Manager - Application & Product Security

2 weeks ago


Hyderabad, India Zeta Services Inc. Full time
About Zeta Zeta is a Next-Gen Banking Tech company that empowers banks and fintechs to launch banking products for the future. It was founded by and Ramki Gaddipati in 2015. Our flagship processing platform - Zeta Tachyon - is the industry’s first modern, cloud-native, and fully API-enabled stack that brings together issuance, processing, lending, core banking, fraud & risk, and many more capabilities as a single-vendor stack. 15M+ cards have been issued on our platform globally. Zeta is actively working with the largest Banks and Fintechs in multiple global markets transforming customer experience for multi-million card portfolios. Zeta has over 1700+employees - with over 70%roles in R&D - across locations in the US,EMEA, and Asia. We raised$280 million at billion valuation from Softbank, Mastercard, and other investors in more @,,,The Role As part of the Risk & Compliance team within the Engineering division at Zeta, the Application Security Manager is tasked with safeguarding all mobile, web applications, and APIs. This involves identifying vulnerabilities through testing and ethical hacking, while also educating developers and DevOps teams on how to resolve them. Your primary goal will be to ensure the security of Zeta's applications and platforms. As a manager, you'llbe responsible for securing all of Zeta’s products. In this individual contributor role, you will report directly to the Chief Information Security Officer (CISO). The role involves ensuring the security of web and mobile applications, APIs, and infrastructure by conducting regular VAPT. It requires providing expert guidance to developers on how to address and fix security vulnerabilities, along with performing code reviews to identify potential security issues. The role also includes actively participating in application design discussions to ensure security is integrated from the beginning and leading Threat Modeling exercises to identify potential threats. Additionally, the profile focuses on developing and promoting secure coding practices, educating developers and QA engineers on security standards for secure coding, data handling, network security, and encryption. The role also entails evaluating and integrating security testing tools like SAST, DAST, and SCA into the CI/CD pipeline to enhance continuous security integration. 

Responsibilities

Guide Security and Privacy Initiatives : Actively participate in design reviews and threat modeling sessions to help shape the security and privacy approach for technology projects, ensuring security is embedded at all stages of application development.  Ensure Secure Application Development : Collaborate with developers and product managers to ensure that applications are securely developed, hardened, and aligned with industry best practices.  Project Scope Management : Define the scope for security initiatives, ensuring continuous adherence throughout each project phase, from initiation to sustenance/maintenance.  Drive Internal Adoption and Visibility : Ensure that security projects are well-understood and adopted by internal stakeholders, fostering a culture of security awareness within the organization.  Security Engineering Expertise : Serve as a technical expert and security champion within Zeta, providing guidance and expertise on security best practices across the organization.  Team Leadership and Development Make decisions on hiring and lead the hiring process to build a skilled security team.  Define and drive improvements in the hiring process to attract top security talent.  Mentor and guide developers and QA teams on secure coding practices and security awareness.  Security Tool and Gap Assessment : Continuously assess and recommend tools to address gaps in application security, ensuring the team is equipped with the best resources to identify and address vulnerabilities.  Stakeholder Liaison : Collaborate with both internal and external stakeholders to ensure alignment on security requirements and deliverables, acting as the main point of contact for all security-related matters within the team.  Bug Bounty Program Management : Evaluate and triage security bugs reported through the Bug Bounty program, working with relevant teams to address and resolve issues effectively.  Own Security Posture : Take ownership of the security posture of various applications across the business units, ensuring that security best practices are consistently applied and maintained.

Skills

Hands-on experience in Vulnerability Assessment (VA) and Penetration Testing (PT) across web, mobile, API, and network/Infra environments.  Deep understanding of the OWASP Top 10 and their respective attack and defense mechanisms.  Strong exposure to Secure SDLC activities, Threat Modeling , and Secure Coding practices.  Experience with both commercial and open-source security tools, including Burp Suite , AppScan , OWASP ZAP , BEEF , Metasploit , Qualys , Nipper , Nessus andSnyk .  Expertise in identifying and exploiting business logic vulnerabilities .  Solid understanding of cryptography , PKI-based systems, and TLS protocols.  Proficiency in various AuthN/AuthZ frameworks (OIDC, OAuth, SAML) and the ability to read, write, and understand Java code.  Experience with Static Analysis and Code Reviews using tools like Snyk ,Fortify ,Veracode , Checkmarx , and SonarQube .  Hands-on experience in reverse engineering mobile apps and using tools like Dex2jar , ADB , Drozer , Clang , iMAS , and Frida/Objection for dynamic instrumentation.  Experience conducting penetration tests and security assessments on internal/external networks, Windows/Linux environments, and cloud infrastructure (primarily AWS).  Ability to identify and exploit security vulnerabilities and misconfigurations in Windows and Linux servers .  Proficiency in shell scripting and automating tasks with tools such as Python or Ruby .  Familiarity with PA-DSS , PCI SSF (S3, SSLC), and other security standards like PCI DSS , DPSC, ASVS and NIST .  Understanding of Java frameworks like Spring Boot , CI/CD processes, and tools like Jenkins & Bitrise.   In-depth knowledge of cloud infrastructure (AWS, Azure), including VPC/VNet, S3 buckets, IAM,Security Groups, blob stores, Load Balancers, Docker containers, and Kubernetes .  Solid understanding of agile development practices.  Active participation in bug bounty programs (HackerOne, Bug Crowd, etc.) and experience with hackathons and Capture the Flag (CTF) competitions.  Knowledge of AWS/Azure services , including network configuration and security management.  Experience with databases (PostgreSQL, Redshift, MySQL) and other data storage solutions like Elasticsearch and S3 buckets Preferred Certifications: OSCP, OSWE, GWAPT, AWAE, AWS Certified Security Specialist, CompTIA Security+ 

