Manager - Application & Product Security

3 days ago


Hyderābād, Sindh, Pakistan Zeta Full time $120,000 - $180,000 per year
About Zeta
Zeta is a Next-Gen Banking Tech company that empowers banks and fintechs to launch banking products for the future. It was founded by Bhavin Turakhia and Ramki Gaddipati in 2015. Our flagship processing platform - Zeta Tachyon - is the industry's first modern, cloud-native, and fully API-enabled stack that brings together issuance, processing, lending, core banking, fraud & risk, and many more capabilities as a single-vendor stack. 15M+ cards have been issued on our platform globally. Zeta is actively working with the largest Banks and Fintechs in multiple global markets transforming customer experience for multi-million card portfolios. Zeta has over 1700+employees - with over 70%roles in R&D - across locations in the US,EMEA, and Asia. We raised$280 million at a$1.5 billion valuation from Softbank, Mastercard, and other investors in 2021.Learn more ,,Linkedin,Twitter

The Role
As part of the Risk & Compliance team within the Engineering division at Zeta, the Application Security Manager is tasked with safeguarding all mobile, web applications, and APIs. This involves identifying vulnerabilities through testing and ethical hacking, while also educating developers and DevOps teams on how to resolve them. Your primary goal will be to ensure the security of Zeta's applications and platforms. As a manager, you'llbe responsible for securing all of Zeta's products. In this individual contributor role, you will report directly to the Chief Information Security Officer (CISO).    The role involves ensuring the security of web and mobile applications, APIs, and infrastructure by conducting regular VAPT. It requires providing expert guidance to developers on how to address and fix security vulnerabilities, along with performing code reviews to identify potential security issues. The role also includes actively participating in application design discussions to ensure security is integrated from the beginning and leading Threat Modeling exercises to identify potential threats. Additionally, the profile focuses on developing and promoting secure coding practices, educating developers and QA engineers on security standards for secure coding, data handling, network security, and encryption. The role also entails evaluating and integrating security testing tools like SAST, DAST, and SCA into the CI/CD pipeline to enhance continuous security integration.  Responsibilities
  • Guide Security and Privacy Initiatives: Actively participate in design reviews and threat modeling sessions to help shape the security and privacy approach for technology projects, ensuring security is embedded at all stages of application development. 
  • Ensure Secure Application Development: Collaborate with developers and product managers to ensure that applications are securely developed, hardened, and aligned with industry best practices. 
  • Project Scope Management: Define the scope for security initiatives, ensuring continuous adherence throughout each project phase, from initiation to sustenance/maintenance. 
  • Drive Internal Adoption and Visibility: Ensure that security projects are well-understood and adopted by internal stakeholders, fostering a culture of security awareness within the organization. 
  • Security Engineering Expertise: Serve as a technical expert and security champion within Zeta, providing guidance and expertise on security best practices across the organization. 
  • Team Leadership and Development
  • Make decisions on hiring and lead the hiring process to build a skilled security team. 
  • Define and drive improvements in the hiring process to attract top security talent. 
  • Mentor and guide developers and QA teams on secure coding practices and security awareness. 
  • Security Tool and Gap Assessment: Continuously assess and recommend tools to address gaps in application security, ensuring the team is equipped with the best resources to identify and address vulnerabilities. 
  • Stakeholder Liaison: Collaborate with both internal and external stakeholders to ensure alignment on security requirements and deliverables, acting as the main point of contact for all security-related matters within the team. 
  • Bug Bounty Program Management: Evaluate and triage security bugs reported through the Bug Bounty program, working with relevant teams to address and resolve issues effectively. 
  • Own Security Posture: Take ownership of the security posture of various applications across the business units, ensuring that security best practices are consistently applied and maintained.
Skills
  • Hands-on experience in Vulnerability Assessment (VA) and Penetration Testing (PT) across web, mobile, API, and network/Infra environments. 
  • Deep understanding of the OWASP Top 10 and their respective attack and defense mechanisms. 
  • Strong exposure to Secure SDLC activities, Threat Modeling, and Secure Coding practices. 
  • Experience with both commercial and open-source security tools, including Burp Suite, AppScan, OWASP ZAP, BEEF, Metasploit, Qualys, Nipper, Nessus andSnyk
  • Expertise in identifying and exploiting business logic vulnerabilities
  • Solid understanding of cryptography, PKI-based systems, and TLS protocols. 
  • Proficiency in various AuthN/AuthZ frameworks (OIDC, OAuth, SAML) and the ability to read, write, and understand Java code. 
  • Experience with Static Analysis and Code Reviews using tools like Snyk,Fortify,Veracode, Checkmarx, and SonarQube
  • Hands-on experience in reverse engineering mobile apps and using tools like Dex2jar, ADB, Drozer, Clang, iMAS, and Frida/Objection for dynamic instrumentation. 
  • Experience conducting penetration tests and security assessments on internal/external networks, Windows/Linux environments, and cloud infrastructure (primarily AWS). 
  • Ability to identify and exploit security vulnerabilities and misconfigurations in Windows and Linux servers
  • Proficiency in shell scripting and automating tasks with tools such as Python or Ruby
  • Familiarity with PA-DSS, PCI SSF (S3, SSLC), and other security standards like PCI DSS, DPSC, ASVS and NIST
  • Understanding of Java frameworks like Spring Boot, CI/CD processes, and tools like Jenkins & Bitrise. 
  • In-depth knowledge of cloud infrastructure (AWS, Azure), including VPC/VNet, S3 buckets, IAM,Security Groups, blob stores, Load Balancers, Docker containers, and Kubernetes
  • Solid understanding of agile development practices. 
  • Active participation in bug bounty programs (HackerOne, Bug Crowd, etc.) and experience with hackathons and Capture the Flag (CTF) competitions. 
  • Knowledge of AWS/Azure services, including network configuration and security management. 
  • Experience with databases (PostgreSQL, Redshift, MySQL) and other data storage solutions like Elasticsearch and S3 buckets
  • Preferred Certifications: OSCP, OSWE, GWAPT, AWAE, AWS Certified Security Specialist, CompTIA Security+ 
Experience and Qualifications
  • 12 to 18 years of overall experience in application security, with a strong background in identifying and mitigating vulnerabilities in software applications. 
  • A background in development and experience in the fintech sector is a plus. 
  • Bachelor of Technology (BE/B.Tech), M.Tech, or ME in Computer Science or an equivalent degree from an Engineering college/University.
Life At Zeta
At Zeta, we want you to grow to be the best version of yourself by unlocking the great potential that lies within you. This is why our core philosophy is 'People Must Grow.' We recognize your aspirations; act as enablers by bringing you the right opportunities, and let you grow as you chase disruptive goals. 
#LifeAtZeta is adventurous and exhilarating at the same time. You get to work with some of the best minds in the industry and experience a culture that values the diversity of thoughts. If you want to push boundaries, learn continuously and grow to be the best version of yourself,  Zeta is the place to be  Explore the life at zeta 
Zeta is an equal opportunity employer.  
At Zeta, we are committed to equal employment opportunities regardless of job history, disability, gender identity, religion, race, marital/parental status, or another special status. We are proud to be an equitable workplace that welcomes individuals from all walks of life if they fit the roles and responsibilities.

