Talent.com
This job offer is not available in your country.
Manager - Application & Product Security

Manager - Application & Product Security

Zeta Services Inc.Hyderabad, Telangana, India
15 hours ago
Job description

About Zeta Zeta is a Next-Gen Banking Tech company that empowers banks and fintechs to launch banking products for the future. It was founded by and Ramki Gaddipati in 2015. Our flagship processing platform - Zeta Tachyon - is the industry’s first modern, cloud-native, and fully API-enabled stack that brings together issuance, processing, lending, core banking, fraud & risk, and many more capabilities as a single-vendor stack. 15M+ cards have been issued on our platform globally. Zeta is actively working with the largest Banks and Fintechs in multiple global markets transforming customer experience for multi-million card portfolios. Zeta has over 1700+employees - with over 70%roles in R&D - across locations in the US,EMEA, and Asia. We raised$280 million at billion valuation from Softbank, Mastercard, and other investors in more @,,, The Role As part of the Risk & Compliance team within the Engineering division at Zeta, the Application Security Manager is tasked with safeguarding all mobile, web applications, and APIs. This involves identifying vulnerabilities through testing and ethical hacking, while also educating developers and DevOps teams on how to resolve them. Your primary goal will be to ensure the security of Zeta's applications and platforms. As a manager, you'llbe responsible for securing all of Zeta’s products. In this individual contributor role, you will report directly to the Chief Information Security Officer (CISO). The role involves ensuring the security of web and mobile applications, APIs, and infrastructure by conducting regular VAPT. It requires providing expert guidance to developers on how to address and fix security vulnerabilities, along with performing code reviews to identify potential security issues. The role also includes actively participating in application design discussions to ensure security is integrated from the beginning and leading Threat Modeling exercises to identify potential threats. Additionally, the profile focuses on developing and promoting secure coding practices, educating developers and QA engineers on security standards for secure coding, data handling, network security, and encryption. The role also entails evaluating and integrating security testing tools like SAST, DAST, and SCA into the CI / CD pipeline to enhance continuous security integration.

Responsibilities

  • Guide Security and Privacy Initiatives : Actively participate in design reviews and threat modeling sessions to help shape the security and privacy approach for technology projects, ensuring security is embedded at all stages of application development.
  • Ensure Secure Application Development : Collaborate with developers and product managers to ensure that applications are securely developed, hardened, and aligned with industry best practices.
  • Project Scope Management : Define the scope for security initiatives, ensuring continuous adherence throughout each project phase, from initiation to sustenance / maintenance.
  • Drive Internal Adoption and Visibility : Ensure that security projects are well-understood and adopted by internal stakeholders, fostering a culture of security awareness within the organization.
  • Security Engineering Expertise : Serve as a technical expert and security champion within Zeta, providing guidance and expertise on security best practices across the organization.
  • Team Leadership and Development
  • Make decisions on hiring and lead the hiring process to build a skilled security team.
  • Define and drive improvements in the hiring process to attract top security talent.
  • Mentor and guide developers and QA teams on secure coding practices and security awareness.
  • Security Tool and Gap Assessment : Continuously assess and recommend tools to address gaps in application security, ensuring the team is equipped with the best resources to identify and address vulnerabilities.
  • Stakeholder Liaison : Collaborate with both internal and external stakeholders to ensure alignment on security requirements and deliverables, acting as the main point of contact for all security-related matters within the team.
  • Bug Bounty Program Management : Evaluate and triage security bugs reported through the Bug Bounty program, working with relevant teams to address and resolve issues effectively.
  • Own Security Posture : Take ownership of the security posture of various applications across the business units, ensuring that security best practices are consistently applied and maintained.

