Full-Time

Application Security Engineer 2

Posted on 6/18/2025

Zeta

Zeta

1,001-5,000 employees

Cloud-native payment card issuer platform

No salary listed

Hyderabad, Telangana, India

In Person

Category
IT & Security (1)
Requirements
  • 2+ years of experience in developing large scale internet or Software as a Service applications
  • 2 to 3 years of overall experience as Web/Mobile Application Security engineer or Developer in medium to large-sized product companies
  • Bachelor of Technology (BE/B.Tech), Master of Technology (M.Tech) or Master of Engineering (ME) in Computer Science or equivalent from a Tier-1 engineering college/university
Responsibilities
  • Perform regular vulnerability assessment and penetration testing for Web & Mobile applications, APIs and Infrastructure
  • Guide developers in fixing security issues
  • Regular code reviews
  • Involve in application design discussions
  • Perform Threat Modelling of Web/Mobile applications
  • Develop secure code practices and educate developers and QA engineers by building security standards, policies for secure coding, secure data handling, secure networking, secure cryptography implementation, etc.
  • Evaluate and integrate security testing tools (SAST, DAST, Software Composition Analysis) into CI/CD pipelines
  • Guide the technology organization's security and privacy initiatives by participating in design reviews and threat modeling
  • Ensure applications developed by developers and product managers are secured and hardened
  • Define the scope and ensure continuous adherence to the scope of projects at each phase (initiation to sustenance/maintenance)
  • Create visibility and adoption of security projects meant for internal customers
  • Act as a security engineering expert and technical champion within Zeta
  • Assess gaps and tools to improve application security
  • Liaison with external and internal stakeholders for the team
  • Mentor developers and QA
  • Evaluate bugs reported through the Bug Bounty program
  • Run security posture assessments of various applications across business units
  • Continuous improvement of web/mobile application security
  • Quarterly vulnerability assessment and penetration testing (internal/external, authenticated/non-authenticated) for mobile/web
  • Secure configuration of Web/Mobile applications, databases, and data
Desired Qualifications
  • OSCP (Preferred)
  • GWAPT (Preferred)
  • Advanced Web Attacks and Exploitation (AWAE) (Preferred)
  • CompTIA Security+ (Preferred)
  • Hands-on vulnerability assessment and penetration testing experience in Web, Mobile, API & Network
  • Thorough understanding of OWASP Top 10 and related attack and defense mechanisms
  • Exposure to Secure Software Development Lifecycle Activities, Threat Modelling and Secure Coding
  • Experience with both commercial and open source tools like Burp Suite, AppScan, OWASP ZAP, BeEF, Metasploit, Qualys, Nessus, Synk, etc.
  • Identifying and exploiting business logic vulnerabilities
  • Solid understanding of Cryptography, PKI-based systems, TLS
  • Understanding of authentication/authorization frameworks (OIDC, OAuth, SAML) and ability to read/write/understand Java code
  • Static Analysis and code reviews using tools like Snyk, Veracode, Checkmarx, SonarQube
  • Reversing mobile applications and related tools (Dex2jar, adb, Drozer, Clang, iMAS) and dynamic instrumentation tools like Frida/Objection
  • Execute penetration tests and security assessments on internal and external networks, Windows and Linux environments, cloud (AWS) infrastructure
  • Identify and exploit incorrect configurations and security vulnerabilities on Windows and Linux servers
  • Shell scripting or automation tasks using Python or Ruby
  • Knowledge of Payment Card Industry Data Security Standard (PCI DSS), PCI Software Security Framework (PCI SSF)
  • Knowledge of security standards such as PCI DSS, UIDAI, GDPR, NIST
  • Understanding of Java frameworks such as Spring Boot, CI/CD, Jenkins
  • Comprehensive understanding of production operations on public cloud infrastructure
  • Excellent written and oral communication and technical documentation skills
  • Participation in various bug bounty programs (HackerOne, Bugcrowd, Private, etc)
  • Experience in conducting hackathons and Capture The Flag events
  • Knowledge of Amazon Web Services or Microsoft Azure (VPC/VNet, S3, load balancers, etc.), Docker and Kubernetes
  • Strong understanding of agile development practices
  • Certifications such as Offensive Security Certified Professional (OSCP) Preferred, Global Information Assurance Certification Web Applications Penetration Tester (GWAPT), Advanced Web Attacks and Exploitation (AWAE), CompTIA Security+
  • Knowledge of databases such as PostgreSQL, Amazon Redshift, MySQL and other data stores like Elasticsearch and S3 buckets

Zeta provides cloud-native, API-connected payment card issuer processing platforms for banks, financial institutions, and fintechs. Its core product, Omni Stack, lets clients launch and manage digital credit, debit, and prepaid card programs through integrated APIs and cloud services. Transactions and card program management are handled via the platform, often with managed services and partner integrations (e.g., Sparrow) to offer comprehensive payment solutions. The company differentiates itself with a fully cloud-native, API-first approach combined with strong regulatory compliance (ISO IEC 27001, PCI DSS 4.0, SOC 2 Type 2), enabling rapid deployment and secure operation of embedded banking and payments. Zeta’s goal is to accelerate the world toward invisible payments by rethinking payment systems from core to edge.

