Zeta
About this role
This is offensive security work inside a banking platform. Zeta's Product Security team sits in Risk and Compliance, and the posting describes the job as securing mobile and web applications and APIs by breaking and hacking them, then teaching the developer and DevOps teams how to fix what you found. You would run vulnerability assessment and penetration testing across web, mobile, SDK, API and network, join design reviews and threat modelling, do static analysis and code review, and reverse engineer mobile applications. The tooling list is long and specific: Burp Suite, OWASP ZAP, Metasploit, Qualys, Nessus, Snyk, Veracode, Checkmarx, Frida and Objection. Read the experience note below carefully, because this posting states two different experience figures and we have published the higher one.
Who this is for
⚠️ The posting states two different experience floors in the same list: 4 or more years of experience developing large scale internet or SaaS applications, and 2 to 3 years of overall experience as a web or mobile application security engineer or developer. We have published the higher figure rather than the flattering one, but if you have 2 to 3 years of application security behind you, this posting arguably describes you and is worth an application. It also asks for a BE, B.Tech, M.Tech or ME in computer science or equivalent, and specifies a Tier 1 engineering college or university, which is a real eligibility filter rather than a preference.
The skills the posting lists: hands on VA and PT experience across web, mobile, SDK, API and network. Thorough understanding of the OWASP Top 10 and their attack and defence mechanisms. Exposure to secure SDLC, threat modelling and secure coding. Commercial and open source tooling including Burp Suite, AppScan, OWASP ZAP, BEEF, Metasploit, Qualys, Nessus and Snyk. Identifying and exploiting business logic vulnerabilities. Cryptography, PKI based systems and TLS. Authentication and authorisation frameworks including OIDC, OAuth and SAML, with the ability to read and write Java. Static analysis and code review with Snyk, Veracode, Checkmarx or SonarQube. Reversing mobile applications with Dex2jar, adb, Drozer, Clang and iMAS, and dynamic instrumentation with Frida or Objection. Penetration testing on internal and external networks, Windows, Linux and AWS infrastructure. Shell scripting or automation in Python or Ruby. Knowledge of PCI DSS, PCI SSF, UIDAI, GDPR and NIST. Java frameworks including Spring Boot, plus CI and CD and Jenkins. Cloudflare WAF rule tuning, traffic and event monitoring, and bot traffic analysis. The posting also states you must have participated in bug bounty programmes such as HackerOne or Bugcrowd.
The day to day: guide security and privacy initiatives through design reviews and threat modelling, harden applications built by other teams, and define and hold the scope of security work from project initiation through maintenance. It is explicitly an individual contributor role reporting to a manager.
Location: Hyderabad only. Who should apply: application security engineers with real offensive testing experience and bug bounty history, who can read code rather than only run scanners.
The skills the posting lists: hands on VA and PT experience across web, mobile, SDK, API and network. Thorough understanding of the OWASP Top 10 and their attack and defence mechanisms. Exposure to secure SDLC, threat modelling and secure coding. Commercial and open source tooling including Burp Suite, AppScan, OWASP ZAP, BEEF, Metasploit, Qualys, Nessus and Snyk. Identifying and exploiting business logic vulnerabilities. Cryptography, PKI based systems and TLS. Authentication and authorisation frameworks including OIDC, OAuth and SAML, with the ability to read and write Java. Static analysis and code review with Snyk, Veracode, Checkmarx or SonarQube. Reversing mobile applications with Dex2jar, adb, Drozer, Clang and iMAS, and dynamic instrumentation with Frida or Objection. Penetration testing on internal and external networks, Windows, Linux and AWS infrastructure. Shell scripting or automation in Python or Ruby. Knowledge of PCI DSS, PCI SSF, UIDAI, GDPR and NIST. Java frameworks including Spring Boot, plus CI and CD and Jenkins. Cloudflare WAF rule tuning, traffic and event monitoring, and bot traffic analysis. The posting also states you must have participated in bug bounty programmes such as HackerOne or Bugcrowd.
The day to day: guide security and privacy initiatives through design reviews and threat modelling, harden applications built by other teams, and define and hold the scope of security work from project initiation through maintenance. It is explicitly an individual contributor role reporting to a manager.
Location: Hyderabad only. Who should apply: application security engineers with real offensive testing experience and bug bounty history, who can read code rather than only run scanners.
Apply on company site
Opens jobs.lever.co, the employer's own application page. Applying is always free.