Application Security Analyst
ZS Pune, Maharashtra, India
Business Consulting and Services · 10,001+ employees
About the role
The Application Security Analyst will perform manual penetration tests on web, mobile, and API environments while conducting secure code reviews. They will also collaborate with development teams to remediate vulnerabilities and provide technical guidance to junior staff.
What they look for
Requirements
Candidates must hold a bachelor's degree in a relevant field and possess 0-4 years of experience in offensive security. Mandatory certifications include OSCP/eWPTx and OSWA/OSWE/CWES/CWEE.
Full description
What You'll Do: The Application Security Analyst in Enterprise will report to the Application Security Lead
- Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
- Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
- Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
- Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
- Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
- Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
- Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
- Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
- Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.
What You'll Bring:
- Bachelor’s in computer science /management of computer information/information assurance or Cybersecurity
- 0-4 years of Penetration Testing / Application Security / Offensive Security
- Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
- Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
- Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
- Must be a self-starter who can learn quickly and independently.
- Fluency in English
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
Similar roles
-
Information Security Engineer — Accreditation of Classified Systems for NATO with security clearance
WLG Brussels, Brussels-Capital, Belgium
-
Cyber Security Engineer — Security Accreditation and Risk Assessment for NATO with security clearance
WLG Brussels, Brussels-Capital, Belgium
-
Agentic Security Engineer
NXP Semiconductors Austin, Texas, United States
-
AI Security Engineer
NXP Semiconductors Austin, Texas, United States
-
AI Application Security Engineer
NXP Semiconductors Austin, Texas, United States
-
Sr. Lead Cybersecurity Analyst, Cybersecurity
Chick-fil-A, Inc. Atlanta, Georgia, United States