaScript...

  • Operations Manager

    1 month ago


    New York, United States Arrow Security Full time

    Job DescriptionJob DescriptionOPERATIONS MANAGER - SECURITY OPERATIONS - ARROW SECURITY NYC REGIONAL OFFICENew York, NYPosition SummaryAs an operative of our company pledge to exceed client expectations, the Operations Manager manages staffing and scheduling of security officers for designated client contract/site location(s). The Account Manager acts as a...

  • Operations Manager

    4 weeks ago


    New York, United States Arrow Security Full time

    Job DescriptionJob DescriptionOPERATIONS MANAGER - SECURITY OPERATIONS - ARROW SECURITY NYC REGIONAL OFFICENew York, NYPosition SummaryAs an operative of our company pledge to exceed client expectations, the Operations Manager manages staffing and scheduling of security officers for designated client contract/site location(s). The Account Manager acts as a...


  • New York, United States Storm2 Full time

    A Principal Security Analyst position is available within our development team, where you will lead our cloud and application cybersecurity strategy. This role is pivotal in ensuring the security and integrity of our software, systems, and data while ensuring compliance with relevant regulations. The ideal candidate will possess strategic thinking abilities,...


  • New York, United States Storm2 Full time

    A Principal Security Analyst position is available within our development team, where you will lead our cloud and application cybersecurity strategy. This role is pivotal in ensuring the security and integrity of our software, systems, and data while ensuring compliance with relevant regulations. The ideal candidate will possess strategic thinking abilities,...