> Markdown version of [/jobs/ext/1146589-job-description-security-analyst-security-engineer](https://www.wearedevelopers.com/jobs/ext/1146589-job-description-security-analyst-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Job Description: Security Analyst / Security Engineer - **Company:** The Maven - **Location:** Seattle, WA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Burp Suite, Cyber Security, DevOps, Identity and Access Management, Intrusion Detection Systems, Nmap, Open Web Application Security, Systems Development Life Cycle, Salesforce.Com, Secure Coding, Web Application Security, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Software Security, QRadar, Information Technology, Nessus, Microsoft Sentinel, Splunk, Qualys, Vulnerability Analysis - **Published:** June 30, 2026 - **Apply:** https://www.dice.com/job-detail/a7702d8b-93f2-4ad0-bf45-3dd31c556ba8 ## About the Role * Bachelor''s degree in Computer Science, Information Security, Cybersecurity, or a related field. * 7 years of experience in information security, application security, or security engineering. * Strong understanding of application security principles and the Secure SDLC. * Experience with vulnerability management tools such as Tenable, Qualys, Rapid7, or similar. * Hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar) and endpoint security solutions. * Knowledge of web application security concepts, including the OWASP Top 10. * Familiarity with common security testing tools such as Burp Suite, Nessus, Nmap, OWASP ZAP, or similar. * Understanding of authentication, authorization, encryption, and identity management concepts. * * Salesforce exp. is required ## Description We are seeking a skilled Security Analyst / Security Engineer to strengthen our organization''s cybersecurity posture. The ideal candidate will have experience in application security, vulnerability management, incident response, and collaborating with cross-functional security and engineering teams. This role is responsible for identifying, assessing, and mitigating security risks while ensuring compliance with organizational security standards and industry best practices., * Perform application security assessments, including secure code reviews and vulnerability identification. * Conduct vulnerability assessments and coordinate remediation efforts with development and infrastructure teams. * Monitor, investigate, and respond to security incidents, ensuring timely containment and resolution. * Analyze security alerts from SIEM, EDR, IDS/IPS, and other security monitoring tools. * Collaborate with development, DevOps, infrastructure, and security teams to integrate security throughout the software development lifecycle (SDLC). * Support penetration testing activities and validate remediation of identified vulnerabilities. * Assist in threat modeling, risk assessments, and security architecture reviews. * Develop and maintain security policies, standards, and technical documentation. * Participate in incident response planning, forensic investigations, and post-incident reviews. * Recommend and implement security controls to reduce organizational risk. * Stay informed about emerging threats, vulnerabilities, and industry best practices. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)