Jonathan Poon
Head of Threat and Vulnerability Management at Zoom. I build clarity, systems, and trust so teams can operate independently and deliver durable outcomes.
- Role
- Head of Threat and Vulnerability Management at Zoom
- Location
- Redmond, WA, US
- LinkedIn followers
- 500 followers
About Jonathan Poon
As the Head of Threat and Vulnerability Management (TVM) at Zoom, I lead a high-performing team of security engineers, data analysts, and remediation experts dedicated to safeguarding the company’s cloud, infrastructure, and web application landscape. Our mission goes beyond operational excellence. We accelerate remediation velocity, strengthen compliance KPIs, and collaborate with security, IT and engineering teams to drive down root-cause vulnerabilities at scale.My leadership style is defined by transparency, empathy, and mentorship, all being qualities my peers and team members consistently recognize.According to my colleagues- I’m strategic yet approachable, empowering my team to take ownership of their roles while offering guidance and support- I prioritize career growth and personal well-being, ensuring my team’s development is never secondary to business outcomes- I’m a calm and steadying presence during organizational changes or high stress situations, providing stability and focus in fast-moving environments.In recent quarters, my team has- Reduced out-of-SLA vulnerabilities across all assets by driving automation, improving data pipelines, and strengthening engineering partnerships- Built advanced data pipelines and dashboards to provide real-time insights into vulnerabilities, ownership, remediation trends, and empowering stakeholders with self-service visibility- Automated audit artifacts for key compliance outcomes ensuring audit readiness- Expanded web application scanning coverage, creating a centralized, trusted inventory for stronger web security oversight- Implemented AI enhancements into support, remediation insights and severity impacts.Looking ahead, my vision is to drive innovation through data, automation, and AI, proactively managing and mitigating risk while increasing insights. At the same time, my team’s growth and well-being remain a top priority, fostering an environment of trust, collaboration, and continuous learning.Whether you are a fellow practitioner, an aspiring professional, or a seasoned leader, feel free to reach out and start a conversation. I love learning from one another.If you are contacting me about a SaaS offering or product, please know that I am not actively evaluating new providers at this time. Out of respect for your time and mine, I am always open to reviewing well-prepared material such as white papers, customer success stories, or research. Please share those rather than a sales pitch.Opinions are my own and not the views of my employer.
Experience
Head of Threat and Vulnerability Management
Feb 2021 — Present · Redmond, WA, US
I lead a globally distributed team of security engineers and analysts responsible for protecting Zoom’s platforms, data, and devices from evolving threats.I build and operate a high-leverage TVM program focused on durable risk reduction, which emphasizes expanded coverage, accelerated remediation, and the design of scalable security systems that operate reliably without constant intervention.Scope and impact include:Established and scaled security capabilities across container security, web application scanning, software release assurance, and end-of-life software monitoring, materially improving coverage and risk visibility across production environments.Built and developed a high-performing TVM organization by hiring for judgment and ownership, investing in growth, and enabling senior engineers to lead independently.Embedded software release security assurance into Zoom’s release lifecycle, improving consistency and reducing downstream risk.Designed and automated remediation notifications and security control workflows, increasing program maturity while reducing operational friction.Drove sustained reductions in open vulnerabilities and outdated container images across cloud registries through clear ownership, prioritization, and partner alignment.Developed unified KPIs and risk indicators that translate technical security signals into business-relevant insights for leadership.Partnered closely with DevOps, IT, and engineering leaders to strengthen rigor, accountability, and shared ownership of remediation outcomes.Standardized tools, processes, and governance to deliver vulnerability management as a predictable, scalable, and resilient security capability.I lead by creating clarity, systems, and trust so teams can operate independently and deliver durable outcomes. I am particularly interested in leveraging automation, data, and AI to advance security maturity while supporting sustainable performance and meaningful career growth for my team.
Education
Ngee Ann Polytechnic
Business Studies, Business Computing
1990 — 1993
Chung Cheng High School (Main)
GCE O Levels, High School
1986 — 1989
Skills
- Virtualization
- Computer Security
- Vpn
- Reverse Engineering
- Security Audits
- Security Awareness
- Cissp
- Malware Analysis
- Cyber Security
- Antivirus
- Information Security Management
- Information Security
- Ida
- Firewalls
- Cloud Computing
- Security Architecture Design
- Security
- Enterprise Software
- Management
- Leadership
- Internet Security
- Vulnerability Management
- Ips
- Application Security
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.