Upload Button Icon Add office photos
Engaged Employer

i

This company page is being actively managed by Zeta Team. If you also belong to the team, you can get access from here

Zeta Verified Tick

Compare button icon Compare button icon Compare
3.3

based on 242 Reviews

filter salaries All Filters

137 Zeta Jobs

Application Security Engineer I/II

2-3 years

Bangalore / Bengaluru

1 vacancy

Application Security Engineer I/II

Zeta

posted 1mon ago

Job Description


Our flagship processing platform - Zeta Tachyon - is the industry s first modern, cloud-native, and fully API-enabled stack that brings together issuance, processing, lending, core banking, fraud & risk, and many more capabilities as a single-vendor stack. 20M+ cards have been issued on our platform globally.
Zeta has over 1700+ employees - with over 70% roles in R&D - across locations in the US , EMEA , and Asia . We raised $280 million at a $1.5 billion valuation from Softbank, Mastercard, and other investors in 2021.
Learn more @ www.zeta.tech , careers.zeta.tech , Linkedin , Twitter
About the Role
    • This role is part of the RIsk & Compliance Team, Engineering division of Zeta. The Application Security Engineer is responsible to secure all mobile & web applications along with API s by breaking and hacking them and educating Developers as well as DevOps teams on how to fix them. The objective is to make zeta applications and platforms secure. As Application Security Engineer of the Product Security sub-division, you will be responsible for securing all the Zeta s Products. You will be working as an individual contributor reporting to a manager.
    • Perform regular VA/PT for Web & Mobile applications, API & Infrastructure
    • Guide developers in fixing security issues.
    • Regular code reviews
    • Involve in application design discussions.
    • Perform Threat Modelling of Web/Mobile applications.
    • Develop secure code practices and educate dev and QA engineers by building security standards, policies for secure coding, secure data handling, secure networking, secure crypto implementation, etc.
    • Evaluate & Integrate security testing tools (SAST, DAST,SCA) in to CI/CD pipelines.
Responsibilities
    • Guide the technology organizations security and privacy initiatives by participating in design reviews and threat modeling.
    • The applications are developed by the developers and product managers, and you will make sure the applications are secured and hardened.
    • You will define the scope and ensure continuous adherence to the scope of projects at each phase (initiation to sustenance/maintenance phase).
    • You will be responsible for creating visibility, and adoption of the projects meant for internal customers.
    • Act as a security engineering expert and technical champion within Zeta.
    • Assess gaps, and tools to improve application security
    • Liasioning with all external and internal stakeholders for the team.
    • Mentoring developers and QA.
    • Evaluate bugs reported through the Bug Bounty program.
    • Run security posture of various applications across BU s.
    • Continuous improvement of web/mobile application security
    • Quarterly VA/PT (internal/external, authenticate/non-authenticated) for mobile/web.
    • Secure configuration of Web/Mobile application, DB, Data etc.

Skills
    • Hands on VA/PT experience in Web, Mobile, API & Network
    • Thorough understanding of OWASP Top 10, their attack & defence mechanisms
    • Exposure to Secure SDLC Activities, Threat Modelling & Secure Coding
    • Experience on both commercial and open source tools like Burpsuite, AppScan, OWASP ZAP, BEEF, MetaSploit, Qualys, Nessus, Synk etc.
    • Identifying & exploiting business logic-related vulnerabilities.
    • Solid understanding of Cryptography, knowledge of PKI-based systems, TLS
    • Understanding of different AuthN/AuthZ frameworks (OIDC, oAuth, SAML) able to read/write/understand java code
    • Performed Static Analysis, Code reviews using tools like Snyk, Veracode, Checkmarx, Sonarqube etc.
    • Hands on Reversing mobile applications, class/small files, data obfuscators, or ciphers (Dex2jar, adb, Drozer, Clang, iMAS) and Dynamic Instrumentation tools like Frida/Objection
    • Execute penetration tests and security assessments on internal and external networks, Windows and Linux environments, cloud (AWS) Infrastructure.
    • Identify and exploit incorrect configurations and security vulnerabilities on Windows and Linux servers. Safely utilize tools, tactics, and procedures used in penetration testing engagements.
    • Shell scripting or automation of simple tasks using Python, or Ruby
    • Knowledge of PA-DSS, PCI SSF (S3, SSLC) etc.
    • Knowledge of security standards like PCI DSS, UIDAI, GDPR, NIST etc.
    • Understanding of Java Frameworks like Springboot, CI/CD, Jenkins.
    • In-depth understanding of production operations on public cloud infrastructure.
    • Excellent written and oral communication and a penchant for technical documentation.
    • Must have participated in various bug bounty programs (HackerOne, Bug Crowd, Private etc)
    • Experience in conducting hackathons and CTF s
    • Knowledge of AWS/Azure (VPC/Vnet, S3 buckets, blob stores, LoadBalancers etc.), Dockers & Containers, Kubernetes
    • Good understanding of agile development practices.
    • Certifications like OSCP(Preferred), GWAPT, Advanced Web Attacks and Exploitation (AWAE), Comptia Security+
    • Knowledge of Databases - Postgresql, Redshift, My SQL etc. and other data stores like Elasticsearch and S3 buckets.
Experience and Qualifications
    • 2+ years of experience in developing large scale internet or SaaS applications.
    • 2 to 3 years of overall experience as Web/Mobile Application Security engineer or Developer in medium to large-sized product companies. Bachelor of Technology (BE/ B.Tech ), M.Tech or ME in Computer Science or equivalent from a Tier-1 engineering college/university
Equal Opportunity


