Application Security Analyst

Zs Associates

Pune District

On-site

INR 600,000 - 1,000,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Zs Associates is seeking an Application Security Analyst in Pune to perform manual penetration tests across web, mobile, APIs, and microservices. You will review code, assess security at design level, and guide junior team members while aligning with DevSecOps and development teams.

The role emphasizes hands-on testing, vulnerability validation, and close collaboration with architects and QA to enhance secure coding practices and incident response readiness.

Qualifications

  • Bachelor's degree in CS/Information Assurance/Cybersecurity or related field.
  • 0-4 years of Penetration Testing/Application Security/Offensive Security.
  • Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE.
  • Preferred Certifications: CRTP/CARTP, CRTE, OSEP, GRTP.

Responsibilities

  • Independently perform manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments.
  • Conduct secure code reviews and assist in design-level security assessments with development and DevSecOps teams.
  • Identify, validate, and document vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and insecure coding patterns.
  • Provide technical guidance to junior AppSec testers and review outputs for accuracy and evidence.
  • Utilize tools like Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, and Postman to identify runtime and source-code vulnerabilities.
  • Collaborate with developers, QA, and architects to support remediation and promote secure coding practices.
  • Assist in security awareness for internal stakeholders and support incident response activities when needed.

Skills

Penetration Testing
Application Security
Offensive Security
English Fluency
Self-motivated
Team Collaboration

Education

Bachelor's in Computer Science / Information Assurance / Cybersecurity

Tools

Burp Suite Pro
OWASP ZAP
Snyk
Checkmarx
Black Duck
Postman

Job description

What You'll Do: The Application Security Analyst in Enterprise will report to the Application Security Lead
  • Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
  • Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
  • Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
  • Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
  • Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
  • Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
  • Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
  • Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
  • Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.
What You'll Bring:
  • Bachelor’s in computer science /management of computer information/information assurance or Cybersecurity
  • 0-4 years of Penetration Testing / Application Security / Offensive Security
  • Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
  • Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
  • Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
  • Must be a self-starter who can learn quickly and independently.
  • Fluency in English
  • Client-first mentality
  • Intense work ethic
  • Collaborative spirit and problem-solving approach
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

Zs Associates • Mumbai

Hybrid
INR 900,000 - 1,500,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Penetration Tester
Application Penetration Tester

ControlCase, LLC • Mumbai

On-site
INR 800,000 - 2,000,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000