Associate Security Analyst (Application Security) Contractual -ITDSGGR

International Monetary Fund
Washington, DC, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) .NET Framework Artificial Intelligence Software System Penetration Testing Microsoft Azure Software as a Service Static Program Analysis Cyber Security Computer Programming Dynamic Program Analysis Information Systems Security Architecture Professional Python (Programming Language)
+16 more
Open Web Application Security Systems Development Life Cycle Power BI Secure Coding Software Engineering Software Vulnerability Management Web Applications Scripting Enterprise Software Applications Software Security Software Application Programming Information Technology Servicenow Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

The Associate Security Analyst (Application Security) supports the integration of security throughout the Software Development Lifecycle (SDLC) by collaborating with development, infrastructure, and application teams to support vulnerability remediation efforts, application security initiatives, and secure development practices. The successful candidate combines foundational application security knowledge with strong coordination, communication, and stakeholder engagement skills to help maintain the security posture of enterprise applications while supporting continuous process improvement., Application Security & Secure SDLC

  • Collaborate with technical teams to promote secure coding practices and support the implementation of Secure SDLC standards, including security requirements for application design and development.
  • Assist in integrating application security tools, such as SAST, DAST, and SCA into CI/CD pipelines, and participate in threat modeling and security design reviews under the guidance of senior engineers.

Vulnerability Management & Security Controls

  • Review security testing results and support remediation efforts for identified vulnerabilities.
  • Help implement security controls for applications deployed in both on-premises and cloud environments.
  • Assist in tracking vulnerability remediation activities and supporting the timely closure of identified findings in collaboration with application and engineering teams.

Security Awareness & Continuous Improvement

  • Support training efforts and knowledge sharing on secure development practices within engineering teams.
  • Stay current with emerging security threats, vulnerabilities, and industry best practices to provide application security guidance to technical teams.

Requirements

  • Educational development, typically acquired by the completion of an advanced university degree, or equivalent, in Computer Science, Cybersecurity, or a related field; or a university degree, or equivalent, supplemented by a minimum of six (6) years of relevant professional experience;
  • Experience in Vulnerability Management, Application Security, Secure Development or related cybersecurity disciplines.
  • Familiarity with security frameworks and standards such as OWASP Top 10, NIST and secure development practices.
  • Experience with one or more programming or scripting languages (e.g., Java, Python, .NET)
  • Understanding of secure architecture principles for web-based and cloud-based applications.
  • Exposure to security testing methodologies and tools, including static analysis, dynamic analysis, vulnerability scanning, and penetration testing.
  • Experience supporting cross-functional initiatives involving multiple stakeholders, technical teams, and business partners.
  • Strong communication, project coordination, organizational, analytical, and collaboration skills, with the ability to manage multiple priorities and track deliverables effectively.

Preferred Qualifications

  • Certifications, such SSCP, Security+, or working toward CISSP or similar.
  • Experience with ServiceNow, Azure DevOps, and Microsoft Azure cloud technologies.
  • Experience using Power BI and AI-enabled tools to support reporting, analytics, and operational efficiency.

This is a one-year contractual appointment. Contractual appointments at the IMF are renewable for up to four years of cumulative contractual service, pending incumbent’s performance, budget availability, and continuous business need.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:46 min

Traditional data architecture before Microsoft Fabric

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · WWC 2025

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all