Company Size

1,001-5,000

Company Stage

Late Stage VC

Total Funding

$430M

Headquarters

San Francisco, California

Founded

2015

Simplify Jobs

Simplify's Take

What believers are saying

  • Raised $50M from Optum in 2025, boosting valuation to $2B from $1.15B.
  • Serves 25M accounts, plans 25M more, with $50M+ annual revenue.
  • Digital Credit as a Service launched 2024 processes 2M daily UPI transactions.

What critics are saying

  • Optum builds competing card processing, poaches Zeta customers within 12-24 months.
  • Mastercard integrates issuer processing, bypasses Zeta for issuers in 18-36 months.
  • Profitability target missed by March 2026, collapses investor confidence immediately.

What makes Zeta unique

  • Zeta's Omni Stack enables rapid launch of compliant digital cards and loans.
  • Tachyon platform powers Sparrow's top-rated credit card for underserved since October 2023.
  • Cloud-native API stack supports issuing, fraud, and digital banking apps globally.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

-2%
Tech in Asia
Oct 14th, 2025
Zeta raises $50M, valuation hits $2B

Zeta, an Indian fintech firm, has raised $50 million from Optum, boosting its valuation to $2 billion, up from $1.15 billion in 2021 when it received $250 million from SoftBank Vision Fund 2. Founded in 2015, Zeta aids banks and fintechs in modernizing services with cloud tech. It serves 25 million accounts, plans to add 25 million more, and aims for profitability by March 2026. The US is its largest market, followed by India, generating over $50 million annually.

VentureCapital.com
Jun 24th, 2025
Acorns Acquires Zeta for Family Finance

Acorns has acquired Zeta, a financial planning platform for couples and families, to enhance its financial wellness offerings across various life stages. This acquisition, which includes Zeta co-founders Kevin Hopkins and Aditi Shekar joining Acorns, marks the company's fifth strategic acquisition in under two years. Existing Zeta customers will gain access to Acorns' financial wellness benefits. Financial terms were not disclosed.

TechCrunch
Feb 11th, 2025
Zeta valued at $2B in new funding | TechCrunch

Zeta, a provider of banking software to banks and fintech startups, has raised $50 million from a strategic investor at a $2 billion valuation. The new Zeta, a provider of banking software to banks and fintech startups, has raised $50 million from a strategic investor at a $2 billion valuation.

Entrackr
Feb 11th, 2025
Zeta secures $50M, valued at $2B

Zeta, a modern banking tech company, has raised $50 million from an undisclosed strategic investor, valuing the company at $2 billion. Zeta became a unicorn in May 2021 with a $250 million Series C round from SoftBank Vision Fund 2. The company also received $30 million from Mastercard in March 2022 at a $1.5 billion valuation. Zeta's Indian entity reported a 9.42% revenue increase to ₹893.12 crore in FY24, with PAT rising 5.4x to ₹119.82 crore.

Business Wire
Mar 7th, 2024
Zeta Powers Sparrow’S Industry-Leading Credit Card For The Underserved

SAN FRANCISCO--(BUSINESS WIRE)--Zeta, a leading provider of next-gen card processing solutions to banks and credit unions, is proud to announce its partnership with Sparrow Financial to power the most modern credit card program in existence for non-prime customers.Sparrow is founded by industry veterans - Evan Feldman and Lisa Sturm - who have spent 30+ years building and managing large-scale credit card portfolios. They embarked on a quest for a modern card processing solution to launch a differentiated card program for underserved Americans. After meticulous evaluation of various card processors, they chose Zeta's Tachyon platform.Evan Feldman, Co-CEO of Sparrow Financial, said: “Sparrow has built the #1 credit card experience for the underserved in every respect, from a seamless application journey and instantaneous underwriting, a user-friendly mobile app, cutting-edge virtual card experience, a hassle-free repayment process, and an operations center that puts the customer first. This achievement has been made possible through the next-gen capabilities and integrated stack of Zeta.”The Sparrow credit card went live in October 2023, leveraging Zeta for card processing, mobile app, servicing, and advanced data & analytics capabilities. And, in under 6 months of launch, it has received glowing reviews for its intuitive and modern experience from customers with consistently high ratings on Credit Karma and mobile app stores, such as:Great card, easy to use app | ⭐⭐⭐⭐⭐“The virtual card is available right away on the app, which was super convenient. Overall the app is really easy to use, especially compared to some of my other cards.”| ⭐⭐⭐⭐⭐ “The virtual card is available right away on the app, which was super convenient

INACTIVE