NIH - Application Scanning Analyst

cFocus Software Incorporated
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Application Configuration Access Protocols Middleware Systems Development Life Cycle Secure Coding Web Application Security Software Engineering Software Vulnerability Management Web Applications Web Services Software Security GWAPT
+5 more
Information Technology Devsecops Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Perform authenticated and unauthenticated web application vulnerability scans.
  • Conduct application security assessments against internally developed and commercial applications.
  • Perform Dynamic Application Security Testing (DAST) and support Static Application Security Testing (SAST) activities.
  • Assess APIs, web services, and middleware for security vulnerabilities.
  • Conduct application configuration reviews and identify security weaknesses.
  • Perform recurring vulnerability scans in accordance with Government-defined schedules.
  • Analyze application scan results to identify security vulnerabilities and misconfigurations.
  • Validate scan findings to eliminate false positives.
  • Prioritize vulnerabilities using risk-based methodologies, including CVSS scoring and exploitability.
  • Correlate application vulnerabilities with infrastructure and network risks.
  • Identify critical vulnerabilities requiring immediate remediation.
  • Perform root cause analysis for recurring application security issues.
  • Collaborate with software development teams to improve application security.
  • Provide remediation recommendations aligned with secure coding practices.
  • Assist developers with vulnerability mitigation strategies.
  • Support integration of security scanning into DevSecOps and CI/CD pipelines.
  • Recommend application security improvements throughout the software development lifecycle (SDLC).
  • Promote secure-by-design principles across NIH application environments.

Requirements

  • Public Trust Clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of experience performing application security assessments or web application vulnerability scanning.
  • Experience conducting authenticated and unauthenticated web application security testing.
  • Experience supporting enterprise vulnerability management programs.
  • Experience interpreting application security findings and developing remediation guidance.
  • Experience supporting Federal cybersecurity or large enterprise environments.
  • Preferred certifications include: GWAPT, GWEB, CSSLP, OSWA, or CEH

Benefits & conditions

Invitation for Job Applicants to Self-Identify as a U.S. Veteran

  • A ā€œdisabled veteranā€ is one of the following:
  • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
  • a person who was discharged or released from active duty because of a service-connected disability.
  • A ā€œrecently separated veteranā€ means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An ā€œactive duty wartime or campaign badge veteranā€ means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An ā€œArmed forces service medal veteranā€ means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on cfocussoftware.applytojob.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:18 min

Implementing routing middleware for seamless multi-fragment origination

Igor Minar Igor Minar +1 Ā· WWC 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal Ā· LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia Ā· LIVE

2:05 min

Unifying application security scanning to reduce developer fatigue

Mia Neethling Mia Neethling Ā· WWC 2025

4:19 min

Securing API requests with frontend interceptors and backend middlewares

Bartosz Pietrucha Ā· JS Congress

Videos

See all

Related articles

See all