Zuora Logo

Zuora

Senior Security Engineer

Reposted 4 Days Ago
Be an Early Applicant
In-Office
Chennai, Tamil Nadu, IND
Senior level
In-Office
Chennai, Tamil Nadu, IND
Senior level
Lead application security initiatives across the SDLC by performing threat modeling, design and code reviews, building security automation and reusable security components, mentoring engineers, and implementing security tooling to reduce risk across cloud-native applications.
The summary above was generated by AI

Company Overview

At Zuora, we do Modern Business. We’re helping people subscribe to new ways of doing business that are better for people, companies and ultimately the planet. It’s an approach resulting from the shift to the Subscription Economy that puts customers first by building recurring relationships instead of one-time product sales and focuses on sustainable growth. Through our leading expertise and multi-product suite, we are transforming all industries and working with the world’s most innovative companies to monetize new business models, nurture subscriber relationships and optimize their digital experiences.

The Team & Role

Zuora’s Application Security & Security Engineering team partners closely with engineering to embed security into the software development lifecycle through scalable tools, processes, and culture.

As an Application Security Engineer, you’ll work hands-on with developers and architects to drive secure design, build security automation, and support critical projects across our cloud-native platform. This role is part of our growing presence in Sydney and offers the opportunity to shape and scale security practices globally.

This is a hybrid position. No remote 

Our Tech Stack: Java, Spring, Rest API, Microservices, Kafka, Spark, NodeJS, AWS, Kubernetes, Terraform, AngularJS 

What you’ll do

  • Collaborate with teams across a global organization to support the adoption and implementation of secure software development practices and tooling.
  • Contribute hands-on to critical engineering and tooling projects, working closely with technical leads and product owners to ensure security is a key part of successful project outcomes.
  • Mentor engineers and influence architectural decisions to ensure security is embedded by design.
  • Design and develop reusable, flexible security components and APIs to support scalable, secure application development across the company.
  • Define and promote best practices to ensure software security without compromising functionality, usability, reliability, or availability.
  • Participate in design and code reviews, providing actionable security recommendations as needed.
  • Collaborate with project teams to design and prototype secure solutions, validating key assumptions and security objectives.
  • Evaluate, implement, and support a range of security tools to improve visibility and reduce risk.
  • Build strong relationships and communicate effectively with stakeholders throughout the SDLC, including Product, Engineering, and Operations teams.

Your experience

  • 8 years of experience in application security, software development, or a related engineering role.
  • Strong understanding of secure software development practices, including experience working with developers to embed security into the SDLC.
  • Hands-on experience conducting security design reviews, threat modeling, and code reviews for web and cloud-based applications.
  • Familiarity with common application vulnerabilities (e.g., OWASP Top 10) and experience in identifying and remediating them.
  • Experience working with security tools such as SAST, DAST, SCA, and container security scanners.
  • Ability to communicate security concepts effectively to both technical and non-technical stakeholders.

Nice to haves:

  • Experience with AWS security best practices and securing cloud-native architectures.
  • Background in DevSecOps or building security automation into CI/CD pipelines.
  • Familiarity with Bug Bounty triage or managing responsible disclosure programs.
  • Experience with regulatory frameworks (e.g., ISO 27001, SOC 2, or GDPR) as they relate to product security.
  • Programming or scripting skills (e.g., Python, JavaScript, or Go) to build internal tools or automation.

#ZEOLife at Zuora

As an industry pioneer, our work is constantly evolving and challenging us in new ways that require us to think differently, iterate often and learn constantly—it’s exciting. Our people, whom we refer to as “ZEOs" are empowered to take on a mindset of ownership and make a bigger impact here. Our teams collaborate deeply, exchange different ideas openly and together we’re making what’s next possible for our customers, community and the world. 

As part of our commitment to building an inclusive, high-performance culture where ZEOs feel inspired, connected and valued, we support ZEOs with:

  • Competitive compensation, variable bonus and performance reward opportunities, and retirement programs
  • Medical, dental and vision insurance
  • Generous, flexible time off 
  • Paid holidays, “wellness” days and company wide end of year break
  • 6 months fully paid parental leave 
  • Learning & Development stipend
  • Opportunities to volunteer and give back, including charitable donation match
  • Free resources and support for your mental wellbeing  

Specific benefits offerings may vary by country and can be viewed in more detail during your interview process.

Location & Work Arrangements

Organizations and teams at Zuora are empowered to design efficient and flexible ways of working, being intentional about scheduling, communication, and collaboration strategies that help us achieve our best results. In our dynamic, globally distributed company, this means balancing flexibility and responsibility — flexibility to live our lives to the fullest, and responsibility to each other, to our customers, and to our shareholders. For most roles, we offer the flexibility to work both remotely and at Zuora offices.

Our Commitment to an Inclusive Workplace

Think, be and do you! At Zuora, different perspectives, experiences and contributions matter. Everyone counts. Zuora is proud to be an Equal Opportunity Employer committed to creating an inclusive environment for all.

Zuora does not discriminate on the basis of, and considers individuals seeking employment with Zuora without regards to, race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.

We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us by sending an email to assistance(at)zuora.com.

Zuora Chennai, Tamil Nadu, IND Office

9th floor, Tower B, OMR, 9:13 Brigade World trade centre, SH 49A, Vijayendra Nagar, Perungudi, Chennai, Tamil Nadu, India, 600096

Similar Jobs

5 Days Ago
In-Office
Chennai, Tamil Nadu, IND
Senior level
Senior level
Artificial Intelligence • Machine Learning
Lead and mature non-human identity and machine access: inventory and secure service accounts, API keys, tokens, certificates, and secrets; implement least-privilege, short-lived credentials, PAM, secrets management, identity governance, cross-account trust across multi-cloud (AWS primary), and automate identity controls via IaC and CI/CD.
Top Skills: Aws IamCertificatesCi/CdCloud Secret ManagersHashicorp VaultJwtMicrosoft EntraMtlsOauth 2.0OidcPowershellPrivileged Access Management (Pam)PythonRackspaceSpiffe/SpireTerraform
5 Days Ago
In-Office or Remote
India
Senior level
Senior level
Blockchain
Lead and own the information security program and security engineering at NEAR Foundation. Drive SOC 2 Type 2 and ISO 27001 readiness, run logging/monitoring/incident response, manage vulnerability and third-party risk, harden identity/access/endpoint stacks, automate security and compliance across SaaS, and advise on tooling and cloud security (AWS/GCP).
Top Skills: AWSBashEdrEntraGCPGoGoogle WorkspaceIamIso 27001LoggingMdmMfaMonitoringOktaPythonSIEMSoc IiSso
5 Days Ago
In-Office or Remote
India
Senior level
Senior level
Cloud • Security • Software • Cybersecurity
Lead application security efforts by governing vulnerability management, automating security workflows, embedding SSDLC practices, partnering with engineering/GRC to meet compliance, and serving as a security SME during incident response and customer escalations.
Top Skills: AWSAzureCCspmDastFedrampGCPGoHipaaIac ScanningIso 27001JavaJavaScriptLinodePciPythonSastScaSoc2Ssdlc

What you need to know about the Chennai Tech Scene

To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account