
Application Security Analyst
Posted Jul 16

Posted Jul 16
This is a fully remote position, open to applicants in United States.
• Integrate security measures and automated verifications into CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secret scanning, container security scanning, and Infrastructure-as-Code (IaC) validation.
• Collaborate with developers and platform engineers to identify, prioritize, and mitigate application, API, container, and cloud security vulnerabilities early in the development process.
• Conduct application security evaluations, architecture assessments, and threat modeling sessions for both new and existing applications.
• Perform secure code reviews and offer guidance on secure coding practices that align with OWASP Top 10, CWE, and industry standards.
• Assist in vulnerability management by confirming findings, minimizing false positives, tracking remediation efforts, and helping to define risk-based service-level expectations.
• Develop and maintain documentation, standards, playbooks, and training materials related to application security, secure development, and DevSecOps methodologies.
• Bachelor's degree in Computer Science, Information Security, or a related discipline.
• Over 4 years of experience in application security, DevOps, cloud security, security engineering, or a related cybersecurity field.
• Proficiency in scripting and programming languages such as Python, PowerShell, Java, JavaScript, C#, or Go is highly desirable and considered an asset.
• Comprehensive understanding of application security principles, secure coding practices, and common attack vectors.
• Familiarity with cloud environments such as Azure and AWS.
• Experience with CI/CD tools like Azure DevOps, GitHub Actions, GitLab CI, or Jenkins.
• Knowledge of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and the NIST Cybersecurity Framework.
• Familiarity with common static and dynamic application security tools.
• Experience with application security solutions such as Veracode, Checkmarx, Fortify, SonarQube, Snyk, Mend, Burp Suite, Rapid7 InsightAppSec, or equivalent tools.
• Experience in securing containerized applications and platforms (Docker, Kubernetes, OpenShift, AKS, EKS, or GKE), including container image scanning, runtime security monitoring, admission controls, and Kubernetes security best practices.
• Ability to analyze security findings, evaluate risk, and effectively communicate remediation recommendations to both technical and non-technical audiences.
• Familiarity with AI-assisted development processes and the relevant security measures.
• Excellent written and verbal communication skills.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Health care and dependent care flexible spending account.
• 401(k) retirement savings plan with a company match.
• Paid time off (PTO) begins accruing immediately upon start date at a rate of 15 days per year, in accordance with Sound's PTO policy.
• Ten company-paid holidays per year.
Cresol Cooperativa
LTS
Equity Resources, Inc
IronArch Technology
Get handpicked remote jobs straight to your inbox weekly.