Performs manual penetration testing of web, mobile, API, and microservices applications; conducts secure code reviews and design assessments; identifies and validates vulnerabilities; documents findings; supports remediation and incident response; guides junior testers; and promotes secure coding and application security awareness.
What You'll Do: The Application Security Analyst in Enterprise will report to the Application Security Lead
What You'll Bring:
- Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
- Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
- Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
- Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
- Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
- Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
- Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
- Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
- Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.
What You'll Bring:
- Bachelor's in computer science /management of computer information/information assurance or Cybersecurity
- 0-4 years of Penetration Testing / Application Security / Offensive Security
- Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
- Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
- Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
- Must be a self-starter who can learn quickly and independently.
- Fluency in English
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
ZS Pune, Mahārāshtra, IND Office
ZS Pune (International Tech Park) Office




International Tech Park, Panchshil Towers Tower-C, ITPP, Vitthal Nagar, Kharadi, Pune, Maharashtra, India, 412207
ZS Pune, Mahārāshtra, IND Office
ZS Pune (World Trade Center) Office



ZS moved to its state-of-the-art World Trade Center office in 2016. Pune is a leading hub for tech talent in India.
Similar Jobs at ZS
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Manage enterprise macOS endpoints using Jamf Pro, Intune, or other MDM platforms. Responsibilities include configuring policies and compliance settings, packaging and deploying applications and patches, troubleshooting device and software issues, supporting security and lifecycle initiatives, monitoring endpoint health, and maintaining technical documentation.
Top Skills:
BashJamf ProKandjimacOSMicrosoft IntuneMobile Device Management (Mdm)NexthinkWorkspace OneZsh
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Leads large-scale technology consulting and digital transformation programs for Life Sciences clients. Responsibilities include solution strategy, delivery governance, stakeholder management, enterprise data and AI implementations, client advisory, proposal development, account expansion, and global team leadership. The role requires expertise in Databricks or Snowflake, Medallion Architecture, cloud data platforms, Generative AI, Agentic AI, and intelligent automation, along with the ability to connect business strategy to technology execution.
Top Skills:
Advanced AnalyticsAgentic AiCloud-Native Data PlatformsDatabricksGenerative AiIntelligent AutomationLarge Language Models (Llms)Medallion ArchitectureSnowflake
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
The Senior Human Resources Associate leads talent acquisition for enterprise technology roles. Responsibilities include sourcing and screening candidates, managing requisitions and interview logistics, advising hiring managers and senior leaders, building talent pipelines, tracking recruiting metrics, coordinating technical interviews, improving candidate and interview processes, and supporting recruiting projects and knowledge-sharing initiatives.
Top Skills:
Ai/MlApplicant Tracking Systems (Ats)CloudCybersecurityData EngineeringLinkedin RecruiterSoftware DevelopmentSourcing Tools
What you need to know about the Pune Tech Scene
Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.








