> Markdown version of [/jobs/ext/1318114-application-security-analyst](https://www.wearedevelopers.com/jobs/ext/1318114-application-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Analyst - **Company:** Sound Physicians - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $75,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Applications Architecture, Software System Penetration Testing, Automation of Tests, Microsoft Azure, Bash Shell, Burp Suite, C Sharp (Programming Language), Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Continuous Integration, DevOps, Github, Python (Programming Language), Key Management, OpenShift, Open Web Application Security, PCI Data Security Standards, Public Key Infrastructure, Windows PowerShell, Systems Development Life Cycle, Fortify (Software), Secure Coding, SonarQube, Software Vulnerability Management, Web Applications, SSL Certificate Management, Sonatype, Software Security, Mitre Att&ck, Veracode, GWAPT, Containerization, Gitlab-ci, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Azure AKS, Checkmarx, Terraform, Software Version Control, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0c296dde0ffe66ce ## About the Role * Strong understanding of application security concepts, secure coding practices, and common attack vectors. * Strong understanding of application security concepts, secure coding practices, and common attack vectors. * Knowledge of security testing methodologies including SAST, DAST, SCA, penetration testing, secret scanning, and IaC security assessments. * Familiarity with cloud platforms such as Azure and AWS. * Familiarity with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab CI, or Jenkins. * Knowledge of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and NIST Cybersecurity Framework. * Experience with application security platforms such as Veracode, Checkmarx, Fortify, SonarQube, Snyk, Mend, Burp Suite, Rapid7 InsightAppSec, or similar tools. * Familiarity with scripting and automation using Python, Powershell, Bash, or similar languages. * Experience securing containerized applications and platforms (Docker, Kubernetes, OpenShift, AKS, EKS, or GKE), including container image scanning, runtime security monitoring, admission controls, and Kubernetes security best practices. * Knowledge of container technologies, source control workflows, and modern software delivery practices. * Familiarity with common static and dynamic application security tools. * Ability to analyze security findings, assess risk, and communicate remediation recommendations effectively to technical and non-technical stakeholders. * Familiarity with AI-assisted development processes and appropriate security controls. * Strong written and verbal communication skills. * Ability to translate technical issues into clear guidance and action plans * Knowledge of cloud-native security controls. * Familiarity with Kubernetes, Terraform, and similar Infrastructure-as-Code tools. * Familiarity with secrets management, PKI, certificate management, and cryptographic controls. * Knowledge of compliance frameworks such as NIST CSF, NIST 800-53, HIPAA, PCI DSS, SOC 2, ISO 27001, and HITRUST., * Bachelor's degree in Computer Science, Information Security, or related field, with industry-recognized certifications such as CSSLP (Certified Secure Software Lifecycle Professional), GWAPT (GIAC Web Application Penetration Tester), OSWE (Offensive Security Web Expert), CEH (Certified Ethical Hacker) * 4+ years of experience in application security, DevOps, cloud security, security engineering, or a related cybersecurity role. * Knowledge of scripting and programming languages such as Python, PowerShell, Java, JavaScript, C#, or Go is highly desirable and considered a plus. * Experience supporting regulated environments such as healthcare, financial services, or other compliance-driven industries. ## Description The Application Security Analyst helps embed security into the software delivery lifecycle by partnering with development, platform, cloud, and security teams to build secure-by-default processes. This role focuses on reducing risk through automation, continuous testing, secure configuration, and practical guidance that enables teams to ship software quickly and safely. The ideal candidate possesses a strong understanding of application security principles, secure coding practices, cloud security controls, vulnerability management, and modern DevSecOps methodologies., * Integrate security controls and automated checks into CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secret scanning, container security scanning, and Infrastructure-as-Code (IaC) validation. * Partner with developers and platform engineers to identify, prioritize, and remediate application, API, container, and cloud security risks early in the development lifecycle. * Perform application security assessments, architecture reviews, and threat modeling exercises for new and existing applications. * Support vulnerability management by validating findings, reducing false positives, tracking remediation, and helping define risk-based service-level expectations. * Conduct secure code reviews and provide guidance on secure coding practices aligned with OWASP Top 10, CWE, and industry standards. * Perform security reviews for application architecture, deployment patterns, third-party components, and cloud configurations. * Develop and maintain secure pipeline standards, reusable guardrails, and policy-as-code checks that improve consistency without creating unnecessary delivery friction. * Collaborate with engineering, infrastructure, and security operations teams on incident response, root cause analysis, and hardening activities related to software delivery platforms. * Create and maintain documentation, standards, playbooks, and training materials related to application security, secure development, and DevSecOps practices. * Track vulnerability trends, security metrics, and recurring issues to improve security maturity across build, release, and runtime workflows. * Stay current on emerging threats, attack techniques, vulnerabilities, and security technologies relevant to application and cloud security. Values * Collaborative: Demonstrates the ability to work well with others to accomplish a goal and get the work done; takes opinions of others into consideration; includes others in the decision-making process. * Eager to Learn: Proactively seeks out information, embraces learning new things and enjoys the learning process. * Intellectually curious: Demonstrates a genuine interest in learning new things and wants to know the reason "why" behind the way things are done. * Committed: Demonstrates dedication to the job, project, organization, customer/clients and co-workers. * Resourceful: Proactive willingness to utilize available information and tools to figure things out. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)