> Markdown version of [/jobs/ext/1287257-application-security-analyst](https://www.wearedevelopers.com/jobs/ext/1287257-application-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Analyst - **Company:** Toyota Motor Sales, U.S.A., Inc. - **Location:** Plano, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), PHP (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Software Applications, Microsoft Azure, Code Review, Continuous Integration, Mobile Application Software, Python (Programming Language), Team Foundation Server, Open Web Application Security, Ansible, Software Engineering, Web Applications, Web Services, Scripting, Google Cloud, Delivery Pipeline, Software Security, Containerization, Kubernetes, Terraform, Docker, Jenkins, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** July 16, 2026 - **Apply:** https://www.juju.com/job/00000000ggze28 ## About the Role + Typically, 3-6 years of experience in application security, with significant hands-on experience using SAST/SCA/DAST tools and methodologies. + Proven expertise in testing complex web applications, APIs, and mobile applications for security vulnerabilities. + Strong understanding of application security standards (e.g., OWASP Top Ten, SANS CWE Top 25). + Familiarity with programming languages and frameworks commonly used in web and mobile applications, including Java, Python, Bash/Shell Scripting, PHP, Javascript, etc. + Strong understanding of CI/CD tools (e.g., Jenkins, Harness, GHA). + Familiarity with containerization and orchestration (Docker, Kubernetes). + Knowledge of cloud platforms (AWS, Azure, GCP) and their security features. + Knowledge of Infrastructure as Code (Terraform, Ansible). Added bonus if you have + Strong analytical and problem-solving skills. + Excellent communication and collaboration abilities. + Ability to work in a fast-paced, agile environment. + Ability to lead security testing initiatives and mentor junior security engineers. ## Description Toyota Financial Services (TFS) Technology team is looking for a highly motivated person to fill a role as a Application Security Analyst. Your responsibilities will be to ensure the security of company software applications, web services, and APIs. You will work closely with development teams to identify vulnerabilities, suggest remediation efforts, and integrate security controls into the DevOps pipeline. The role involves ensuring the security and integrity of our products and third-party software, providing guidance on security risks. What you'll be doing + Collaborate with developers to "shift left"-integrating security early in the software development life cycle (SDLC) + Integrate security tools like SAST, DAST, and SCA into development processes. + Review code for security vulnerabilities and provide guidance to developers on remediation and secure coding practices. + Prepare detailed vulnerability reports and dashboards for leadership, prioritizing risks based on business impact. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)