At Zuora, we drive Modern Business by enabling the Subscription Economy, focusing on recurring customer relationships and sustainable growth. The Application Security & Security Engineering team partners with engineering to embed security into the software development lifecycle (SDLC) through tools, processes, and culture. As an Application Security Engineer, you will work hands-on with developers and architects to drive secure design, build security automation, and support critical projects across Zuora’s cloud-native platform. This hybrid role is based in Sydney and offers the opportunity to shape and scale security practices globally.
Responsibilities
- Collaborate with teams across a global organization to support the adoption and implementation of secure software development practices and tooling.
- Contribute hands-on to critical engineering and tooling projects, working closely with technical leads and product owners to ensure security is a key part of successful project outcomes.
- Mentor engineers and influence architectural decisions to ensure security is embedded by design.
- Design and develop reusable, flexible security components and APIs to support scalable, secure application development across the company.
- Define and promote best practices to ensure software security without compromising functionality, usability, reliability, or availability.
- Participate in design and code reviews, providing actionable security recommendations as needed.
- Collaborate with project teams to design and prototype secure solutions, validating key assumptions and security objectives.
- Evaluate, implement, and support a range of security tools to improve visibility and reduce risk.
- Build strong relationships and communicate effectively with stakeholders throughout the SDLC, including Product, Engineering, and Operations teams.
Requirements
- 8 years of experience in application security, software development, or a related engineering role.
- Strong understanding of secure software development practices, including experience working with developers to embed security into the SDLC.
- Hands-on experience conducting security design reviews, threat modeling, and code reviews for web and cloud-based applications.
- Familiarity with common application vulnerabilities (e.g., OWASP Top 10) and experience in identifying and remediating them.
- Experience working with security tools such as SAST, DAST, SCA, and container security scanners.
- Ability to communicate security concepts effectively to both technical and non-technical stakeholders.
Nice to have
- Experience with AWS security best practices and securing cloud-native architectures.
- Background in DevSecOps or building security automation into CI/CD pipelines.
- Familiarity with Bug Bounty triage or managing responsible disclosure programs.
- Experience with regulatory frameworks (e.g., ISO 27001, SOC 2, or GDPR) as they relate to product security.
- Programming or scripting skills (e.g., Python, JavaScript, or Go) to build internal tools or automation.
Benefits
- Competitive compensation, variable bonus and performance reward opportunities, and retirement programs
- Medical, dental and vision insurance
- Generous, flexible time off
- Paid holidays, 'wellness' days and company wide end of year break
- 6 months fully paid parental leave
- Learning & Development stipend
- Opportunities to volunteer and give back, including charitable donation match
- Free resources and support for your mental wellbeing
Additional details
- Company Overview: Zuora enables the Subscription Economy, focusing on recurring customer relationships and sustainable growth through a multi-product suite.
- The Team & Role: Application Security & Security Engineering team embeds security into the SDLC via tools, processes, and culture.
- Tech Stack: Java, Spring, Rest API, Microservices, Kafka, Spark, NodeJS, AWS, Kubernetes, Terraform, AngularJS
- This is a hybrid position. No remote
- Organizations and teams at Zuora are empowered to design efficient and flexible ways of working, balancing flexibility and responsibility.
- For most roles, Zuora offers the flexibility to work both remotely and at Zuora offices.
- Zuora is an Equal Opportunity Employer committed to an inclusive environment for all.
- Zuora does not discriminate on the basis of race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.
- Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact assistance(at)zuora.com.
- Specific benefits offerings may vary by country and can be viewed in more detail during the interview process.