ZS Logo

ZS

Application Security Analyst

Posted 12 Days Ago
Be an Early Applicant
Hybrid
Pune, Maharashtra
Mid level
Hybrid
Pune, Maharashtra
Mid level
Performs manual penetration testing of web, mobile, API, and microservices applications; conducts secure code reviews and design assessments; identifies and validates vulnerabilities; documents findings; supports remediation and incident response; guides junior testers; and promotes secure coding and application security awareness.
The summary above was generated by AI
What You'll Do: The Application Security Analyst in Enterprise will report to the Application Security Lead
  • Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
  • Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
  • Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
  • Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
  • Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
  • Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
  • Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
  • Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
  • Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.

What You'll Bring:
  • Bachelor's in computer science /management of computer information/information assurance or Cybersecurity
  • 0-4 years of Penetration Testing / Application Security / Offensive Security
  • Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
  • Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
  • Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
  • Must be a self-starter who can learn quickly and independently.
  • Fluency in English
  • Client-first mentality
  • Intense work ethic
  • Collaborative spirit and problem-solving approach

Similar Jobs at ZS

Yesterday
Hybrid
Senior level
Senior level
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Leads client-facing data engineering engagements from discovery through production, translating business requirements into cloud architectures, ETL/ELT pipelines, data lakes, warehouses, and analytics solutions. Oversees technical delivery, project planning, quality reviews, testing, documentation, and stakeholder communications. Mentors engineers and consultants, drives coding and data quality standards, supports business development, and develops scalable solutions using Python, SQL, Spark, and major cloud platforms. The role also contributes to AI-enabled data engineering and supply chain or manufacturing solutions.
Top Skills: Amazon AthenaAmazon Managed AirflowAmazon RedshiftAmazon S3Amazon SagemakerSparkAws EmrAws GlueAws Lake FormationAws NeptuneAzure Data FactoryAzure Data Lake StorageAzure Synapse AnalyticsDatabricksLlmNeo4JPysparkPythonRagRdfSnowflakeSQL
Yesterday
Hybrid
Mid level
Mid level
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Support enterprise DLP and DSPM operations by monitoring and investigating data security incidents, tuning policies, conducting data discovery and classification, managing cloud and SaaS data sources, and preparing compliance reports and security metrics. The role collaborates with security, legal, privacy, compliance, HR, infrastructure, and business teams on incident response, remediation, and continuous improvement.
Top Skills: AWSAzureBigidCrowdstrikeData Loss Prevention (Dlp)Data Security Posture Management (Dspm)Endpoint Detection And Response (Edr)Microsoft 365Microsoft DefenderMicrosoft PurviewMicrosoft SentinelServicenowSharepointZscaler Dlp
2 Days Ago
Hybrid
Junior
Junior
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Manage AWS infrastructure across production, staging, and development environments. Responsibilities include incident response, troubleshooting, root cause analysis, monitoring, access management, patching coordination, resource and cost optimization, and maintaining high availability. The role supports Terraform-based provisioning, drift remediation, automation, and CI/CD infrastructure deployments while collaborating with Engineering, Security, and Data teams.
Top Skills: AWSAws Cost ExplorerCi/CdCloudwatchEc2EmrIamLambdaOn-Premises InfrastructureRdsS3Terraform

What you need to know about the Chennai Tech Scene

To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account