…

Application Security Analyst

ZS Associates · Consulting & Professional Services

  • Pune, India
  • On-site
  • Posted 18 days ago
  • Cybersecurity

About the job

What You'll Do: The Application Security Analyst  in  Enterprise  will report to the Application Security Lead

Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.

What You'll Bring:

Bachelor’s in computer science /management of computer information/information assurance or Cybersecurity
0-4 years of Penetration Testing / Application Security / Offensive Security
Must have Security Certifications:  OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
Must  be a self-starter who can learn quickly and independently.
Fluency in English
Client-first mentality
Intense work ethic
Collaborative spirit and problem-solving approach

Responsibilities

What You'll Do: The Application Security Analyst in Enterprise will report to the Application Security Lead

Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.

What You'll Bring:

Bachelor’s in computer science /management of computer information/information assurance or Cybersecurity
0-4 years of Penetration Testing / Application Security / Offensive Security
Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
Must be a self-starter who can learn quickly and independently.
Fluency in English
Client-first mentality
Intense work ethic
Collaborative spirit and problem-solving approach