Application Security Specialist
ZS Associates · State of Mahārāshtra, India
ZS Associates · State of Mahārāshtra, India
: **ZS** is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by **bringing together data, science, technology** and **human ingenuity** to deliver better outcomes for all. Here you’ll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a **client-first mentality** to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS. : **Application Security Specialist** We are seeking an experienced professional to join us as an Application Security Specialist in our Pune, India office. This professional will be responsible for Implementing DevSecOps Practices across cloud environments & mature ZS’s Application Security Program. This role requires strategic and out-of-box thinking, high technical expertise, and effective communication skills to proactively identify and address security risks. **What you'll do:** As an Application Security Specialist in the Enterprise you will - - Lead the design and implementation of DevSecOps framework, integrating security seamlessly into CI/CD pipelines across multiple environments and platforms. - Collaborate with developers, SREs, and security teams to embed security controls and testing at build, deployment, and runtime stages. - Build and manage automation for SAST, DAST, SCA, container security, and IaC scanning tools (e.g., SonarQube, Checkmarx, Snyk, Trivy, Terraform Scan). - Analyze results from SAST, SCA, and DAST scans to validate findings, eliminate false positives, and work with development teams to prioritize and remediate security issues. - Leverage expertise in TeamCity and AWS to build secure, scalable CI/CD pipelines and enforce security controls throughout the software delivery lifecycle - Champion “shift-left” security practices by developing reusable pipelines, templates, and toolchains that promote secure coding and rapid feedback loops. - Ensure ongoing visibility and reporting of security posture in cloud-native workloads, container platforms, and serverless environments. - Lead training sessions and build developer-friendly resources to raise DevSecOps awareness across engineering teams. - Stay current with evolving tools, threats, and best practices in secure software delivery, continuously innovating to improve security effectiveness and developer experience. - Partner with product owners, developers, architects, and QA engineers to build secure-by-design applications. - Provide mentorship and security guidance to internal stakeholders to raise overall security maturity. - Collaborate closely with Application Security teams to align on secure development standards, threat modeling efforts, and triaging complex vulnerabilities identified during code and runtime analysis. **What you'll bring:** - Bachelor’s in computer science /management of computer information/information assurance or Cybersecurity - 6+ years of DevSecOps / Secure DevOps /Security Engineer/ Application & Cloud Security roles - Must have Certifications: OSWE/CSSLP/ AWS Certified Solutions Architect / AWS Security Specialty - Preferred Certifications: AWS CLP, GIAC (GCSA), GIAC (GWAPT), OSCP, OSWA, OSEP, eWPT - Expertise in implementing DevSecOps practices in cloud-native CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Jenkins, TeamCity, Azure DevOps, Bit-Bucket). - Strong hands-on experience with application security tools such as SonarQube, Fortify, Checkmarx, Snyk, Veracode, BlackDuck, Burp Suite, OWASP ZAP. - Knowledge of containerization and orchestration security (Docker, Kubernetes, Helm) and tools like Trivy, Kube-bench, and Aqua. - Working knowledge of programming/scripting languages like Python, Java, JavaScript, C#, .Net or go. - Familiarity with cloud-native security controls (AWS Security Hub, Azure Defender, GCP Security Command Center). - Strong scripting skills in Python, Bash, or PowerShell for automation and tool integration. - Ability to develop and enforce security guardrails, policies, and standards in automated and scalable ways. - In-depth understanding of OWASP, CWE, CVE scoring, and secure SDLC methodologies. - Ability to clearly document findings and communicate risk effectively to technical and non-technical stakeholders. - Fluency in English - Client-first mentality - Intense work ethic - Collaborative spirit and problem-solving approach : **How you’ll grow:** - Cross-functional skills development & custom learning pathways - Milestone training programs aligned to career progression opportunities - Internal mobility paths that empower growth via s-curves, individual contribution and role expansions **Perks & Benefits:** At ZS, your growth matters. We offer a comprehensive total rewards package that supports your health and well‑being, financial future, time away, and professional development. With robust skills‑building programs, multiple career progression paths, internal mobility, and a deeply collaborative culture, you’ll have the opportunity to do meaningful work, expand your capabilities, and thrive as part of a global community. For details on total rewards in India, visit ZS India office locations | Where we work | ZS. **Hybrid working model:** We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections. **Travel:** Travel is a requirement at ZS for client facing ZS