Staff Application Security Engineer

2 Months ago • 4 Years + • Cyber Security

Job Summary

Job Description

The Staff Application Security Engineer will be responsible for conducting thorough static and dynamic analysis of applications, implementing SCA tools for open-source components, and assessing/securing containerized environments and IAC deployments. This role requires expertise in application security, secure coding practices, vulnerability management, and experience with various security tools. The engineer will identify and address security vulnerabilities within codebases. This role involves collaboration with the Product Security team and reporting to the Director of Vulnerability Management.
Must have:
  • Expertise in Application Security with over 4 years of experience.
  • Proficiency with application security tools like Snyk, Semgrep, etc.
  • Strong understanding of secure coding practices and vulnerability management.
  • Experience in identifying and addressing security vulnerabilities.
Good to have:
  • Experience as a software developer or within a DevSecOps position.
  • Extensive experience in Cloud Security.
Perks:
  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Job Details

About Zscaler

Serving thousands of enterprise customers around the world including 40% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform, which is found in our SASE and SSE offerings, protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. 

Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

We're looking for an experienced Staff Application Security Engineer for our Product Security team. Reporting to the Director of Vulnerability Management, you'll be responsible for:

  • Conducting thorough static and dynamic analysis of our applications to identify and remediate security vulnerabilities early in the development process (SAST/DAST)
  • Implementing SCA tools to identify and manage open-source components, ensuring that all third-party libraries and frameworks used in our codebase are secure and up-to-date (Software Composition Analysis)
  • Assessing and securing our containerized environments and IAC deployments, ensuring that security best practices are followed to protect our infrastructure from potential threats (Container and Infrastructure as Code Security)

What We're Looking for (Minimum Qualifications)

  • Expertise in Application Security, encompassing over 4 years of hands-on experience in deploying and overseeing security protocols like Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA), or Infrastructure as Code (IaC)
  • Proficiency with application security tools such as Snyk, Semgrep, Coverity, Checkmarx, Burp Suite, OWASP ZAP, and dependency management tools
  • Strong understanding of secure coding practices, vulnerability management, and remediation techniques with expertise in source control (Github, Bitbucket), and CI pipelines (ArgoCD, Jenkins)
  • Experience in identifying and addressing security vulnerabilities within codebases, ensuring prompt and efficient management throughout the CVE/CWE lifecycle

What Will Make You Stand Out (Preferred Qualifications)

  • Experience as a software developer or within a DevSecOps position, with proficiency in programming languages such as Java, Python, JavaScript, C/C++, and Golang
  • Extensive experience in Cloud Security, adept at securing cloud environments including AWS, Azure, and Google Cloud, with comprehensive knowledge of cloud-native security tools and methodologies

#LI-Hybrid

#LI-GL2

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws.

See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Similar Jobs

Qualcomm - Engineer - Debugging

Qualcomm

Hyderabad, Telangana, India (On-Site)
2 Months ago
Wolters Kluwer - Senior Software Test Automation Engineer

Wolters Kluwer

Pune, Maharashtra, India (Hybrid)
2 Days ago
Qualcomm - Staff Engineer, Machine Learning Engineering

Qualcomm

San Diego, California, United States (On-Site)
2 Months ago
ShyftLabs - Lead Automation Architect SDET

ShyftLabs

Noida, Uttar Pradesh, India (Hybrid)
1 Week ago
Nice - Mid-Level Software Engineer (AWS, GO)

Nice

Sandy, Utah, United States (On-Site)
1 Month ago
Alation - Cybersecurity Engineer

Alation

Chennai, Tamil Nadu, India (Hybrid)
6 Days ago
Adtran - IT Security Administrator

Adtran

Gdynia, Pomeranian Voivodeship, Poland (Hybrid)
1 Year ago
Jane Street - Physical Security Systems Engineer

Jane Street

New York, United States (On-Site)
2 Months ago
Perplexity - Cloud Security Engineer

Perplexity

California, United States (On-Site)
1 Month ago
OKX - Head of Cybersecurity Audit

OKX

San Jose, California, United States (On-Site)
1 Week ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

ShyftLabs - QA Engineer

ShyftLabs

Noida, Uttar Pradesh, India (On-Site)
2 Weeks ago
Unity - DevOps Tech Lead

Unity

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
2 Months ago
Synechron - Jr Developer Java (Developer)

Synechron

Montreal, Quebec, Canada (On-Site)
1 Month ago
Illumina - Software Engineer 2 - Java Developer

