Application Security Analyst

Zs Associates

Mumbai

Hybrid

INR 900,000 - 1,500,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Zs Associates in Mumbai is seeking an Application Security Analyst to join the Enterprise team. The role involves performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments.

You will review secure code, collaborate with Development and DevSecOps, and use Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, and Postman to identify vulnerabilities at runtime and in source code.

Qualifications

  • Bachelor’s degree in computer science, information systems, or cybersecurity.
  • 0–4 years of penetration testing or application security experience.
  • Must hold OSCP/eWPTx and OSWA/OSWE/CWES/CWEE certifications.
  • Preferred CRTP/ CARTP, CRTE, OSEP, GRTP certifications.
  • Preferred cloud security certifications: AWS CLP, AWS Security Specialty.
  • Self-starter who learns quickly; fluent in English.
  • Client-first mentality and strong work ethic.
  • Collaborative problem-solver.

Responsibilities

  • Perform manual application penetration testing across web, mobile, APIs, and microservices.
  • Conduct secure code reviews and design-level security assessments.
  • Identify and document OWASP Top 10, SANS Top 25 issues and misconfigurations.
  • Provide guidance to junior testers and review outputs.
  • Use Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, and Postman.
  • Ensure high-quality findings with reproducible evidence.
  • Collaborate with developers, QA, and architects to remediate.
  • Support security awareness and incident response activities.

Skills

Penetration testing
Application security
Security testing
Team collaboration
English proficiency

Education

Bachelor's degree in CS/InfoSec
OSCP/eWPTx and OSWA/OSWE/CWES/CWEE certifications
Preferred: CRTP/ CARTP, CRTE, OSEP, GRTP

Tools

Burp Suite Pro
OWASP ZAP
Snyk
Checkmarx
Black Duck
Postman

Job description

What You\'ll Do:

The Application Security Analyst in Enterprise will report to the Application Security Lead



  • Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.

  • Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.

  • Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.

  • Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.

  • Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.

  • Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.

  • Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.

  • Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.

  • Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.


What You\'ll Bring:


  • Bachelor\'s in computer science /management of computer information/information assurance or Cybersecurity

  • 0-4 years of Penetration Testing / Application Security / Offensive Security

  • Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE

  • Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP

  • Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty

  • Must be a self-starter who can learn quickly and independently.

  • Fluency in English

  • Client-first mentality

  • Intense work ethic

  • Collaborative spirit and problem-solving approach

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

Zs Associates • Pune District

On-site
INR 600,000 - 1,000,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Security Lead- Red Teaming and Application Security
Security Lead- Red Teaming and Application Security

Security Brigade • Navi Mumbai

On-site
INR 4,000,000 - 7,000,000