Skip to content

Open nowPosted 9 days ago

Security Engineer- Application & Cloud

Zello8 open roles

Where
Austin, Texas
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer- Application & CloudZello · Austin, Texas
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Zello's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Zello postings stay open a median of 27 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 9 days ago

Zello median: 27 days open

The posting

IMPORTANT: Please be aware, scammers may try to impersonate Zello by reaching out regarding job opportunities. We will never ask you for bank account information, checks, or other sensitive information as part of our hiring process. All correspondence will come from the zello.com email domain. If you’re unsure, please email [email protected] with questions.

ABOUT ZELLO

Zello is a voice-first communication platform, powered by our industry-leading push-to-talk technology, to improve collaboration and productivity for desk-less workers. With over 175+ million users, we’re the #1 rated push-to-talk app in the world, delivering 9 billion (yes, with a B) messages a month.

At Zello, our company values are at the heart of what we do everyday. We’re proud to serve the frontline, we’re privileged to connect people in times of crisis across the globe, and we’re honored to support first responders.

And this is where you come in.

Zello keeps frontline teams connected with instant voice, on a platform trusted by public safety, healthcare, utilities, and large retail. Our Security Engineering function has proven that AI can multiply security signal: our AI security reviewer is now our largest source of findings. The bottleneck has moved from detection to triage and remediation. You'll be the second security engineer, splitting an operate/build rotation with the Director of Security Engineering and building the automation that lets security scale without scaling headcount.

AFTER A SUCCESSFUL FIRST YEAR, YOU WILL

- Have completed Zello's Google Cloud hardening project, including the long-standing items that had been open for more than six months.

- Have set the direction for and shipped supply chain security: SCA, SAST, and secrets scanning running in CI across our primary repos and blocking on High/Critical findings, plus package inventory and malicious-package scanning.

- Have launched a vulnerability triage pipeline within six months that deduplicates, scores, and routes findings to owning teams, and auto-triages at least half of incoming findings by month twelve.

- Have helped turn the vulnerability backlog net-negative and brought High/Critical findings open past SLA to zero, with the AI security agent tuned so its findings arrive already triaged.

WHAT YOU'LL DO

- Take your turn on interrupt duty (findings triage, access questions, incidents, and customer security assessments), then swap to protected build time.

- Tune the AI security reviewer and triage agents, and decide which calls stay with a human owner.

- Build the intake pipeline that routes findings from the AI reviewer, bug bounty, pen tests, and audits to the teams that own the code, with SLA clocks per severity.

- Lead the Google Cloud hardening project across IAM, org policy, and workload configuration.

- Choose and roll out code scanning and supply chain controls in GitHub and CI/CD, and make sure engineers can act on what the scanners find.

- Review code and designs that touch authorization, identity, and tenancy, and push fixes through Platform, Web, and Backend teams.

- Write the runbooks and requirements that let anyone on the team run a security process without you.

WHO YOU ARE

- You've built and shipped security automation in code, and you can walk us through something you wrote that still runs in production.

- You've applied LLMs or agents to real security work, and you have opinions about where AI output needs a human owner.

- You can read application code and spot an exploitable authorization, identity, or secrets flaw, then explain it to the team that has to fix it.

- You've rolled out security scanning in CI and turned the results into fixes, not just dashboards.

- You've secured IAM and workloads in a major cloud. GCP is ideal; AWS or Azure is fine.

- You get fixes shipped by teams you don't manage, and engineers describe working with you as straightforward.

- You learn fast and go broad. You're comfortable moving between incident mode and build mode in the same week.

THIS ROLE IS NOT

- A people management role or the first step toward building a large security team.

- A GRC or compliance role. Governance and audit programs sit with our CISO.

- A 24/7 SOC role. Off-hours infrastructure monitoring stays with our MDR partner.

- An IT helpdesk role. Day-to-day SaaS provisioning belongs to Ops.

We hire for potential, passion for our mission, and a knack for solving difficult problems over checking every qualification box. We have competitive pay, equity with significant upside, and intentionally design our benefits to encourage healthy and well-balanced employees, flexible schedules and time off. We even offer a sabbatical after every five years of service so you’re able to pursue and enjoy what matters most to you. And of course, we wouldn’t be a technology company without a ping-pong table and free snacks in our break room. Join us!

Zello provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

All Zello personnel are required to comply with defined security, privacy, and compliance requirements applicable to their role along with requirements that are applicable to all Zello personnel.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Zello's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Zello's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Zello's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.