Illumina

Mechelen, Flanders, Belgium (Hybrid)
1 Month ago
Hawkeye Innovations - Frontend Test Automation Engineer

Hawkeye Innovations

Basingstoke, England, United Kingdom (Hybrid)
3 Months ago
ShyftLabs - Cloud Engineer

ShyftLabs

Atlanta, Georgia, United States (Hybrid)
1 Week ago
hogarth - Studio Production Artist

hogarth

Shanghai, China (On-Site)
1 Month ago
London stock Exchange - Senior DevOps Engineer

London stock Exchange

Bucharest, Bucharest, Romania (On-Site)
1 Week ago
Intergalactic Gaming - Front-end Developer

Intergalactic Gaming

Manchester, England, United Kingdom (On-Site)
1 Year ago
Next Level Business Services - Java Developer with Oracle SOA

Next Level Business Services

Cincinnati, Ohio, United States (On-Site)
9 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Sprinkler - Senior Implementation Consultant

Sprinkler

Gurugram, Haryana, India (On-Site)
2 Months ago
Applied materials  - Mechanical Design Engineer

Applied materials

Bengaluru, Karnataka, India (On-Site)
2 Months ago
London stock Exchange - Senior Business Analyst - Performance Management

London stock Exchange

Bengaluru, Karnataka, India (Hybrid)
1 Year ago
cyara - Software Development Engineer In Test

cyara

Hyderabad, Telangana, India (Hybrid)
2 Months ago
Qualcomm - Linux BSP / QNX Platform Staff Engineer

Qualcomm

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Enphase Energy - Engineer - Customer Service Spanish

Enphase Energy

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Capgemini - Mechanical & Physical Engineer

Capgemini

Pune, Maharashtra, India (On-Site)
1 Month ago
Spaulding Ridge - Salesforce SPIFF Implementation Specialist

Spaulding Ridge

Jaipur, Rajasthan, India (On-Site)
1 Month ago
Qualcomm - Engineer - C#, Angular

Qualcomm

Hyderabad, Telangana, India (On-Site)
1 Month ago
Axi - DevOps Engineer

Axi

Bengaluru, Karnataka, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

smarsh - Lead Security Operations Analyst

smarsh

India (Hybrid)
1 Month ago
laika games - Application Security Engineer

laika games

Hillsboro, Oregon, United States (On-Site)
1 Week ago
GoDaddy - Principal Security Engineer

GoDaddy

India (Remote)
1 Week ago
Rocket studio - Senior/Expert Security Specialist (IT)

Rocket studio

Warsaw, Masovian Voivodeship, Poland (Hybrid)
2 Months ago
Cadence - Sr. Software Security Engineer

Cadence

Cork, County Cork, Ireland (On-Site)
1 Month ago
Jane Street - Network Engineer, Security

Jane Street

London, England, United Kingdom (On-Site)
1 Week ago
Zscaler - Senior Devops Engineer (Terraform/Security Solutions)

Zscaler

Bengaluru, Karnataka, India (Hybrid)
2 Months ago
Apple - Security Compliance Engineer - Knowledge Management

Apple

Cupertino, California, United States (On-Site)
1 Month ago
Microsoft - Technical Support Engineer - Security & Compliance

Microsoft

(On-Site)
2 Months ago
Tide - Staff Security Engineer, Identity

Tide

Hyderabad, Telangana, India (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Zscaler enables the world’s leading organizations to securely transform their networks and applications for a mobile and cloud first world. Its flagship services, Zscaler Internet Access and Zscaler Private Access, create fast, secure connections between users and applications, regardless of device, location, or network. Zscaler services are 100% cloud-delivered and offer the simplicity, enhanced security, and improved user experience that traditional appliances or hybrid solutions are unable to match. Used in more than 185 countries, Zscaler operates the world’s largest cloud security platform, protecting thousands of enterprises and government agencies from cyberattacks and data loss.



Stay Connected:

LinkedIn: https://www.linkedin.com/company/zscaler

Twitter: https://www.twitter.com/zscaler

Facebook: https://www.facebook.com/Zscaler/

Bellevue, Washington, United States (On-Site)

Hyderabad, Telangana, India (Hybrid)

Hyderabad, Telangana, India (Hybrid)

San Jose, California, United States (On-Site)

Madrid, Community Of Madrid, Spain (Remote)

San Jose, California, United States (Hybrid)

Bengaluru, Karnataka, India (Hybrid)

San Jose, California, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by Zscaler

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug