Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Information Security Engineer - VAPT, Thick client application image - Rise Careers
Job details

Senior Information Security Engineer - VAPT, Thick client application

About Zscaler

Serving thousands of enterprise customers around the world including 40% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. 

Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. 

Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

We're looking for an experienced Senior Security Researcher II to join our Cyber and Data Security team to contribute as Senior Researcher. Reporting to Sr. Manager, Security Research, You'll be responsible for:

  • Pen testing on Zscaler Applications and infrastructure.
  • Work on Security Automation and Continuously review security bulletins and related news.
  • Help prioritize vulnerabilities for engineering and operations team

What We're Looking for (Minimum Qualifications)

  • Experience of 5+ years in in manual security assessments using industry leading tools for web applications, thick client and APIs.
  • Experience with Security Architecture reviews in the areas of network security, complex thick client and web applications
  • Expertise in Thick client application pen testing - Win, Mac, Linux, Android & iOS.
  • Must have strong fundamentals in security concepts, cryptography, Unix architecture, and networking.
  • Must be able to read and debug popular programming languages (C/C++, Java, Javascript, etc.) and identify security weaknesses.

What Will Make You Stand Out (Preferred Qualifications)

  • Must be able to validate findings, perform root cause analysis.
  • Must have good scripting knowledge to automate repetitive tasks
  • Flexible to work on multiple related areas of Security research- Container security, AI/ML security, Cloud Security

#LI-Hybrid

#LI-PM5

At Zscaler, we believe that diversity drives innovation, productivity, and success. We are looking for individuals from all backgrounds and identities to join our team and contribute to our mission to make doing business seamless and secure. We are guided by these principles as we create a representative and impactful team, and a culture where everyone belongs. For more information on our commitments to Diversity, Equity, Inclusion, and Belonging, visit the Corporate Responsibility page of our website.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is proud to be an equal opportunity and affirmative action employer. We celebrate diversity and are committed to creating an inclusive environment for all of our employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status or any other characteristics protected by federal, state, or local laws.

See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules. For additional information about the federal requirements, click here.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Information Security Engineer - VAPT, Thick client application, Zscaler

If you're looking to make a real impact in the cybersecurity world, Zscaler is the place for you! We're on the hunt for a Senior Information Security Engineer - VAPT, specializing in thick client applications, to join our dynamic team in Bangalore. Imagine being a key player in protecting thousands of enterprise customers worldwide, including a whopping 40% of Fortune 500 companies. At Zscaler, our mission is straightforward yet profound: we aim to make the cloud a secure and enjoyable place to do business. As part of our Cyber and Data Security team, you'll dive deep into penetration testing on Zscaler’s applications and infrastructure. You’ll have the opportunity to enhance security automation and stay ahead of the curve by continuously reviewing security bulletins. Your expertise in manual security assessments and thick client application pen testing across multiple platforms will be crucial in prioritizing vulnerabilities for our engineering and operations teams. With 5+ years of experience under your belt, you’ll be well-versed in security concepts and possess a strong foundational knowledge of networking and cryptography. At Zscaler, we not only value your technical skills but also your innovative spirit. We're proud of our inclusive culture that champions diversity and fosters creativity. Come be part of our journey, where your ideas will fuel the next generation of secure cloud solutions!

Frequently Asked Questions (FAQs) for Senior Information Security Engineer - VAPT, Thick client application Role at Zscaler
What are the primary responsibilities of a Senior Information Security Engineer - VAPT at Zscaler?

As a Senior Information Security Engineer - VAPT at Zscaler, your core responsibilities will include conducting in-depth penetration tests on Zscaler's applications and infrastructure, implementing security automation, and continuously reviewing security bulletins and related news. You'll help prioritize vulnerabilities that need attention from our engineering and operations teams, ensuring a robust security posture for our cloud-based solutions.

Join Rise to see the full answer
What qualifications are required for the Senior Information Security Engineer - VAPT position at Zscaler?

To be considered for the Senior Information Security Engineer - VAPT position at Zscaler, you should have a minimum of 5 years of experience in manual security assessments, particularly in web applications and thick clients. Strong expertise in conducting pen tests across various platforms such as Windows, macOS, Linux, Android, and iOS is essential. Additionally, a solid grasp of security architecture, networking, and cryptography fundamentals is crucial.

Join Rise to see the full answer
How does Zscaler support the professional growth of their Senior Information Security Engineers - VAPT?

