Performs manual penetration testing of web, mobile, API, and microservices applications; conducts secure code reviews and design assessments; identifies and validates vulnerabilities; documents findings; supports remediation and incident response; guides junior testers; and promotes secure coding and application security awareness.
What You'll Do: The Application Security Analyst in Enterprise will report to the Application Security Lead
What You'll Bring:
- Typical daily work will consist of independently performing manual application penetration tests on web, mobile, APIs, and microservices across production and pre-production environments under defined testing scopes.
- Conduct secure code reviews and assist in design-level security assessments in collaboration with development and DevSecOps teams.
- Identify, validate, and document application security vulnerabilities related to OWASP Top 10, SANS Top 25, misconfigurations, and common insecure coding or design patterns.
- Provide technical guidance to junior AppSec testers, review assessment outputs, validate findings, and support skill development through peer reviews and knowledge sharing.
- Utilize industry-standard tools such as Burp Suite Pro, OWASP ZAP, Snyk, Checkmarx, Black Duck, Postman, and custom scripts to identify vulnerabilities at both runtime and source code levels.
- Ensure high-quality security testing by following established testing standards, performing peer validation of findings, and ensuring vulnerabilities are accurate, reproducible, and well-evidenced.
- Collaborate closely with developers, QA engineers, and architects to support remediation efforts and promote secure coding practices.
- Assist in providing security awareness and guidance to internal stakeholders to improve application security maturity.
- Support incident response activities by assisting in root cause analysis, vulnerability validation, and post-incident security assessments related to application security issues.
What You'll Bring:
- Bachelor's in computer science /management of computer information/information assurance or Cybersecurity
- 0-4 years of Penetration Testing / Application Security / Offensive Security
- Must have Security Certifications: OSCP/eWPTx and OSWA/OSWE/CWES/CWEE
- Preferred Security Certifications: CRTP/CARTP, CRTE, OSEP, GRTP
- Preferred Security Cloud Certifications: AWS CLP, AWS Security Specialty
- Must be a self-starter who can learn quickly and independently.
- Fluency in English
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
ZS London, England Office

Opened in 1993, our London office helped ZS expand into Europe. As one of the most diverse offices in Europe, London is central to how ZS innovates healthcare and beyond.
Similar Jobs at ZS
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Manage AWS infrastructure across Prod/Stage/Dev, handle incident management and root cause analysis for core AWS services, ensure availability and performance, monitor health and cost, perform access management and resource optimization, support Terraform-based provisioning, automate operational tasks, and work with CI/CD pipelines while collaborating with Engineering, Security, and Data teams.
Top Skills:
AWSCi/CdCloudwatchCost ExplorerEc2EmrIamLambdaRdsS3Terraform
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Lead the evolution of ZS’s global finance technology ecosystem, including SAP S/4HANA migration from SAP ECC. Translate finance requirements into scalable systems and process solutions, coordinate enhancements and integrations, strengthen forecasting, revenue recognition, close, project finance, reporting, governance, and controls, and support adoption and change management across global teams.
Top Skills:
CRMHr SystemsReporting And Analytics PlatformsSap EccSap Fi/CoSap Professional Services (Ps)Sap S/4HanaWorkflow Systems
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Lead the enterprise-wide data security and governance strategy, establishing policies, controls, classification standards, lifecycle processes, and compliance practices. Oversee data security tooling across cloud, SaaS, and hybrid environments, including DLP, DSPM, data catalogs, SIEM, IAM, and encryption integrations. Manage risk assessments, incident response, breach remediation, stakeholder adoption, training, and governance KPIs. Lead and mentor a team of data security professionals while managing tooling and organizational change.
Top Skills:
AlationApi SecurityAtlanBigidCcpaCloud-Native SecurityCollibraData CatalogsData ClassificationData DiscoveryData LineageData Loss Prevention (Dlp)DspmEncryptionGdprHipaaIamInformaticaMicrosoft PurviewPci DssSIEMSoxZscaler Dlp
What you need to know about the London Tech Scene
London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.