Employment Type: Full Time, Permanent

Read full job description

Prepare for Application Security Engineer roles with real interview advice

People are getting interviews at Zeta through

(based on 41 Zeta interviews)
Job Portal
Referral
Company Website
Campus Placement
Walkin
29%
27%
17%
10%
2%
15% candidates got the interview through other sources.
High Confidence
?
High Confidence means the data is based on a large number of responses received from the candidates.

What people at Zeta are saying

What Zeta employees are saying about work life

based on 242 employees
79%
87%
75%
92%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

Zeta Benefits

Submitted by Company
Child care
Gymnasium
Cafeteria
Free Food
Team Outings
Education Assistance +2 more
Submitted by Employees
Cafeteria
Team Outings
Health Insurance
Job Training
Work From Home
Soft Skill Training +6 more
View more benefits

Compare Zeta with

Paytm

3.3
Compare

PhonePe

4.0
Compare

Mobikwik

4.0
Compare

Payed

2.8
Compare

Razorpay

3.6
Compare

BillDesk

3.2
Compare

PayPal

3.9
Compare

CCAvenue

2.1
Compare

Instamojo

3.4
Compare

Ola Money

3.3
Compare

Oracle

3.7
Compare

Fractal Analytics

4.0
Compare

Watchyourhealth.com

4.9
Compare

Subex

3.4
Compare

Kiya.ai

3.5
Compare

MathCo

3.0
Compare

Sedemac Mechatronics

4.1
Compare

Hughes Systique Corporation

3.9
Compare

Shorthills AI

4.3
Compare

eligarf Technologies

4.4
Compare

Similar Jobs for you

Security Consultant at ILLUME CREATIVE STUDIO

Bangalore / Bengaluru

2-7 Yrs

₹ 1-5 LPA

AWS Devops Engineer at Rackspace Technology

Remote

3-6 Yrs

₹ 5-8 LPA

Engineer 1 at Resy

Gurgaon / Gurugram

1-3 Yrs

₹ 2-5 LPA

Test Engineer - II at Abbott Healthcare Pvt. Ltd

Mumbai

2-6 Yrs

₹ 4-8 LPA

Staff Engineer at Redpine Signals, Inc.

Hyderabad / Secunderabad

3-8 Yrs

₹ 5-10 LPA

Linux Developer at Harman Connected Services Corporation India Pvt.

Bangalore / Bengaluru

3-5 Yrs

₹ 5-7 LPA

Solution Engineer 2 at Ericsson India Global Services Pvt. Ltd.

Bangalore / Bengaluru

2-5 Yrs

₹ 4-7 LPA

Solution Engineer 2 at Ericsson India Global Services Pvt. Ltd.

Bangalore / Bengaluru

2-6 Yrs

₹ 4-8 LPA

Software Quality Engineer at Aspen Technology

Bangalore / Bengaluru

2-5 Yrs

₹ 4-7 LPA

Product Security Engineer at SnapRoute

Bangalore / Bengaluru

2-6 Yrs

₹ 5-9 LPA

Zeta Bangalore / Bengaluru Office Location

View all
Bengaluru Office
Headquarter
Ground Floor, Tower C, Diamond district, Old Airport Rd, Domlur Bengaluru
560008

Application Security Engineer I/II

2-3 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

Director - Finance and Accounts

7-10 Yrs

Mumbai, Bangalore / Bengaluru

2d ago·via naukri.com

Director - Engineering (Backend)

15-18 Yrs

Bangalore / Bengaluru

3d ago·via naukri.com

Technical Support Engineer

1-4 Yrs

Bangalore / Bengaluru

6d ago·via naukri.com

Quality Assurance Engineer-I/II

3-4 Yrs

Hyderabad / Secunderabad

10d ago·via naukri.com

Software Development Engineer II - Frontend

2-4 Yrs

Hyderabad / Secunderabad

15d ago·via naukri.com

Lead Software Development Engineer in Test

13-17 Yrs

Mumbai

15d ago·via naukri.com

Senior Software Development Engineer - Backend

5-8 Yrs

Hyderabad / Secunderabad

16d ago·via naukri.com

Software Development Engineer in Test II

2-7 Yrs

Hyderabad / Secunderabad

16d ago·via naukri.com

Senior Quality Assurance Engineer

4-7 Yrs

Hyderabad / Secunderabad

16d ago·via naukri.com
write
Share an Interview