Skills

  • Hands-on experience in Vulnerability Assessment (VA) and Penetration Testing (PT) across web, mobile, API, and network / Infra environments.
  • Deep understanding of the OWASP Top 10 and their respective attack and defense mechanisms.
  • Strong exposure to Secure SDLC activities, Threat Modeling , and Secure Coding practices.
  • Experience with both commercial and open-source security tools, including Burp Suite , AppScan , OWASP ZAP , BEEF , Metasploit , Qualys , Nipper , Nessus andSnyk .
  • Expertise in identifying and exploiting business logic vulnerabilities .
  • Solid understanding of cryptography , PKI-based systems, and TLS protocols.
  • Proficiency in various AuthN / AuthZ frameworks (OIDC, OAuth, SAML) and the ability to read, write, and understand Java code.
  • Experience with Static Analysis and Code Reviews using tools like Snyk , Fortify , Veracode , Checkmarx , and SonarQube .
  • Hands-on experience in reverse engineering mobile apps and using tools like Dex2jar , ADB , Drozer , Clang , iMAS , and Frida / Objection for dynamic instrumentation.
  • Experience conducting penetration tests and security assessments on internal / external networks, Windows / Linux environments, and cloud infrastructure (primarily AWS).
  • Ability to identify and exploit security vulnerabilities and misconfigurations in Windows and Linux servers .
  • Proficiency in shell scripting and automating tasks with tools such as Python or Ruby .
  • Familiarity with PA-DSS , PCI SSF (S3, SSLC), and other security standards like PCI DSS , DPSC, ASVS and NIST .
  • Understanding of Java frameworks like Spring Boot , CI / CD processes, and tools like Jenkins & Bitrise.
  • In-depth knowledge of cloud infrastructure (AWS, Azure), including VPC / VNet, S3 buckets, IAM,Security Groups, blob stores, Load Balancers, Docker containers, and Kubernetes .
  • Solid understanding of agile development practices.
  • Active participation in bug bounty programs (HackerOne, Bug Crowd, etc.) and experience with hackathons and Capture the Flag (CTF) competitions.
  • Knowledge of AWS / Azure services , including network configuration and security management.
  • Experience with databases (PostgreSQL, Redshift, MySQL) and other data storage solutions like Elasticsearch and S3 buckets .
  • Preferred Certifications : OSCP, OSWE, GWAPT, AWAE, AWS Certified Security Specialist, CompTIA Security+
  • Experience and Qualifications

  • 12 to 18 years of overall experience in application security, with a strong background in identifying and mitigating vulnerabilities in software applications.
  • A background in development and experience in the fintech sector is a plus.
  • Bachelor of Technology (BE / ), , or ME in Computer Science or an equivalent degree from an Engineering college / University .
  • Life At Zeta At Zeta, we want you to grow to be the best version of yourself by unlocking the great potential that lies within you. This is why our core philosophy is ‘People Must Grow.’ We recognize your aspirations; act as enablers by bringing you the right opportunities, and let you grow as you chase disruptive goals.  #LifeAtZeta is adventurous and exhilarating at the same time. You get to work with some of the best minds in the industry and experience a culture that values the diversity of thoughts. If you want to push boundaries, learn continuously and grow to be the best version of yourself, Zeta is the place to be! Zeta is an equal opportunity employer. At Zeta, we are committed to equal employment opportunities regardless of job history, disability, gender identity, religion, race, marital / parental status, or another special status. We are proud to be an equitable workplace that welcomes individuals from all walks of life if they fit the roles and responsibilities.

    Create a job alert for this search

    Application Security • Hyderabad, Telangana, India

    Related jobs
    Senior Application Security Engineer

    Senior Application Security Engineer

    Practical DevSecOpsHyderabad, India, India
    Remote
    Quick Apply
    Permanent(Full Time / Full-Time).We are seeking an Application Security Engineer to join our team and help maintain, enhance, and develop security training exercises for our renowned DevSecOps, API S...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Application Security Engineer II

    Application Security Engineer II

    Zeta Services Inc.Hyderabad, Telangana, India
    It was founded by and Ramki Gaddipati in 2015.Our flagship processing platform - Zeta Tachyon - is the industry’s first modern, cloud-native, and fully API-enabled stack that brings together issuan...Show moreLast updated: 15 hours ago
    • Promoted
    Assistant Manager - Process - Solar Cell

    Assistant Manager - Process - Solar Cell

    Premier Energies LimitedRangareddy, Telangana, India
    Founded in 1995, Premier Energies is a leading solar cell and module manufacturer based in Telangana, India.We operate advanced facilities with 2 GW cell and 5. GW module capacity, and are expanding...Show moreLast updated: 30+ days ago
    • Promoted
    Engineering Manager - Product Security

    Engineering Manager - Product Security

    MedtronicHyderabad, Telangana, India
    At Medtronic, we are committed to pushing the boundaries of technology to improve healthcare outcomes.We value innovation, collaboration, and diversity, and we believe that together we can change h...Show moreLast updated: 21 days ago
    • Promoted
    • New!
    Senior Cyber Security Application Security Engineer

