Staff Software Development Engineer (Application Security)

3 Months ago • 7-10 Years • Cyber Security

Job Summary

Job Description

As an Application Security Lead, you'll be responsible for enhancing the security of Zscaler's applications by conducting static and dynamic analysis, managing open-source components, detecting and remediating vulnerabilities, securing containerized environments and infrastructure as code deployments, and improving secret management practices. You'll collaborate closely with development teams to implement security best practices and ensure the overall security of our platform.
Must have:
  • 7+ years of hands-on experience in application security
  • Proficiency with SAST, DAST, and SCA tools
  • Expertise in secure coding practices, vulnerability management, and remediation
  • Experience with source control (Github, Bitbucket) and CI pipelines
Good to have:
  • 3+ years of experience in SAST, DAST, Container Security, IAC, or Secrets Management
  • Experience as a software developer or in a DevSecOps role
  • Proficiency in languages like Java, Python, JavaScript, C/C++, and Golang
  • Experience securing cloud environments (AWS, Azure, Google Cloud)
Perks:
  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks

Job Details

About Zscaler

Serving thousands of enterprise customers around the world including 40% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. 

Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. 

Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

We're looking for an experienced Application Security Lead to join our Product Security team. Reporting to the Director of Vulnerability Management, you'll be responsible for:

  • Static and Dynamic Application Security Testing (SAST/DAST): Conduct static and dynamic analysis of our applications to identify and improve security vulnerabilities early in the development process.
  • Software Composition Analysis (SCA): Implement SCA tools to manage open-source components, ensuring that all third-party libraries and frameworks used in our codebase are secure and up-to-date.
  • CVE Detection and Remediation: monitor for Common Vulnerabilities and Exposures (CVEs) in our code, and work with development teams to fix these vulnerabilities promptly to prevent potential exploits.
  • Secret Management: Detect and improve hard-coded secrets in our codebase, ensuring that sensitive information such as API keys and passwords are securely managed and stored.
  • Container and Infrastructure as Code (IAC) Security: Assess and secure our containerized environments and IAC deployments, ensuring that security best practices are followed to protect our infrastructure from potential threats.

Job Location - Bangalore

What We're Looking for (Minimum Qualifications)

  • Application Security Expertise. Minimum of 7 years of hands-on experience in application security, including implementing and managing security measures such as SAST, DAST, and SCA.
  • Tools. Proficiency with application security tools such as Snyk, Semgrep, Coverity, Checkmarx, Burp Suite, OWASP ZAP, and dependency management tools.
  • Secure Software Development Lifecycle. Experience with secure coding practices, vulnerability management, and remediation techniques. Expertise with source control (Github, Bitbucket), and CI pipelines (ArgoCD, Jenkins).
  • CVE/CWE Lifecycle. Experience detecting and remediating security issues within codebases, ensuring vulnerability management.

What Will Make You Stand Out (Preferred Qualifications)

  • Domain Expertise. Minimum of 3 years of hands-on experience in at least one of the following areas of operations: 1. SAST, including implementing language-specific detection rules and driving remediation of static analysis reports. 2. DAST, including understanding of web application architecture, common web vulnerabilities, and interpret the results of dynamic testing. 3. Container Security, including understanding of containerization concepts, orchestration platforms (Kubernetes), security best practices, and supervising secure container lifecycle processes. 4. IAC, including hands-on expertise with cloud infrastructure design, provisioning, and management, and best practices for writing secure and maintainable infrastructure code. 5. Secrets, including implementing detection rules for secrets in source control, SaaS apps, infrastructure platforms and driving best practices for secrets storage and usage.
  • Previous experience as a software developer or in a DevSecOps role, with proficiency in languages such as Java, Python, JavaScript, C/C++, and Golang. Demonstrated experience securing cloud environments (e.g., AWS, Azure, Google Cloud) and familiarity with cloud-native security tools and practices.

#LI-Hybrid

#LI-SK3

At Zscaler, we believe that diversity drives innovation, productivity, and success. We are looking for individuals from all backgrounds and identities to join our team and contribute to our mission to make doing business seamless and secure. We are guided by these principles as we create a representative and impactful team, and a culture where everyone belongs. For more information on our commitments to Diversity, Equity, Inclusion, and Belonging, visit the Corporate Responsibility page of our website.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is proud to be an equal opportunity and affirmative action employer. We celebrate diversity and are committed to creating an inclusive environment for all of our employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status or any other characteristics protected by federal, state, or local laws.

