Skip to content

Open nowPosted 73 days ago

Product Security Engineer II

Zeta25 open roles

Where
Hyderabad
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowProduct Security Engineer IIZeta · Hyderabad
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Zeta's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 73 days ago

The posting

About us: Build the future of banking.

Zeta is a next-generation banking technology company providing cloud-native, fully stackable processing and core banking platforms for issuers. With a focus on scalability, compliance, and innovation, Zeta empowers financial institutions to modernize their technology infrastructure and deliver secure, seamless digital banking experiences.

Our impact runs at real-world scale. Today, over 25 million cards are live on Zeta-powered platforms across 7 countries, supported by a passionate team of 1,700+ Zetanauts across India, the US, EMEA, and Asia. Backed by SoftBank Vision Fund, Mastercard, and other reputed strategic investors, we reached a valuation of $2 billion in 2025.

Our focus is on establishing product lines that focus on key outcomes by addressing real customer pain points, modernizing legacy systems, and strengthening core fundamentals. As a result, our systems and platforms support a wide range of banking and payments capabilities, including:

1. Tachyon, our cloud-native banking stack built for population-scale systems

2. Cipher, our unified authentication platform for secure, high-volume banking environments

3. Digital Credit as a Service, enabling banks to launch credit lines on UPI

4. Elena, our intelligent and conversational AI platform for banking

5. Pixel, India’s first digital-native credit card, launched in partnership with HDFC Bank, for whom we also revamped their PayZapp mobile app: Winner of the Celent Model Bank Award for Payments Innovation 2024

6. Sparrow, the leading card experience for non-prime cardholders in the US

…and more across cards, payments, lending, and core banking.

We are an engineering-first organization that values ownership, bias for action, and long-term thinking. Together, we solve some of the hardest problems in banking tech. Our culture is built around trust, collaboration, and creating the conditions for you to drive impact proportionate to your potential. Reinforcing our commitment to creating an inclusive and supportive workplace, we have been consistently recognized as a Great Place to Work.

If you want to build cutting-edge banking tech that enables banks to serve millions reliably, securely, and at a population scale, Zeta is your playground.

If you would like to learn more about how we have grown and evolved over the years, watch our journey here. You can also explore our website and follow us on LinkedIn, Instagram, YouTube, and X.

About the Role:

This role is part of the Risk & Compliance Team, Engineering division of Zeta. The Product Security Engineer is responsible to secure all mobile & web applications along with API’s by breaking and hacking them and educating Developers as well as DevOps teams on how to fix them. The objective is to make zeta applications and platforms secure. As Application Security Engineer of the Product Security sub-division, you will be responsible for securing all the Zeta’s Products. You will be working as an individual contributor reporting to a manager.

  • Perform regular VA/PT for Web & Mobile applications, API & Infrastructure
  • Guide developers in fixing security issues.
  • Regular code reviews
  • Involve in application design discussions.
  • Perform Threat Modelling of Web/Mobile applications.
  • Develop secure code practices and educate dev and QA engineers by building security standards, policies for secure coding, secure data handling, secure networking, secure crypto implementation, etc.
  • Evaluate & Integrate security testing tools (SAST, DAST,SCA) in to CI/CD pipelines.

Responsibilities:

  • Guide the technology organization's security and privacy initiatives by participating in design reviews and threat modeling.
  • The applications are developed by the developers and product managers, and you will make sure the applications are secured and hardened.
  • You will define the scope and ensure continuous adherence to the scope of projects at each phase (initiation to sustenance/maintenance phase).
  • You will be responsible for creating visibility, and adoption of the projects meant for internal customers.
  • Act as a security engineering expert and technical champion within Zeta.
  • Assess gaps, and tools to improve application security
  • Liasioning with all external and internal stakeholders for the team.
  • Mentoring developers and QA.
  • Evaluate bugs reported through the Bug Bounty program.
  • Run security posture of various applications across BU’s.
  • Continuous improvement of web/mobile application security
  • Quarterly VA/PT (internal/external, authenticate/non-authenticated) for mobile/web.
  • Secure configuration of Web/Mobile application, DB, Data etc.

Skills:

  • Hands on VA/PT experience in Web, Mobile, SDK, API & Network
  • Thorough understanding of OWASP Top 10, their attack & defense mechanisms
  • Exposure to Secure SDLC Activities, Threat Modelling & Secure Coding
  • Experience with both commercial and open-source tools like Burp suite, AppScan, OWASP ZAP, BEEF, Metasploit, Qualys, Nessus, Synk etc.
  • Identifying and exploiting business logic-related vulnerabilities.
  • Solid understanding of Cryptography, knowledge of PKI-based systems, TLS
  • Understanding of different AuthN/AuthZ frameworks (OIDC, oAuth, SAML) able to read/write/understand java code
  • Performed Static Analysis, Code reviews using tools like Snyk, Veracode, Checkmarx, Sonarqube etc.
  • Hands on Reversing mobile applications, class/small files, data obfuscators, or ciphers (Dex2jar, adb, Drozer, Clang, iMAS) and Dynamic Instrumentation tools like Frida/Objection
  • Execute penetration tests and security assessments on internal and external networks, Windows and Linux environments, cloud (AWS) Infrastructure.
  • Identify and exploit incorrect configurations and security vulnerabilities on Windows and Linux servers. Safely utilize tools, tactics, and procedures used in penetration testing engagements.
  • Shell scripting or automation of simple tasks using Python, or Ruby
  • Knowledge of PCI DSS, PCI SSF (S3, SSLC) etc.
  • Knowledge of security standards like PCI DSS, UIDAI, GDPR, NIST, etc.
  • Understanding Java Frameworks like Springboot, CI/CD, Jenkins.
  • In-depth understanding of production operations on public cloud infrastructure.
  • Excellent written and oral communication and a penchant for technical documentation.
  • Must have participated in various bug bounty programs (HackerOne, Bug Crowd, Private etc)
  • Experience in conducting hackathons and CTF’s
  • Knowledge of AWS/Azure (VPC/Vnet, S3 buckets, blob stores, LoadBalancers etc.), Dockers & Containers, Kubernetes
  • Good understanding of agile development practices.
  • Certifications like OSCP(Preferred), GWAPT, Advanced Web Attacks and Exploitation (AWAE), Comptia Security+
  • Knowledge of Databases - Postgresql, Redshift, My SQL etc. and other data stores like Elasticsearch and S3 buckets.
  • Experience in the FinTech domain is highly desirable.
  • Knowledge of payment key management, cryptographic key handling, and HSM operations will be an added advantage.
  • Cloudflare WAF experience or knowledge in the areas:
  • Cloudflare WAF Rules Review and Configuration
  • Cloudflare WAF Rules Tuning
  • Cloudflare Traffic and Event Monitoring
  • Bot Traffic Analysis
  • Detecting and handling anonymous or un-authenticated API Calls.

Experience and Qualifications:

  • 4+ years of experience in developing large scale internet or SaaS applications.
  • 2 to 3 years of overall experience as Web/Mobile Application Security engineer or Developer in medium to large-sized product companies.
  • Bachelor of Technology (BE/B.Tech), M.Tech or ME in Computer Science or equivalent from a Tier-1 engineering college/university.

Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Zeta's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Zeta's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Zeta's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.