Application Security Analyst

ZS

Maharashtra

On-site

INR 600,000 - 1,200,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ZS is looking for an Application Security Analyst to perform manual penetration testing on web, mobile, APIs, and microservices across production and pre-production environments. The role includes secure code reviews, security assessments, and mentoring junior testers, using Burp Suite Pro, OWASP ZAP, Snyk, and other industry tools.

You will work with development, QA, and architecture teams to promote secure coding practices, support incident response, and enhance application security maturity

Qualifications

  • Hands-on experience performing manual application penetration testing.
  • Experience conducting secure code reviews and design-level security assessments.
  • Familiarity with OWASP Top 10 and common insecure coding patterns.

Responsibilities

  • Perform manual app security penetration testing on web, mobile, APIs, and microservices in production and pre-production.
  • Conduct secure code reviews and design-level security assessments with DevSecOps teams.
  • Identify and document vulnerabilities per OWASP Top 10, SANS Top 25, and misconfigurations.
  • Provide guidance to junior testers and review assessment outputs.
  • Use tools like Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and scripts to detect issues.

Skills

Penetration testing
Application security
Offensive security
Security certifications

Education

Bachelor's degree in CS/InfoSec

Tools

Burp Suite Pro
OWASP ZAP
Snyk
Checkmarx
Black Duck
Postman
Custom scripts

Job description

What You’ll Do

The Application Security Analyst in Enterprise will report to the Application Security Lead.

  • Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
  • Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
  • Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
  • Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
  • Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
  • Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
  • Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
  • Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
  • Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.
What You’ll Bring
  • Bachelor’s in computer science /management of computer information/information assurance or Cybersecurity
  • 0-4 years of Penetration Testing / Application Security / Offensive Security
  • Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
  • Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
  • Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
  • Must be a self-starter who can learn quickly and independently.
  • Fluency in English
  • Client-first mentality
  • Intense work ethic
  • Collaborative spirit and problem-solving approach
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

Zs Associates • Pune District

On-site
INR 600,000 - 1,000,000
Application Security Analyst
Application Security Analyst

Zs Associates • Mumbai

Hybrid
INR 900,000 - 1,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Associate Security Analyst (AppSec)
Associate Security Analyst (AppSec)

Kratikal Tech Private Limited • Mumbai

On-site
INR 300,000 - 500,000
Health insurance
Gratuity payment
Employees' Provident Fund
Security Analyst / Sr. Security Analyst
Security Analyst / Sr. Security Analyst

Nio Stars Technologies LLP • Mumbai

On-site
INR 1,200,000 - 2,400,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Kolkata District

On-site
INR 2,800,000 - 4,000,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Delhi

On-site
INR 1,200,000 - 1,800,000