Staff Software Development Engineer (Application Security)

Zscaler is the operator of the world's largest security cloud, accelerating digital transformation for enterprises to be more agile, efficient, resilient, and secure.
Security
Staff Software Engineer
Hybrid
1,000 - 5,000 Employees
7+ years of experience
Cybersecurity · Enterprise SaaS

Description For Staff Software Development Engineer (Application Security)

Zscaler, a leading cloud security company, is seeking an experienced Application Security Lead to join their Product Security team. Reporting to the Director of Vulnerability Management, you'll be responsible for:

  1. Static and Dynamic Application Security Testing (SAST/DAST): Conduct static and dynamic analysis of applications to identify and improve security vulnerabilities early in the development process.

  2. Software Composition Analysis (SCA): Implement SCA tools to manage open-source components, ensuring all third-party libraries and frameworks are secure and up-to-date.

  3. CVE Detection and Remediation: Monitor for Common Vulnerabilities and Exposures (CVEs) in the codebase and work with development teams to fix these vulnerabilities promptly.

  4. Secret Management: Detect and improve hard-coded secrets in the codebase, ensuring sensitive information is securely managed and stored.

  5. Container and Infrastructure as Code (IAC) Security: Assess and secure containerized environments and IAC deployments, following security best practices.

The ideal candidate will have:

  • Minimum 7 years of hands-on experience in application security
  • Proficiency with tools like Snyk, Semgrep, Coverity, Checkmarx, Burp Suite, OWASP ZAP, and dependency management tools
  • Experience with secure coding practices, vulnerability management, and remediation techniques
  • Expertise with source control (Github, Bitbucket) and CI pipelines (ArgoCD, Jenkins)
  • Experience detecting and remediating security issues within codebases

Preferred qualifications include:

  • 3+ years of hands-on experience in SAST, DAST, Container Security, IAC, or Secrets management
  • Previous experience as a software developer or in a DevSecOps role
  • Proficiency in languages such as Java, Python, JavaScript, C/C++, and Golang
  • Experience securing cloud environments (AWS, Azure, Google Cloud)

Zscaler offers comprehensive benefits, including various health plans, time off, parental leave, retirement options, and education reimbursement. The company is committed to diversity, equity, and inclusion, welcoming applicants from all backgrounds to contribute to their mission of making business seamless and secure.

Last updated 2 months ago

Responsibilities For Staff Software Development Engineer (Application Security)

  • Conduct static and dynamic analysis of applications
  • Implement Software Composition Analysis (SCA) tools
  • Monitor for Common Vulnerabilities and Exposures (CVEs)
  • Detect and improve hard-coded secrets in the codebase
  • Assess and secure containerized environments and IAC deployments

Requirements For Staff Software Development Engineer (Application Security)

Java
Python
JavaScript
Kubernetes
  • Minimum of 7 years of hands-on experience in application security
  • Proficiency with application security tools (Snyk, Semgrep, Coverity, Checkmarx, Burp Suite, OWASP ZAP)
  • Experience with secure coding practices and vulnerability management
  • Expertise with source control (Github, Bitbucket) and CI pipelines (ArgoCD, Jenkins)
  • Experience detecting and remediating security issues within codebases

Benefits For Staff Software Development Engineer (Application Security)

Medical Insurance
Dental Insurance
Vision Insurance
Parental Leave
401k
  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks

Interested in this job?

Jobs Related To Zscaler Staff Software Development Engineer (Application Security)

Sr. Staff Automation Engineer

Sr. Staff Automation Engineer role at Zscaler, developing security testing frameworks and implementing cloud security measures with 8+ years of experience required.

Staff Software Engineer - Customer Reliability Engineering

Staff Software Engineer position at Zscaler focusing on customer reliability engineering and cloud security solutions.

Staff Software Engineer, Secure Development Engineering

Lead security engineering initiatives at Airbnb, architecting and implementing secure development solutions that protect millions of users while empowering thousands of developers.

Staff Security Engineer, EMEA

Lead security investigations and threat detection at Airbnb EMEA, developing scalable tools and mentoring team members in forensic analysis and incident response.

Senior Cloud Security Architect

Senior Cloud Security Architect position at Google's Mandiant division, focusing on cybersecurity transformation services and enterprise security architecture.