
Application Security Analyst
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in Arizona, +1 more state.
• Assist in monitoring and supporting the enterprise information security framework as instructed by management.
• Oversee daily operations and provide support for Application Security tools, including resolving incidents and tickets.
• Offer expertise during security incidents, document observations, and contribute to the enhancement of protocols.
• Maintain and upgrade platforms related to application security.
• Refine application security policies and rulesets.
• Integrate security tools such as SAST and DAST within CI/CD pipelines and workloads.
• Conduct security assessments of Terraform configurations and reusable Infrastructure as Code modules.
• Verify Terraform modifications for security, compliance, and conformity with established cloud architecture standards.
• Monitor code repositories and resources for potential security threats.
• Investigate and respond to security incidents and findings.
• Develop SIEM queries and analyze the outcomes.
• Address findings from security tools and collaborate with business and IT partners on remediation efforts.
• Implement, configure, manage, and support Web Application Firewalls, including the tuning of rulesets and policies.
• Participate in application security projects and initiatives.
• Execute special projects as required.
• Support and uphold EMCOR’s Security Program.
• A minimum of 3 years of practical experience in an Application Security, Product Security, DevOps, or DevSecOps role.
• Proficiency in working with cloud platforms such as Azure, AWS, GCP, and OCI.
• Experience with CI/CD and developer workflow automation tools like GitHub Actions and Azure DevOps Pipelines.
• Background in developing or reviewing Terraform for Azure infrastructure deployment, including reusable modules.
• Experience in managing and fine-tuning Web Application Firewall (WAF) policies, particularly for Azure Front Door.
• Proven experience in triaging and addressing vulnerabilities identified by GitHub Advanced Security (GHAS) or Microsoft Defender for Cloud, including CodeQL, Secret Scanning, and Dependency Review.
• Demonstrated expertise in using PowerShell for administrative and automation tasks.
• Strong communication skills, with the ability to interact professionally across all organizational levels.
• Excellent project management skills.
• Commitment to consistently providing outstanding customer service.
• Medical coverage
• Dental coverage
• Vision coverage
• Health savings accounts
• Flexible spending accounts
• Life insurance
• Disability insurance
• 401(k) Savings Plan
• College Coach
• Employee assistance program
• Bonus eligible
• Competitive salary and benefits package
Vision Cybersecurity
Stefanini LATAM
Bancorbrás
Kemper
Get handpicked remote jobs straight to your inbox weekly.