[ref. a22411518] Staff Application Security Engineer - Bangalore

apartmentZscaler placeBangalore calendar_month 

Job Description

About Zscaler:

Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries.

Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

About the Role:

We're looking for an experienced Application Security Lead to join our Product Security team. Reporting to the Director of Vulnerability Management, you'll be responsible for:

  • Static and Dynamic Application Security Testing (SAST/DAST): Conduct static and dynamic analysis of our applications to identify and improve security vulnerabilities early in the development process.
  • Software Composition Analysis (SCA): Implement SCA tools to manage open-source components, ensuring that all third-party libraries and frameworks used in our codebase are secure and up-to-date.
  • CVE Detection and Remediation: monitor for Common Vulnerabilities and Exposures (CVEs) in our code, and work with development teams to fix these vulnerabilities promptly to prevent potential exploits.
  • Secret Management: Detect and improve hard-coded secrets in our codebase, ensuring that sensitive information such as API keys and passwords are securely managed and stored.
  • Container and Infrastructure as Code (IAC) Security: Assess and secure our containerized environments and IAC deployments, ensuring that security best practices are followed to protect our infrastructure from potential threats.
What We're Looking for (Minimum Qualifications)
  • Application Security Expertise. Minimum of 6+ years of hands-on experience in application security, including implementing and managing security measures such as SAST, DAST, and SCA.
  • Tools. Proficiency with application security tools such as Snyk, Semgrep, Coverity, Checkmarx, Burp Suite, OWASP ZAP, and dependency management tools.
  • Secure Software Development Lifecycle. Experience with secure coding practices, vulnerability management, and remediation techniques. Expertise with source control (Github, Bitbucket), and CI pipelines (ArgoCD, Jenkins).
  • CVE/CWE Lifecycle. Experience detecting and remediating security issues within codebases, ensuring vulnerability management.
What Will Make You Stand Out (Preferred Qualifications)
  • Domain Expertise. Hands-on experience in at least one of the following areas of operations: 1. SAST, including implementing language-specific detection rules and driving remediation of static analysis reports. 2. DAST, including understanding of web application architecture, common web vulnerabilities, and interpret the results of dynamic testing. 3. Container Security, including understanding of containerization concepts, orchestration platforms (Kubernetes), security best practices, and supervising secure container lifecycle processes. 4. IAC, including hands-on expertise with cloud infrastructure design, provisioning, and management, and best practices for writing secure and maintainable infrastructure code. 5. Secrets, including implementing detection rules for secrets in source control, SaaS apps, infrastructure platforms and driving best practices for secrets storage and usage.
  • Previous experience as a software developer or in a DevSecOps role, with proficiency in languages such as Java, Python, JavaScript, C/C++, and Golang. Demonstrated experience securing cloud environments (e.g., AWS, Azure, Google Cloud) and familiarity with cloud-native security tools and practices.
local_fire_departmentUrgent

IT Application Security Engineer

placeBangalore
Responsibilities: Position Purpose: The Application Security Engineer will collaborate closely with development, operations, and cloud infrastructure teams to implement robust security controls throughout StoneX’s cloud environments, containerized applications...
electric_boltImmediate start

Sr Network Security Engineer

placeBangalore
Responsibilities: Finastra is currently seeking a Senior Network Security Engineer, to join our amazing network team. Reporting to Senior Director, Network Engineering and Implementation, this position is responsible for network security...
apartmentAmazonplaceBangalore
across numerous countries and payment methods. Paramount to our success is ensuring that our customer data is secure. As an application security engineer within India Payments Security, you will partner with engineering teams in a consulting facility...