Staff Information Security Engineer

Bangalore, IND

Zscaler

Zscaler, the zero trust cybersecurity leader, accelerates digital transformation with fast, secure connections between users, devices and apps over any network.

View all jobs at Zscaler

Apply now Apply later

About Zscaler

Serving thousands of enterprise customers around the world including 40% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. 

Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. 

Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

We're looking for an experienced Application Security Engineer for our Product Security team. Reporting to the Director of Vulnerability Management, you'll be responsible for:

  • Conducting thorough static and dynamic analysis of our applications to identify and remediate security vulnerabilities early in the development process (SAST/DAST)
  • Implementing SCA tools to identify and manage open-source components, ensuring that all third-party libraries and frameworks used in our codebase are secure and up-to-date (Software Composition Analysis)
  • Assessing and securing our containerized environments and IAC deployments, ensuring that security best practices are followed to protect our infrastructure from potential threats (Container and Infrastructure as Code Security)

What We're Looking for (Minimum Qualifications)

  • Expertise in Application Security, encompassing over 4 years of hands-on experience in deploying and overseeing security protocols like Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA)
  • Proficiency with application security tools such as Snyk, Semgrep, Coverity, Checkmarx, Burp Suite, OWASP ZAP, and dependency management tools
  • Strong understanding of secure coding practices, vulnerability management, and remediation techniques with expertise in source control (Github, Bitbucket), and CI pipelines (ArgoCD, Jenkins)
  • Experience in identifying and addressing security vulnerabilities within codebases, ensuring prompt and efficient management throughout the CVE/CWE lifecycle

What Will Make You Stand Out (Preferred Qualifications)

  • At least 2 years of practical experience in one or more of the following operational areas: Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), or Infrastructure as Code (IaC)
  • Experience as a software developer or within a DevSecOps position, with proficiency in programming languages such as Java, Python, JavaScript, C/C++, and Golang
  • Extensive experience in Cloud Security, adept at securing cloud environments including AWS, Azure, and Google Cloud, with comprehensive knowledge of cloud-native security tools and methodologies

#LI-Hybrid

#LI-SK3

At Zscaler, we believe that diversity drives innovation, productivity, and success. We are looking for individuals from all backgrounds and identities to join our team and contribute to our mission to make doing business seamless and secure. We are guided by these principles as we create a representative and impactful team, and a culture where everyone belongs. For more information on our commitments to Diversity, Equity, Inclusion, and Belonging, visit the Corporate Responsibility page of our website.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is proud to be an equal opportunity and affirmative action employer. We celebrate diversity and are committed to creating an inclusive environment for all of our employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status or any other characteristics protected by federal, state, or local laws.

See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules. For additional information about the federal requirements, click here.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  4  0  0

Tags: Agile Application security AWS Azure Bitbucket Burp Suite C Checkmarx Cloud DAST DevSecOps GCP GitHub Golang Java JavaScript Jenkins OWASP Privacy Product security Python SAST Strategy Vulnerabilities Vulnerability management Zero Trust

Perks/benefits: Health care Medical leave Parental leave

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.