> Markdown version of [/jobs/ext/1551025-nih-application-scanning-analyst](https://www.wearedevelopers.com/jobs/ext/1551025-nih-application-scanning-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NIH - Application Scanning Analyst - **Company:** cFocus Software Incorporated - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Application Configuration Access Protocols, Middleware, Systems Development Life Cycle, Secure Coding, Web Application Security, Software Engineering, Software Vulnerability Management, Web Applications, Web Services, Software Security, GWAPT, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 3, 2026 - **Apply:** http://cfocussoftware.applytojob.com/apply/jobs/details/BGTXCL9Bo8 ## About the Role * Public Trust Clearance * B.S. Computer Science, Information Technology, or a related field * 5+ years of experience performing application security assessments or web application vulnerability scanning. * Experience conducting authenticated and unauthenticated web application security testing. * Experience supporting enterprise vulnerability management programs. * Experience interpreting application security findings and developing remediation guidance. * Experience supporting Federal cybersecurity or large enterprise environments. * Preferred certifications include: GWAPT, GWEB, CSSLP, OSWA, or CEH ## Description * Perform authenticated and unauthenticated web application vulnerability scans. * Conduct application security assessments against internally developed and commercial applications. * Perform Dynamic Application Security Testing (DAST) and support Static Application Security Testing (SAST) activities. * Assess APIs, web services, and middleware for security vulnerabilities. * Conduct application configuration reviews and identify security weaknesses. * Perform recurring vulnerability scans in accordance with Government-defined schedules. * Analyze application scan results to identify security vulnerabilities and misconfigurations. * Validate scan findings to eliminate false positives. * Prioritize vulnerabilities using risk-based methodologies, including CVSS scoring and exploitability. * Correlate application vulnerabilities with infrastructure and network risks. * Identify critical vulnerabilities requiring immediate remediation. * Perform root cause analysis for recurring application security issues. * Collaborate with software development teams to improve application security. * Provide remediation recommendations aligned with secure coding practices. * Assist developers with vulnerability mitigation strategies. * Support integration of security scanning into DevSecOps and CI/CD pipelines. * Recommend application security improvements throughout the software development lifecycle (SDLC). * Promote secure-by-design principles across NIH application environments. ## Related Videos - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) - [Developer’s Perspective: Overview of the Tezos Blockchain Ecosystem](https://www.wearedevelopers.com/videos/237-developer-s-perspective-overview-of-the-tezos-blockchain-ecosystem) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Exploring BOS: The Blockchain Operating System by NEAR Protocol](https://www.wearedevelopers.com/videos/781-exploring-bos-the-blockchain-operating-system-by-near-protocol) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)