IMPORTANT: Please be aware, scammers may try to impersonate Zello by reaching out regarding job opportunities. We will never ask you for bank account information, checks, or other sensitive information as part of our hiring process. All correspondence will come from the zello.com email domain. If you’re unsure, please email [email protected] with questions.
About ZelloZello is a voice-first communication platform, powered by our industry-leading push-to-talk technology, to improve collaboration and productivity for desk-less workers. With over 175+ million users, we’re the #1 rated push-to-talk app in the world, delivering 9 billion (yes, with a B) messages a month.
At Zello, our company values are at the heart of what we do everyday. We’re proud to serve the frontline, we’re privileged to connect people in times of crisis across the globe, and we’re honored to support first responders.
And this is where you come in.
Zello keeps frontline teams connected with instant voice, on a platform trusted by public safety, healthcare, utilities, and large retail. Our Security Engineering function has proven that AI can multiply security signal: our AI security reviewer is now our largest source of findings. The bottleneck has moved from detection to triage and remediation. You'll be the second security engineer, splitting an operate/build rotation with the Director of Security Engineering and building the automation that lets security scale without scaling headcount.
After a successful first year, you willHave completed Zello's Google Cloud hardening project, including the long-standing items that had been open for more than six months.
Have set the direction for and shipped supply chain security: SCA, SAST, and secrets scanning running in CI across our primary repos and blocking on High/Critical findings, plus package inventory and malicious-package scanning.
Have launched a vulnerability triage pipeline within six months that deduplicates, scores, and routes findings to owning teams, and auto-triages at least half of incoming findings by month twelve.
Have helped turn the vulnerability backlog net-negative and brought High/Critical findings open past SLA to zero, with the AI security agent tuned so its findings arrive already triaged.
Take your turn on interrupt duty (findings triage, access questions, incidents, and customer security assessments), then swap to protected build time.
Tune the AI security reviewer and triage agents, and decide which calls stay with a human owner.
Build the intake pipeline that routes findings from the AI reviewer, bug bounty, pen tests, and audits to the teams that own the code, with SLA clocks per severity.
Lead the Google Cloud hardening project across IAM, org policy, and workload configuration.
Choose and roll out code scanning and supply chain controls in GitHub and CI/CD, and make sure engineers can act on what the scanners find.
Review code and designs that touch authorization, identity, and tenancy, and push fixes through Platform, Web, and Backend teams.
Write the runbooks and requirements that let anyone on the team run a security process without you.
You've built and shipped security automation in code, and you can walk us through something you wrote that still runs in production.
You've applied LLMs or agents to real security work, and you have opinions about where AI output needs a human owner.
You can read application code and spot an exploitable authorization, identity, or secrets flaw, then explain it to the team that has to fix it.
You've rolled out security scanning in CI and turned the results into fixes, not just dashboards.
You've secured IAM and workloads in a major cloud. GCP is ideal; AWS or Azure is fine.
You get fixes shipped by teams you don't manage, and engineers describe working with you as straightforward.
You learn fast and go broad. You're comfortable moving between incident mode and build mode in the same week.
A people management role or the first step toward building a large security team.
A GRC or compliance role. Governance and audit programs sit with our CISO.
A 24/7 SOC role. Off-hours infrastructure monitoring stays with our MDR partner.
An IT helpdesk role. Day-to-day SaaS provisioning belongs to Ops.
We hire for potential, passion for our mission, and a knack for solving difficult problems over checking every qualification box. We have competitive pay, equity with significant upside, and intentionally design our benefits to encourage healthy and well-balanced employees, flexible schedules and time off. We even offer a sabbatical after every five years of service so you’re able to pursue and enjoy what matters most to you. And of course, we wouldn’t be a technology company without a ping-pong table and free snacks in our break room. Join us!
Zello provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
All Zello personnel are required to comply with defined security, privacy, and compliance requirements applicable to their role along with requirements that are applicable to all Zello personnel.
Zello Austin, Texas, USA Office
We're at downtown Austin on West 6th, with quick highway access. Directly across from Mean Eyed Cat and El Arroyo, there’s always somewhere for lunch or drinks.
Similar Jobs at Zello
What you need to know about the Austin Tech Scene
Key Facts About Austin Tech
- Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
- Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
- Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
- Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