See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules. For additional information about the federal requirements, click here.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Similar Jobs

Axinous - People Consultant

Axinous

San Jose, California, United States (On-Site)
3 Months ago
ION - Senior DevSecOps Engineer, Italy

ION

Pisa, Tuscany, Italy (On-Site)
4 Months ago
eBay - Engineering Manager - Cloud Security

eBay

San Jose, California, United States (Hybrid)
4 Months ago
Axinous - Education Operations Specialist

Axinous

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Google - Strategy and Operations Analyst Lead, Go-To-Market

Google

New York, New York, United States (On-Site)
3 Months ago
Intel Corporation - Government Information Security - Program Manager

Intel Corporation

Hillsboro, Oregon, United States (Hybrid)
3 Months ago
PwC - IN-Associate_IA_Internal Audit Services_Advisory_Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago
Trellix - Senior Product Manager - SIEM

Trellix

Bengaluru, Karnataka, India (On-Site)
4 Months ago
ByteDance - Global SRE Lead, Security Engineering

ByteDance

Singapore (On-Site)
3 Months ago
paypal - MTS 1, Information Security Engineer

paypal

Beijing, Beijing, China (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Axinous - Senior Software Engineer - Risk360

Axinous

San Jose, California, United States (Hybrid)
3 Months ago
Palo Alto Networks - Prisma Cloud Solutions Architect - Healthcare

Palo Alto Networks

San Francisco, California, United States (Remote)
3 Months ago
Google - Workspace Cloud Architect

Google

(On-Site)
3 Months ago
Saviynt - Consultant, Professional Services, IAM/IGA

Saviynt

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Saviynt - Account Executive

Saviynt

Dallas, Texas, United States (Remote)
4 Months ago
Saviynt - Account Executive

Saviynt

Austin, Texas, United States (Remote)
4 Months ago
Saviynt - IAM Technical Architect, Professional Services - New

Saviynt

Atlanta, Georgia, United States (Remote)
4 Months ago
Trend Micro - Inside Regional Account Manager

Trend Micro

North Sydney, New South Wales, Australia (On-Site)
4 Months ago
Palo Alto Networks - Principal Solutions Consultant-iGSI

Palo Alto Networks

Bengaluru, Karnataka, India (Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Luxoft - Lead Java Developer

Luxoft

New Delhi, Delhi, India (Remote)
3 Months ago
DNEG - Editorial Assistant (DNEG Animation)

DNEG

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Nagarro - Staff Engineer, IOT

Nagarro

India (Remote)
4 Months ago
Axinous - Learning Experience Designer (ID)

Axinous

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Tiger Advertising - Social Media Manager

Tiger Advertising

Ahmedabad, Gujarat, India (On-Site)
4 Months ago
PivotRoots - Senior Manager - Paid Media

PivotRoots

Maharashtra, India (On-Site)
4 Months ago
PhonePe - Area Collections Manager - Lending (Multiple Locations)

PhonePe

Bengaluru, Karnataka, India (On-Site)
3 Months ago
IMAGE Creative Education - VFX Artist

IMAGE Creative Education

Hyderabad, Telangana, India (On-Site)
3 Months ago
Laespace Design Studio - Furniture Designer

Laespace Design Studio

Hyderabad, Telangana, India (On-Site)
5 Months ago
PwC - IN_Senior Associate _ Market Risk BA _Captive Financial Services_Advisory_Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ION - Intermediate IT Auditor, Italy

ION

Collecchio, Emilia-Romagna, Italy (On-Site)
4 Months ago
Zelis - Sr Soc Threat Analyst - Tier3

Zelis

Hyderabad, Telangana, India (On-Site)
3 Months ago
CloudLinux - Senior Go Developer for Imunify (worldwide remote)

CloudLinux

Vojvodina, Serbia (Remote)
3 Months ago
PwC - IN_Manager_Tech Lead_SFDC_Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Western Digital - Manager, Security

Western Digital

Bengaluru, Karnataka, India (On-Site)
5 Months ago
ByteDance - Senior Product Manager - Cloud Security

ByteDance

Singapore (On-Site)
3 Months ago
DNEG - Chief Information Security Officer

DNEG

(Hybrid)
5 Months ago
Trend Micro - (Sr.) Software Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
Playtech - T1 Security Analyst

Playtech

(On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Axonius gives customers the confidence to control complexity by mitigating threats, navigating risk, automating response actions, and informing business-level strategy. With solutions for both cyber asset attack surface management (CAASM) and SaaS management, Axonius is deployed in minutes and integrates with hundreds of data sources to provide a comprehensive asset inventory, uncover gaps, and automatically validate and enforce policies. Cited as one of the fastest-growing cybersecurity startups, with accolades from CNBC, Forbes, and Fortune, Axonius covers millions of assets, including devices and cloud assets, user accounts, and SaaS applications, for customers around the world. For more, visit Axonius.com.

View All Jobs

Get notified when new jobs are added by Axinous

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug