Responsibilities
- Guide technology organization security and privacy initiatives through design reviews and threat modeling.
- Ensure web and mobile applications are secured and hardened throughout the project lifecycle.
- Define project scope and ensure continuous adherence from initiation through maintenance.
- Create visibility and adoption for security projects serving internal customers.
- Act as a security engineering expert and technical champion within Zeta.
- Assess application security gaps and identify tools and improvements.
- Coordinate with internal and external stakeholders.
- Mentor developers and QA teams on security practices.
- Evaluate vulnerabilities reported through bug bounty programs.
- Assess the security posture of applications across business units.
- Drive continuous improvement of web and mobile application security.
- Conduct quarterly internal and external, authenticated and unauthenticated vulnerability assessments and penetration tests.
- Secure the configuration of web and mobile applications, databases, data, cloud infrastructure, and servers.
Requirements
- Hands-on vulnerability assessment and penetration testing experience across web, mobile, SDK, API, and network environments.
- Thorough understanding of the OWASP Top 10, attack and defense mechanisms, threat modeling, secure coding, and secure SDLC activities.
- Experience with commercial and open-source security tools including Burp Suite, AppScan, OWASP ZAP, BeEF, Metasploit, Qualys, Nessus, Snyk, Veracode, Checkmarx, and SonarQube.
- Ability to identify and exploit business-logic vulnerabilities and incorrect configurations.
- Understanding of cryptography, PKI-based systems, TLS, authentication and authorization frameworks, and payment key management.
- Experience reversing mobile applications and using tools such as Dex2jar, adb, Drozer, Clang, iMAS, Frida, and Objection.
- Experience conducting security assessments and penetration tests in Windows, Linux, and AWS environments.
- Shell scripting or automation experience using Python or Ruby.
- Knowledge of PA-DSS, PCI SSF, PCI DSS, UIDAI, GDPR, and NIST security standards.
- Ability to read, write, and understand Java code and familiarity with Spring Boot, Jenkins, CI/CD, and production operations on public cloud infrastructure.
- Knowledge of AWS, Azure, Docker, containers, Kubernetes, databases, data stores, and Cloudflare WAF.
- Participation in bug bounty programs and experience conducting hackathons or CTFs.
- OSCP, GWAPT, AWAE, or CompTIA Security+ certifications are relevant, with OSCP preferred.
- Bachelor of Technology, BE/B.Tech, M.Tech, or ME in Computer Science or an equivalent qualification from a Tier-1 engineering college or university.
- At least 4 years of experience developing large-scale internet or SaaS applications and 2 to 3 years of experience as a web/mobile application security engineer or developer.
- FinTech experience and knowledge of HSM operations are desirable.
Tech Stack
Categories
About Zeta
Headquartered in San Francisco, California, Zeta was named by Celent in 2023 as being among the likeliest partners for US banks and credit unions looking to modernize to a next-gen issuer processing platform. With our marquee credit card ranked #2 by American cardholders, Zeta is already acknowledged by leading issuers as the go-to platform for market-leading credit card experiences. Globally, Zeta is recognized as a next-gen banking technology company. Our platform enables financial institutions to launch extensible and compliant banking asset and liability products, across cards, loans and deposits, rapidly. Our cloud-native and fully API-enabled stack supports processing, issuing, lending, core banking, fraud, loyalty, digital banking apps, and many other capabilities. Zeta has 1700+ employees with over 70% in technology roles across locations in the US, Middle East, and Asia, with regional headquarters in Mumbai, India. Globally, customers have issued 25M+ cards on our platform. Visit us at www.zeta.tech or follow us on LinkedIn, YouTube, and X.
