Never miss an opening. Get the daily email.
Daily Tech Jobs India

Product Security Engineer II

Zeta · Hyderabad, India

Verified live on July 30, 2026
By the Daily Tech Jobs desk at munotes.in · Published · About us · Contact
Get every day's jobs where you already are
Zeta
Hyderabad, IndiaFull-time4+ years (2 to 3 in application security)

About this role

This is offensive security work inside a banking platform. Zeta's Product Security team sits in Risk and Compliance, and the posting describes the job as securing mobile and web applications and APIs by breaking and hacking them, then teaching the developer and DevOps teams how to fix what you found. You would run vulnerability assessment and penetration testing across web, mobile, SDK, API and network, join design reviews and threat modelling, do static analysis and code review, and reverse engineer mobile applications. The tooling list is long and specific: Burp Suite, OWASP ZAP, Metasploit, Qualys, Nessus, Snyk, Veracode, Checkmarx, Frida and Objection. Read the experience note below carefully, because this posting states two different experience figures and we have published the higher one.

Who this is for

⚠️ The posting states two different experience floors in the same list: 4 or more years of experience developing large scale internet or SaaS applications, and 2 to 3 years of overall experience as a web or mobile application security engineer or developer. We have published the higher figure rather than the flattering one, but if you have 2 to 3 years of application security behind you, this posting arguably describes you and is worth an application. It also asks for a BE, B.Tech, M.Tech or ME in computer science or equivalent, and specifies a Tier 1 engineering college or university, which is a real eligibility filter rather than a preference.

The skills the posting lists: hands on VA and PT experience across web, mobile, SDK, API and network. Thorough understanding of the OWASP Top 10 and their attack and defence mechanisms. Exposure to secure SDLC, threat modelling and secure coding. Commercial and open source tooling including Burp Suite, AppScan, OWASP ZAP, BEEF, Metasploit, Qualys, Nessus and Snyk. Identifying and exploiting business logic vulnerabilities. Cryptography, PKI based systems and TLS. Authentication and authorisation frameworks including OIDC, OAuth and SAML, with the ability to read and write Java. Static analysis and code review with Snyk, Veracode, Checkmarx or SonarQube. Reversing mobile applications with Dex2jar, adb, Drozer, Clang and iMAS, and dynamic instrumentation with Frida or Objection. Penetration testing on internal and external networks, Windows, Linux and AWS infrastructure. Shell scripting or automation in Python or Ruby. Knowledge of PCI DSS, PCI SSF, UIDAI, GDPR and NIST. Java frameworks including Spring Boot, plus CI and CD and Jenkins. Cloudflare WAF rule tuning, traffic and event monitoring, and bot traffic analysis. The posting also states you must have participated in bug bounty programmes such as HackerOne or Bugcrowd.

The day to day: guide security and privacy initiatives through design reviews and threat modelling, harden applications built by other teams, and define and hold the scope of security work from project initiation through maintenance. It is explicitly an individual contributor role reporting to a manager.

Location: Hyderabad only. Who should apply: application security engineers with real offensive testing experience and bug bounty history, who can read code rather than only run scanners.
Apply on company site Opens jobs.lever.co, the employer's own application page. Applying is always free.
More roles like this, every day

Every link is checked live before we post it. Get the day's list in your inbox.

Free · one email a day · unsubscribe anytime

More from July 30, 2026

← Back to all jobs