Talent.com
This job offer is not available in your country.
Application Security Specialist

Application Security Specialist

ZSpune, India
5 hours ago
Job description

ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, our most valuable asset is our people. Here you’ll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning; bold ideas; courage and passion to drive life-changing impact to ZS.

Our most valuable asset is our people .

At ZS we honor the visible and invisible elements of our identities, personal experiences and belief systems—the ones that comprise us as individuals, shape who we are and make us unique. We believe your personal interests, identities, and desire to learn are part of your success here. about our diversity, equity, and inclusion efforts and the networks ZS supports to assist our ZSers in cultivating community spaces, obtaining the resources they need to thrive, and sharing the messages they are passionate about.

Application Security Specialist

We are seeking an experienced professional to join us as an Application Security Specialist in our Pune, India office. This professional will be responsible for Implementing DevSecOps Practices across cloud environments & mature ZS’s Application Security Program. This role requires strategic and out-of-box thinking, high technical expertise, and effective communication skills to proactively identify and address security risks.

What you'll do :

  • Lead the design and implementation of DevSecOps framework, integrating security seamlessly into CI / CD pipelines across multiple environments and platforms.
  • Collaborate with developers, SREs, and security teams to embed security controls and testing at build, deployment, and runtime stages.
  • Build and manage automation for SAST, DAST, SCA, container security, and IaC scanning tools (e.g., SonarQube, Checkmarx, Snyk, Trivy, Terraform Scan).
  • Analyze results from SAST, SCA, and DAST scans to validate findings, eliminate false positives, and work with development teams to prioritize and remediate security issues.
  • Leverage expertise in TeamCity and AWS to build secure, scalable CI / CD pipelines and enforce security controls throughout the software delivery lifecycle
  • Champion “shift-left” security practices by developing reusable pipelines, templates, and toolchains that promote secure coding and rapid feedback loops.
  • Ensure ongoing visibility and reporting of security posture in cloud-native workloads, container platforms, and serverless environments.
  • Lead training sessions and build developer-friendly resources to raise DevSecOps awareness across engineering teams.
  • Stay current with evolving tools, threats, and best practices in secure software delivery, continuously innovating to improve security effectiveness and developer experience.
  • Partner with product owners, developers, architects, and QA engineers to build secure-by-design applications.
  • Provide mentorship and security guidance to internal stakeholders to raise overall security maturity.
  • Collaborate closely with Application Security teams to align on secure development standards, threat modeling efforts, and triaging complex vulnerabilities identified during code and runtime analysis.

What you'll bring :

  • Expertise in implementing DevSecOps practices in cloud-native CI / CD pipelines (e.g., GitLab CI, GitHub Actions, Jenkins, TeamCity, Azure DevOps, Bit-Bucket).
  • Strong hands-on experience with application security tools such as SonarQube, Fortify, Checkmarx, Snyk, Veracode, BlackDuck, Burp Suite, OWASP ZAP.
  • Knowledge of containerization and orchestration security (Docker, Kubernetes, Helm) and tools like Trivy, Kube-bench, and Aqua.
  • Working knowledge of programming / scripting languages like Python, Java, JavaScript, C#, .Net or go.
  • Familiarity with cloud-native security controls (AWS Security Hub, Azure Defender, GCP Security Command Center).
  • Strong scripting skills in Python, Bash, or PowerShell for automation and tool integration.
  • Ability to develop and enforce security guardrails, policies, and standards in automated and scalable ways.
  • In-depth understanding of OWASP, CWE, CVE scoring, and secure SDLC methodologies.
  • Ability to clearly document findings and communicate risk effectively to technical and non-technical stakeholders.
  • Strong Collaboration, Communication and Interpersonal skills with the ability to collaborate effectively with cross-functional teams, communicate complex technical concepts to non-technical stakeholders, and build consensus around security initiatives.
  • Good to have skills and abilities :

  • Knowledge of policy-as-code frameworks (e.g., OPA / Gatekeeper, Sentinel).
  • Familiarity with DevSecOps Maturity Models and experience driving measurable security improvements across teams.
  • Exposure to compliance automation for frameworks such as SOC 2, HIPAA, GDPR.
  • Experience in chaos engineering, resilience testing, or runtime application self-protection (RASP).
  • Experience with Infrastructure as Code (IaC) security using Terraform, CloudFormation, and tools like tfsec or Checkov.
  • Experience and expertise in application penetration testing, including business logic abuse, authentication / authorization flaws, and client-side vulnerabilities
  • Familiarity with common reconnaissance, exploitation, and post exploitation techniques.
  • Experience in API security testing, including assessment of REST and GraphQL endpoints for issues such as broken object-level authorization (BOLA), mass assignment, injection flaws, and improper rate limiting.
  • Academic Qualifications :

  • Bachelor’s in computer science / management of computer information / information assurance or Cybersecurity
  • 6+ years of DevSecOps / Secure DevOps / Security Engineer / Application & Cloud Security roles
  • Must have Certifications : OSWE / CSSLP / AWS Certified Solutions Architect / AWS Security Specialty
  • Preferred Certifications : AWS CLP, GIAC (GCSA), GIAC (GWAPT), OSCP, OSWA, OSEP, eWPTX
  • Perks & Benefits :

    ZS offers a comprehensive total rewards package including health and well-being, financial planning, annual leave, personal growth and professional development. Our robust skills development programs, multiple career progression options and internal mobility paths and collaborative culture empowers you to thrive as an individual and global team member. We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients / ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.

    Travel :

    Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.