    Senior Cyber Security Application Security Engineer

    BlackbaudHyderabad, Telangana, India
    We’re hiring on the Blackbaud Application Security team!.As a member of the Cyber Security organization at Blackbaud, the Application Security Engineer is a specialized position that plays a key ro...Show moreLast updated: 15 hours ago
    • Promoted
    • New!
    Application Lead

    Application Lead

    AccentureHyderabad, Telangana, India
    Lead the effort to design, build and configure applications, acting as the primary point of contact.SAP Sales and Distribution (SD). Summary : We are seeking an experienced Global SAP Program Manager...Show moreLast updated: 15 hours ago
    • Promoted
    • New!
    Product Designer

    Product Designer

    ALPLA India Private Ltd.IDA Pashamylaram, Telangana, India
    Product Designer (Executive / Sr Executive).Injection mouldedCaps and Closures (FMCG).Years preferably in FMCG sector.Diploma (NTTF, CIPET) / BE(Mech / Auto). SiemensNX preferred, Creo, SolidWorks, Ca...Show moreLast updated: 15 hours ago
    • Promoted
    Product Security Engineer

    Product Security Engineer

    Horizontal TalentHyderabad, Telangana, India
    We are seeking a skilled and motivated Medical Device Product Security Engineer to join our cross-functional product development team. This role is responsible for ensuring that our medical devices ...Show moreLast updated: 10 days ago
    • Promoted
    Zonal SHE Manager

    Zonal SHE Manager

    United Breweries Ltd.Sangareddy, Telangana, India
    Full time degree in Engineering & technology from a recognized institute.Diploma In Industrial Safety from DISH approved institution is essential. Compliance with Legal Obligations and Company Requi...Show moreLast updated: 6 days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    FoodsmartHyderabad, Telangana, India
    Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians.Our platform is designed to foster healthier food choices, drive lasting behavior c...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Sr Staff Product Security Architect (SSDL)

    Sr Staff Product Security Architect (SSDL)

    ServiceNowHyderabad, Telangana, India
    Product Security is Shifting Everywhere and holistically improving the maturity of the security program.The Secure Software Development Lifecycle (SSDL) team helps the organization measure and impr...Show moreLast updated: 15 hours ago
    • Promoted
    Deputy Manager IT

    Deputy Manager IT

    Premier Energies LimitedRangareddy, Telangana, India
    Founded in 1995, Premier Energies is a leading solar cell and module manufacturer based in Telangana, India.We operate advanced facilities with 2 GW cell and 5. GW module capacity, and are expanding...Show moreLast updated: 6 days ago
    • Promoted
    • New!
    Cyber Security / Application Securit...

    Cyber Security / Application Securit...

    Anicalls (Pty) LtdHyderabad, Telangana, India
    Strong in application security, including the ability to perform an independent security review of solution architectures and design appropriate security controls ( Application Vulnerability Assess...Show moreLast updated: 15 hours ago
    • Promoted
    • New!
    Principal Product Security Engineer

    Principal Product Security Engineer

    IN2 COV - COV Engineering Services PLNanakramguda, Telangana, India
    At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovati...Show moreLast updated: 15 hours ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    QualiZealHyderabad, Telangana, India
    Conduct Static Application Security Testing (SAST) and Software Composition Analysis (SCA).Perform Dynamic Application Security Testing (DAST) and Interactive Application Security Testing (IAST) fo...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    NopalCyberHyderabad, Telangana, India
    NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Through Managed Extended Detection and Response (MXDR), Attack Su...Show moreLast updated: 10 days ago
    • Promoted
    • New!
    Application Architect Manager

    Application Architect Manager

    PepsiCoHyderabad, Telangana, India
    The Application Architect will play a pivotal role in software development activities and long-term initiative planning and collaboration across the Strategy & Transformation (S&T) organization.Sof...Show moreLast updated: 15 hours ago
    • Promoted
    • New!
    Application Security Engineer

    Application Security Engineer

    Anicalls (Pty) LtdHyderabad, Telangana, India
    Create and manage bug bounty programs.Evangelize software security best practices.Perform threat modeling, architecture design reviews, and detection capabilities. Develop and implement security too...Show moreLast updated: 15 hours ago