- Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
- Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
- Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
- Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
- Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
- Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
- Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
- Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
- Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.
What You'll Bring:
- Bachelor's in computer science /management of computer information/information assurance or Cybersecurity
- 0-4 years of Penetration Testing / Application Security / Offensive Security
- Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
- Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
- Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
- Must be a self-starter who can learn quickly and independently.
- Fluency in English
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
Skills Required
- Bachelor's degree in computer science, management of computer information, information assurance, or cybersecurity
- 0-4 years of penetration testing, application security, or offensive security experience
- OSCP or eWPTx certification
- OSWA, OSWE, CWES, or CWEE certification
- Fluency in English
- Self-starter with ability to learn quickly and independently
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
- CRTP, CARTP, CRTE, OSEP, or GRTP certification
- AWS Cloud Practitioner or AWS Security Specialty certification
ZS Compensation & Benefits Highlights
-
Healthcare Strength — Medical through UMR/UnitedHealthcare with CVS Caremark, fully covered vision exams with an eyewear allowance, robust dental (including orthodontia), and multiple mental‑health options (Talkspace, Bend Health, EAP) indicate a broad, high‑quality package. Additional programs like Sword for musculoskeletal care and company‑paid life and disability coverage further reinforce the depth of health protections.
-
Parental & Family Support — Family‑forming and hormonal‑health coverage via Carrot is described up to $95,000, alongside adoption support, backup care for children/elders/pets, and Milk Stork for business‑traveling parents. Paid family leave is outlined at 10 weeks, with birth mothers potentially reaching up to 16 weeks when combined with the Family Leave Program.
-
Leave & Time Off Breadth — Vacation starts at 15 days per year and increases to 20 days after 36 months, paired with 11 company holidays and a floating holiday. Sick leave with rollover and bereavement provisions add practical flexibility around time away.
ZS Insights
What We Do
ZS is a management consulting and technology firm that partners with companies to improve life and how we live it. We transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Founded in 1983, ZS has more than 15,000+ employees in over 40 offices worldwide.
Why Work With Us
ZS is home to passionate people who embrace innovative thinking, collaboration and a client-first mindset. Welcome to a company where new ideas are celebrated, curiosity is welcomed, learning opportunities are abundant and colleagues become lifelong connections.
Gallery
ZS Teams
ZS Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
The Flexible & Connected model is our ZS standard. ZSers decide where it makes the most sense for them to work each day given client or teamwork.













































































