> Markdown version of [/jobs/ext/2219928-cyber-security-analyst-iii-app-security-and-vulnerability-remote](https://www.wearedevelopers.com/jobs/ext/2219928-cyber-security-analyst-iii-app-security-and-vulnerability-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst III - App Security and Vulnerability (Remote) - **Company:** First Citizens - **Location:** Austin, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Automation of Tests, Microsoft Azure, Bash Shell, Burp Suite, Cloud Computing Security, Static Program Analysis, CompTIA Security+, Cyber Security, Computer Programming, Github, Python (Programming Language), Machine Learning, Open Web Application Security, Systems Development Life Cycle, Fortify (Software), Web Application Security, SoapUI, Software Engineering, Software Vulnerability Management, Scripting, Google Cloud, Postman, Sonatype, Software Security, Veracode, Cross-Site Scripting (XSS), Checkmarx, Virtual Agents, Data Pipelines, Devsecops, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/d550ebc7-50e6-4d8d-92b3-38bfeb634718 ## About the Role Minimum Required Education and Experience: Bachelor's Degree and 6 years' experience., High School Diploma or GED/Equivalent and 10 years' experience in Information Security., * Hands-on experience with: + SAST, DAST, and SCA tools + Web application security testing (OWASP Top 10, API security) * Strong understanding of: + Secure software development lifecycle (SDLC / DevSecOps) + Common vulnerabilities (e.g., injection, XSS, authentication flaws) * Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash) * Experience interpreting and prioritizing scan results and remediation plans, * Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps) * Familiarity of container and cloud security (AWS, Azure, Google Cloud Platform) * Familiarity with AI/ML concepts and security implications * Industry certifications such as: * CEH, Security+, SSCP, GIAC or comparable. Key Skills: * Strong analytical and problem-solving skills * Provide risk-based recommendations to stakeholders * Ability to communicate technical findings to both technical and non-technical stakeholders * Experience working cross-functionally with development and engineering teams * Attention to detail with a risk-based security mindset Nice-to-Have Experience: * API security testing tools (Postman, SoapUI) * AI-assisted security tooling (e.g., anomaly detection, code analysis assistants) * Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2) * AI/ML & Emerging Technologies * Leverage AI/ML-based security tools for enhanced detection and analysis * Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks) * Participate in securing AI-driven applications and data pipelines Threat Analysis & Risk Management * Assess potential threats and attack vectors relevant to applications and APIs * Apply threat modeling techniques (e.g., STRIDE) during development lifecycle ## Description We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role focuses on identifying, analyzing, and mitigating security risks across software development pipelines using SAST, DAST, and SCA tools. The ideal candidate combines hands-on technical expertise with knowledge of modern security practices and emerging technologies, including AI/ML., Application Security & Code Analysis * Perform static (SAST), dynamic (DAST), and software composition analysis (SCA) to identify vulnerabilities in applications and third-party components * Analyze scan results, triage findings, and prioritize remediation efforts based on risk * Partner with development teams to remediate vulnerabilities and improve secure coding practices Vulnerability Management * Conduct regular security assessments and vulnerability scans across applications and environments * Validate and reproduce vulnerabilities, including false positive elimination * Track and report vulnerability metrics, risk trends, and remediation progress Security Tools & Automation * Configure, deploy, and maintain security scanning tools (e.g., Checkmarx, Veracode, Fortify, Snyk, Burp Suite, OWASP ZAP) * Automate security testing processes using scripting or APIs * Improve scanning efficiency and coverage through tuning and optimization ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)