• Hands-on, IC Senior Security Engineer comfortable working with Azure cloud configurations and implementing security remediation tactics at a technical level
  • Experienced engineer who fosters a risk-based, “automate everything”, collaborative, and “blameless” way of working 
  • Remote-first opportunity for US-based employees with the option to work in-person out of our Manhattan office 

Start your adventure with Zip 

Join Zip’s Engineering function and put your name to solving fascinating challenges at scale in an agile, test-driven development environment. If you value good domain-driven design and enjoy delivering quality work at pace, you’ll be a great fit with the squads responsible for building cloud-native software applications that serve millions of customers and process billions of dollars in payments. 

As a Senior Cloud Security Engineer, you will be responsible for implementing cloud security controls that ensure the trust and reliability of our Buy Now, Pay Later (BNPL) service. Your day to day work will span analyzing an Azure cloud-native, microservices environment for security control gaps and implementing secure configurations and solutions for network, IAM and application security. You will champion cross-functional collaboration across security and engineering teams and implement globally applicable controls wherever possible. 

 

Interesting problems you’ll get to solve

  • Assess and implement secure architecture patterns in Azure for identity and access management, container and API security, key management, patching and network segmentation. 
  • Investigate design flaws and security configurations
  • Participate in annual cloud architecture assessment and quarterly audit/risk assessments 
  • Integrate third party SaaS and Security products securely into a containerized cloud-native environment 
  • Support incident response analysis and internal penetration testing, as needed
  • Produce detailed cloud configuration assessments and evidence artifacts for internal and external audits (ISO 27001, PCI-DSS and SOC audits).
  • Work with engineering teams to deploy secure-by-design product features and enhancements
  • Create and maintain a repository of technology architecture diagrams and threat models.
  • Collaborate with engineering teams to ensure continuous adoption of security controls and remediation of security findings 
  • Present security and risk posture narratives for leadership and board reporting 

 

Key FY Initiatives

  • Uplifting the Zip U.S. security maturity via standardized security implementations
  • Elevating the application security program to ensure proper security controls from design through production
  • Automate security solutions for automated patching, identity and access management, and API security

 

What you’ll bring to the team 

  • 7+ years of experience in hands-on security engineering roles
  • Must have hands-on security administration experience on Azure - Active Directory, Identity governance, portal, Infrastructure/SSO/MFA, Terraform IaC and Github
  • Experience integrating and interpreting security telemetry from security products such as VPNs, Mobile Device Management (MDM), SIEM, and EDR in a cloud-native environment
  • Experience implementing network and container security, service mesh and firewalls
  • Preferred certifications: CISSP, GPEN, GCIH, CISM, CEH, or comparable information security assurance certifications
  • Experience with financial industry security governance, including PCI DSS, SOC2, ISO 27K and state regulations
  • A passion for security and technical knowledge of threats that affect cloud infrastructure and software
  • Alignment with big picture business objectives, and an understanding of cost-benefit considerations
  • A learner’s mindset, self-motivated with a strong attention to detail and you believe in meaningful documentation
  • Ability to collaborate and prioritise tasks in a high-growth business environment, collaborating with stakeholders across multiple time zones
  • Our values in your DNA: Customer First, Own It, Stronger Together and Change the Game

What you’ll get in return

Zip is a place where you’ll get out what you put in. The newness of our sector means we need to move at pace and embrace change, and our promise to you when you join the team is that you’ll feel empowered and trusted to make big things happen quickly. 

We want you to feel welcome and as though you have the support to be yourself, and care for yourself at work. Because it’s important to us that you make the most of the opportunities you’ll get to grow your skills and your career, and be surrounded by smart, friendly people and leaders that have your back.

We think these are just some of the best things about being a Zipster. We will also offer you:

  • Flexible working culture
  • Incentive programs
  • 20 days PTO every year
  • Generous paid parental leave
  • Leading family support policies
  • 100% employer covered insurance
  • Beautiful Midtown office with a casual dress code
  • Learning and wellness subscription stipend
  • Company-sponsored 401k match

 

The Pay Range for this position: $150,000- $220,000 USD based on the industry benchmark for position, function, level and Zip's compensation strategies. However, actual base salary will depend on varying circumstances and individualized factors, such as job-related knowledge, skills, experience, and other objective business considerations. 

Subject to those same considerations, the total compensation package for this position may also include other elements, including a bonus and/or equity awards, in addition to a full range of medical, financial, and/or other benefits. 

 

Be a part of a team that reflects the diversity of our customers

We pride ourselves on being a workplace that provides equal opportunities to people of all ages, cultural backgrounds, sexual orientations, gender identities, abilities, veteran status, and everything else that makes you unique.

Equally, we’re committed to ensuring our recruitment processes are accessible and inclusive. Please let us know If there are any adjustments that need to be made to ensure you have a fair and equitable experience.

And finally…get to know us

Zip Co Limited (ASX: ZIP) is a digital financial services company, offering innovative, people-centred products that bring customers and merchants together.

Operating in two core markets - Australia and New Zealand (ANZ) and the Americas, Zip offers point-of-sale credit and digital payment services, connecting millions of customers with its global network of tens of thousands of merchants.

We’re proud to be a values-led business and our values - Customer First, Own it, Stronger Together and Change the Game - guide us in everything we do.

I acknowledge by clicking "Submit Application", that the information provided is true and correct. I also understand that any willful dishonesty may render for refusal of this application or immediate termination of employment. By providing your information, you acknowledge that you have read our Zip Applicant and Candidate Privacy Notice and authorize Zip to process your data subject to those terms.

Before you apply, give Zip a try   -> rebrand.ly/check-zip-out

 Before you apply, give Zip a try

We are a proud 2024 Circle Back initiative employer and will respond to every applicant.

Apply for this Job

* Required

resume chosen  
(File types: pdf, doc, docx, txt, rtf)
cover_letter chosen  
(File types: pdf, doc, docx, txt, rtf)


Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Zip Co Limited’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.


Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.


Please reach out to our support team via our help center.
Please complete the reCAPTCHA above.