Zscaler is committed to fostering the professional development of its Senior Information Security Engineers - VAPT by offering continuous learning opportunities, including training sessions and workshops. We also encourage involvement in industry conferences and provide resources for certifications to help you stay ahead in the ever-evolving field of cybersecurity.

Join Rise to see the full answer
What skills make a Senior Information Security Engineer - VAPT stand out at Zscaler?

To stand out as a Senior Information Security Engineer - VAPT at Zscaler, having strong scripting skills to automate tasks, an ability to validate findings through root cause analysis, and flexibility to work in related areas such as container security, AI/ML security, and cloud security will set you apart. Your innovative mindset will contribute significantly to enhancing our security services.

Join Rise to see the full answer
What is the company culture like for Senior Information Security Engineers - VAPT at Zscaler?

The culture at Zscaler for Senior Information Security Engineers - VAPT is built on collaboration, inclusivity, and innovation. We strive to maintain an environment that encourages diverse perspectives and drives creativity. Being recognized as a Best Workplace in Technology, Zscaler offers a supportive atmosphere where engineers can thrive and make a meaningful impact.

Join Rise to see the full answer
Common Interview Questions for Senior Information Security Engineer - VAPT, Thick client application
Can you describe your experience with penetration testing for thick client applications?

In your response, highlight specific examples of penetration tests you've conducted on thick client applications, detailing the tools used and methodologies followed. Emphasize your understanding of the unique challenges posed by thick clients and how you approached them to identify vulnerabilities.

Join Rise to see the full answer
What security tools and frameworks are you proficient in as a Senior Information Security Engineer - VAPT?

Discuss the various security tools and frameworks you have experience with, such as OWASP ZAP, Burp Suite, Metasploit, or Nessus. Illustrate your proficiency by mentioning specific situations where you've effectively utilized these tools to enhance security assessments.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats and vulnerabilities?

Explain your methods for staying current with industry trends, such as following cybersecurity blogs, attending workshops or webinars, and engaging in professional networks. Mention any specific resources or communities you rely on to get the latest information on threats and vulnerabilities.

Join Rise to see the full answer
Can you walk us through your process for prioritizing security vulnerabilities?

Outline your methodology for assessing and prioritizing vulnerabilities, including risk assessment techniques, impact analysis, and collaboration with engineering teams. Being able to articulate a structured approach illustrates your thought process and decision-making skills.

Join Rise to see the full answer
What scripting languages are you comfortable with, and how have you used them in security automation?

Mention the scripting languages you're proficient in, such as Python or Bash, and provide examples of how you've used them for automating security tasks. This could include automating vulnerability scans, log analysis, or even generating reports.

Join Rise to see the full answer
Tell me about a challenging security issue you encountered and how you resolved it.

Choose a specific case where you faced a significant security challenge. Break down the problem, your approach to investigating it, the solution you implemented, and the impact it had on overall security posture.

Join Rise to see the full answer
How do you conduct a security architecture review?

Explain your approach to performing a security architecture review, including the frameworks or models you follow, the key components you assess, and how you communicate your findings to stakeholders to drive improvements.

Join Rise to see the full answer
What experience do you have with cloud security, and how does it relate to thick client applications?

Discuss your familiarity with cloud security principles and how they intersect with thick client applications. Provide examples of how you've assessed security in cloud environments, particularly regarding thick client integrations.

Join Rise to see the full answer
What role do you believe diversity plays in enhancing a security team’s effectiveness?

Share your thoughts on how diversity enriches problem-solving and innovation within a security team. Discuss any personal experiences where diverse perspectives led to a stronger security strategy or solution.

Join Rise to see the full answer
What is your understanding of the Zero Trust security model?

Articulate your knowledge of the Zero Trust model, explaining its principles and importance in modern cybersecurity strategies. Discuss any experience you have implementing Zero Trust concepts in previous roles.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago
Posted 10 days ago
Photo of the Rise User
Obrela Remote No location specified
Posted 22 hours ago
Photo of the Rise User
Devoteam Remote John M. Keynesplein 10, 1066 EP Amsterdam, Netherlands
Posted 10 days ago
Posted 4 days ago

Zscaler: Securing your cloud transformation We are passionate about being the best; the best global security company that enables mobile and enterprise businesses to be more secure, safer, and faster.

818 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
SALARY RANGE
$120,000/yr - $150,000/yr
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
January 28, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!