Experience and Qualifications

12 to 18 years of overall experience in application security, with a strong background in identifying and mitigating vulnerabilities in software applications.  A background in development and experience in the fintech sector is a plus.  Bachelor of Technology (BE/ ), , or ME in Computer Science or an equivalent degree from an Engineering college/University . Life At Zeta At Zeta, we want you to grow to be the best version of yourself by unlocking the great potential that lies within you. This is why our core philosophy is ‘People Must Grow.’ We recognize your aspirations; act as enablers by bringing you the right opportunities, and let you grow as you chase disruptive goals. #LifeAtZeta is adventurous and exhilarating at the same time. You get to work with some of the best minds in the industry and experience a culture that values the diversity of thoughts. If you want to push boundaries, learn continuously and grow to be the best version of yourself, Zeta is the place to be Zeta is an equal opportunity employer. At Zeta, we are committed to equal employment opportunities regardless of job history, disability, gender identity, religion, race, marital/parental status, or another special status. We are proud to be an equitable workplace that welcomes individuals from all walks of life if they fit the roles and responsibilities.
  • Cim Amp Associate 2

    2 weeks ago


    Hyderabad, India RSM US LLP Full time

    As a member of our CIM group, working specifically with Tax Accounting Methods & Periods (AMP), you will be responsible for the following job duties which are focused around two core concepts: your technical and quality expertise and delivering excellent client service: - Delivery of AMP projects supervised by regional and WNT AMP specialists, including...


  • Hyderabad, India Zeta Services Inc. Full time

    About Zeta Zeta is a Next-Gen Banking Tech company that empowers banks and fintechs to launch banking products for the future. It was founded by and Ramki Gaddipati in 2015. Our flagship processing platform - Zeta Tachyon - is the industry’s first modern, cloud-native, and fully API-enabled stack that brings together issuance, processing, lending, core...


  • Hyderabad, India Talent Pro Full time

    Job Title: Global Product Marketing Manager Application SecurityLocation: Bangalore (Hybrid)Key Responsibilities:- Lead global product marketing initiatives for application security solutions across multiple geographies (NA, EMEA, APAC).- Manage and mentor cross-functional global teams, aligning on GTM strategies, campaigns, and product launches.- Develop...


  • Hyderabad, India Aqua Security Full time

    Job Description About the Role We are seeking a passionate and experienced Customer Success Manager (CSM) to join our Digital Scaled Success Team in Hyderabad, India. As part of a global initiative to manage customers with an ARR $100K and a combined portfolio of $10M, you will play a vital role in driving customer onboarding, enablement, product adoption,...


  • Hyderabad, Telangana, India ServiceNow Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Company Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based...

  • Engineering manager

    4 weeks ago


    Hyderabad, India Medtronic Full time

    Company Overview: At Medtronic, we are committed to pushing the boundaries of technology to improve healthcare outcomes. We value innovation, collaboration, and diversity, and we believe that together we can change healthcare worldwide. Join us in our mission to alleviate pain, restore health, and extend life through meaningful innovations. Position...

  • Engineering Manager

    2 weeks ago


    Hyderabad, India Medtronic Full time

    Company Overview: At Medtronic, we are committed to pushing the boundaries of technology to improve healthcare outcomes. We value innovation, collaboration, and diversity, and we believe that together we can change healthcare worldwide. Join us in our mission to alleviate pain, restore health, and extend life through meaningful innovations. Position...

  • Engineering Manager

    2 weeks ago


    hyderabad, India Medtronic Full time

    Company Overview: At Medtronic, we are committed to pushing the boundaries of technology to improve healthcare outcomes. We value innovation, collaboration, and diversity, and we believe that together we can change healthcare worldwide. Join us in our mission to alleviate pain, restore health, and extend life through meaningful innovations. Position...

  • Engineering manager

    2 weeks ago


    Hyderabad, India Medtronic Full time

    Company Overview:At Medtronic, we are committed to pushing the boundaries of technology to improve healthcare outcomes. We value innovation, collaboration, and diversity, and we believe that together we can change healthcare worldwide. Join us in our mission to alleviate pain, restore health, and extend life through meaningful innovations.Position...


  • Hyderabad, India NCR Full time

    About NCR NCR Corporation (NYSE: NCR) is a leader in transforming, connecting and running technology platforms for self-directed banking, stores and restaurants. NCR is headquartered in Atlanta, Ga., with 38,000 employees globally. NCR is a trademark of NCR Corporation in the United States and other countries. Application Security Architect Position...