    Create a job alert for this search

    Application Specialist • pune, India

    Related jobs
    • Promoted
    Senior Application Security Specialist

    Senior Application Security Specialist

    YASH Technologiespune, maharashtra, in
    Must to Have Responsibilities : .Should be able to understand and articulate technical aspects clearly.Understand cloud development processes and provide security support throughout,.Hands-on with at...Show moreLast updated: 8 days ago
    • Promoted
    • New!
    Security Analyst

    Security Analyst

    Radical Technologiespune, India
    We are looking for a Security Analyst to join our Security Operations Center (SOC) team.The ideal candidate will be responsible for continuously monitoring security alerts and incidents using Micro...Show moreLast updated: 5 hours ago
    • Promoted
    • New!
    Qualys - Web Application Security Analyst - DAST Tools

    Qualys - Web Application Security Analyst - DAST Tools

    QUALYS SECURITY TECHSERVICES PRIVATE LIMITEDPune
    Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!.Appsec team in Qualys looking for web application security to be part of Applica...Show moreLast updated: 20 hours ago
    • Promoted
    TripleLift - Senior Application Security Engineer - NIST

    TripleLift - Senior Application Security Engineer - NIST

    TripleLiftPune
    About TripleLift : We're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actiona...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Architect - AWS

    Application Security Architect - AWS

    NPG ConsultantsPune
    Lead secure-by-design initiatives for AWS-hosted applications.Combine AppSec expertise with hands-on development and cloud-native architecture to enable scalable security design patterns, proactive...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Testing (Pune)

    Application Security Testing (Pune)

    DigiHelic Solutions Pvt. Ltd.Pune, Maharashtra, India
    Job Title-Application Security Testing.Hands on experience with Application Security solutions (SAST, SCA, IAST, DAST, API), Penetration testing, and vulnerability analysis.Hands on experience with...Show moreLast updated: 1 day ago
    • Promoted
    Senior Application Security Consultant

    Senior Application Security Consultant

    YASH TechnologiesPune, Maharashtra, India
    Should be able to understand and articulate technical aspects clearly.Understand cloud development processes and provide security support throughout,. Hands-on with at least two tools like Nessus Pr...Show moreLast updated: 7 days ago
    • Promoted
    • New!
    Application Security Engineer

    Application Security Engineer

    emersonpune, India
    In this Role, Your Responsibilities Will Be : .Analysis of UML diagrams and DFDs / Threat Models for security flaws and detailing specific recommendations in software and system setup to address them.M...Show moreLast updated: 5 hours ago
    • Promoted
    SAP Security Specialist (WFH - Contract)

    SAP Security Specialist (WFH - Contract)

    DSAPRO IT Private Limitedpune, maharashtra, in
    Remote
    We have a SAP Security Specialist position (Contract - Work-from-Home) for one of our clients who is a niche US product company. Design, implement, and maintain SAP security roles and authorizations...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    Application Security Engineer

    Application Security Engineer

    Copelandpune, India
    In this Role, Your Responsibilities Will Be : .Analysis of UML diagrams and DFDs / Threat Models for security flaws and detailing specific recommendations in software and system setup to address them.M...Show moreLast updated: 5 hours ago
    • Promoted
    • New!
    Web Application Security Analyst

    Web Application Security Analyst

    Qualyspune, India
    Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!.Appsec team in Qualys looking for web application security to be part of Applica...Show moreLast updated: 5 hours ago
    • Promoted
    Application Security Consultant

    Application Security Consultant

    YASH Technologiespune, maharashtra, in
    Must to Have Responsibilities : .Should be able to understand and articulate technical aspects clearly.Understand cloud development processes and provide security support throughout,.Hands-on with at...Show moreLast updated: 8 days ago
    • Promoted
    Web Application Specialist

    Web Application Specialist

    ITC Infotechpune, maharashtra, in
    ITCI Cyber Security team is looking for the role who is operational excellence and strategic configuration of Cloudflare WAF, focused on protecting public-facing web assets.The individual will ensu...Show moreLast updated: 15 days ago
    • Promoted
    • New!
    Senior Application Security, Actimize

    Senior Application Security, Actimize

    NICEpune, India
    At NiCE, we don’t limit our challenges.We set the highest standards and execute beyond them.And if you’re like us, we can offer you the ultimate career opportunity that will light a fire within you...Show moreLast updated: 5 hours ago
    • Promoted
    • New!
    Application Security Analyst

    Application Security Analyst

    0548 Varian Medical Systems Int’l (India) Pvt Ltdpune, India
    At Varian, a Siemens Healthineers Company, we bring together the world's best talent to realize our vision of a world without fear of cancer. Together, we work passionately to develop and deliver ea...Show moreLast updated: 5 hours ago
    • Promoted
    • New!
    Team Lead - Application Security

    Team Lead - Application Security

    METRO LOGISTICSpune, India
    Metro Global Solution Center (MGSC) is internal solution partner for METRO, a € Billion international wholesaler with operations in 31 countries through 625 stores & a team of 93,000 people globall...Show moreLast updated: 5 hours ago
    • Promoted
    Application Security Engineer - Vulnerability Management

    Application Security Engineer - Vulnerability Management

    ETENICO RECRUITSPune
    Job Responsibilities : - Read / learn / discuss latest trends / tools / best practices / updates of cyber security, application development, and cloud services industries.Perfo...Show moreLast updated: 29 days ago
    • Promoted
    Urbint - Application Security Engineer II

    Urbint - Application Security Engineer II

    UrbintPune
    Job Summary : We are seeking an Application Security Engineer-II to help embed security within Urbints software developm...Show moreLast updated: 28 days ago