  • Hyderābād, Sindh, Pakistan Zeta Full time $80,000 - $120,000 per year

    About Zeta Zeta is a Next-Gen Banking Tech company that empowers banks and fintechs to launch banking products for the future. It was founded by Bhavin Turakhia and Ramki Gaddipati in 2015. Our flagship processing platform - Zeta Tachyon - is the industry's first modern, cloud-native, and fully API-enabled stack that brings together issuance, processing,...


  • Hyderābād, Sindh, Pakistan Backbase Full time $120,000 - $200,000 per year

    keep millions of users and their banking data safe and secure.No day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand and with hackers and tech evolving by the day, you'll need to stay on your toes and ahead of the game.Your core responsibility is to ensure the delivery of...


  • Hyderābād, Sindh, Pakistan Backbase Full time 1,200,000 - 2,400,000 per year

    Principal AI Application Security EngineerThe job in short: keep millions of users and their banking data safe and secure.No day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand and with hackers and tech evolving by the day, you'll need to stay on your toes and ahead of the...


  • Hyderābād, Sindh, Pakistan Backbase Full time 1,500,000 - 3,000,000 per year

    The job in shortNo day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand and with hackers and tech evolving by the day, you'll need to stay on your toes and ahead of the game.Your core responsibility is to guide and support the developer teams in delivering and  deploying...


  • Hyderābād, Sindh, Pakistan UltraViolet Cyber Full time $40,000 - $80,000 per year

    Cyber Security Analyst UltraViolet Cyber is seeking a Cyber Security Analyst to add to our existing team. Primary responsibilities will require: (i) in-depth analysis of intrusions in diverse computing environments; (ii) thorough packet analyses; (iii) implementing/optimizing changes to security infrastructure; (iv) integrating threat intelligence into the...

  • Security Architect

    2 weeks ago


    Hyderābād, Sindh, Pakistan UST Full time 1,500,000 - 2,500,000 per year

    9 - 12 Years1 OpeningBangalore, HyderabadRole descriptionSecurity ArchitectExperience : 7 plus yearsKey Responsibilities Perform threat modeling on application and infrastructure designs to identify risks, vulnerabilities, and attack vectors.Review application components and underlying infrastructure (servers, databases, middleware, APIs, networks, cloud...

  • Security Operations

    2 weeks ago


    Hyderābād, Sindh, Pakistan Blue Yonder Full time 1,200,000 - 3,600,000 per year

    ResponsibilitiesDetect and respond to cyber security threats to ensure your organization operates securely.Partner with the existing internal SOC team across the world and keep the CISO informed about security Incidents.Act as a liaison between the SOC team, other internal stakeholders, and external parties such as vendors, clients, or regulatory...


  • Hyderābād, Sindh, Pakistan Loginsoft Full time 2,000,000 - 2,500,000 per year

    Job Description:We are looking for a highly skilled DevOps Engineer with hands-on experience managing and deploying Azure Policies in multi-tenant environments. The ideal candidate will have a deep understanding of Azure governance, compliance, and infrastructure automation to help enforce organizational standards and ensure secure, compliant Azure...


  • Hyderābād, Sindh, Pakistan Hope Global School Full time 3,200,000 per year

    Job DescriptionResponsible for designing and implementing enterprise-wide security architectures to protect organizational information systems. Ensures robust security frameworks, compliance with industry standards, and proactive threat mitigation. Collaborates with IT, risk, and business teams to evaluate security risks, integrate advanced security...


  • Hyderābād, Sindh, Pakistan F5 Full time

    At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.Everything we do centers around...