Information Security Technical Analyst

21Tech, LLC
United States
2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$114,109.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure Cloud Computing Cyber Security Open Web Application Security Web Application Security Web Applications Scripting Google Cloud Containerization
+2 more
Information Technology Vulnerability Analysis

Job description

  • Manage and maintain the flow of incoming vulnerability cases, including CVE notifications, cloud-based vulnerabilities, cloud misconfigurations, access control issues, web application vulnerabilities, and source code vulnerabilities.
  • Conduct technical assessments of vulnerabilities to assist engineering teams and DRIs with remediation efforts, including the implementation of available patches where possible.
  • Partner across security and product teams to identify and resolve vulnerabilities and security issues using a prioritized approach that is grounded in risk management principles.
  • Research and report on vendor advisories, zero-day vulnerabilities, bug trackers, and other sources to gather intelligence and analyze any potential impact to Client.
  • Manage the risk exception process by partnering across Security teams to identify areas of risk and collaborate with business units to make informed, risk-based decisions.
  • Proactively identify opportunities to reduce toil by suggesting and championing the automation of manual triage, case management, and escalation workflows.
  • Minimize recurring vulnerabilities by collaborating with partners to identify and solve root causes, ensuring long-term remediation.
  • Monitor vulnerability metrics, including backlog status, historical trends, and remediation rates, to assess the overall security posture of the organization.
  • Maintain runbooks or playbooks and document any new processes or procedures.
  • Collaborate with Engineering and Compliance teams to manage penetration testing (pentest) results and address PCI-related vulnerabilities.
  • Support ongoing bug bounty programs with a third-party vendor and internal stakeholders to prioritize and fix vulnerabilities.
  • Support ongoing and periodic security risk assessment exercises that involve identifying, evaluating, and monitoring cybersecurity risks using both quantitative and qualitative methodologies.
  • Collaborate with cross-functional teams (engineering, product, and others) to gather relevant data required for risk analysis and provide domain and subject matter expertise in security and risk.
  • Support risk mitigation and control improvement actions to drive risk remediation.
  • Support the adoption, evolution, and continuous improvement of a risk program.

Requirements

Do you have experience in Web Application Security Testing?, This position is a remote 12-month contract. You must be able to work in the PT zone, and be authorized to work in the US, no H1B Visa status. Hourly rate is $54.86, W2 + paid holidays through Talent Table. NO C2C., * Five or more years of demonstrated security, intelligence, and risk management experience in a technology-focused company.

  • General understanding of cloud infrastructure (AWS, GCP, Azure), networking, and containerization.
  • Experience with scripting to design and implement security automation workflows.
  • Experience with multiple vulnerability scanning tools.
  • Deep technical understanding of common security vulnerabilities such as web application vulnerabilities, OWASP Top 10, cloud vulnerabilities and misconfigurations, and source code vulnerabilities.
  • Strong knowledge of risk countermeasures and compensating controls.
  • Ability to work independently and in a collaborative environment with excellent communication and interpersonal skills.
  • Minimum of 5 years of experience in Information Security, Information Technology, or a related field.
  • Information Security degree preferred., * Fundamental knowledge of information security principles, including threats, vulnerabilities, and risk management.
  • Proficient in utilizing AI agents and workflow automation for process improvements.
  • Technical problem-solving mindset with a strong work ethic, motivation, and results-driven attitude.
  • Holds security certifications such as CISSP, Security+, CySA+, or equivalent GIAC certifications.

Benefits & conditions

Pulled from the full job description

  • Paid holidays

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all