> Markdown version of [/jobs/ext/2472976-application-security-analyst](https://www.wearedevelopers.com/jobs/ext/2472976-application-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Analyst - **Company:** Stellantis - **Location:** Auburn Hills, MI, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** HTML, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Applications Architecture, Application Firewall, Automation of Tests, Microsoft Azure, Bash Shell, Burp Suite, C Sharp (Programming Language), Mobile Application Development, Cloud Computing, Code Review, Cyber Security, Information Systems, Computer Programming, Continuous Delivery, Continuous Integration, Github, Internet Security, Mobile Application Software, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Akamai, Secure Coding, Mobile Security, Software Engineering, SQL Databases, Web Applications, Scripting, Google Cloud, Software Security, Firewalls (Computer Science), Gitlab, Kubernetes, Information Technology, Cloudflare, Checkmarx, Teamcity, Ddos, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Dynamic Application Security Testing - **Published:** August 2, 2026 - **Apply:** https://www.careerbuilder.com/job-details/application-security-analyst-auburn-hills-mi--c3c003de-3740-4675-b57e-4ffd76dcaf85 ## About the Role Bachelor's degree in Computer Science, Information Technology, or related field * 3+ years of hands-on experience in application security, security testing, and DevSecOps * Strong understanding of: * Application architectures (web, mobile, APIs) * Software development methodologies (Agile, SDLC) * Modern programming languages (Java, C#, Python) * Experience performing and interpreting results from: * SAST, DAST, IAST, SCA, and mobile security testing tools * Hands-on experience with secure code review in common languages (Java, C#, Python preferred) * Prior background in application development, including: * Compiled code * Web applications / services * Mobile app development * Knowledge of security frameworks and standards: * NIST, ISO 27001 * NIST SSDF or similar secure development frameworks * Strong understanding of: * OWASP Top 10 vulnerabilities and mitigation techniques * Common attack vectors (web exploits, DDoS, bot attacks) * Experience with WAF technologies: * Akamai, Cloudflare, AWS WAF, Azure Front Door * Familiarity with cloud platforms and modern environments: * AWS, Azure, GCP * Containers (Docker, Kubernetes) * Working knowledge of: * Programming/scripting: Java, JavaScript, SQL, HTML * Scripting languages (Python, Bash preferred) * Strong analytical, problem-solving, and communication skills * Ability to explain technical risks to non-technical audiences * Experience writing security reports and documentation * Ability to work independently and cross-functionally Preferred Qualifications: * Industry certifications: * GIAC GWEB * ISC2 CSSLP * EC-Council CASE * Or equivalent AppSec certifications Skills: Agile Programming Methodologies, Analysis Skills, Applications Security, Cloud Computing, Code Reviews, Communication Skills, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cross-Functional, Firewalls, HTML (HyperText Markup Language), ISO (International Organization for Standardization), Information Technology & Information Systems, Internet Application, Internet Security, Java, JavaScript, Machine Tool, Microsoft C# (C Sharp), Mobile Applications Development, Problem Solving Skills, Programming Languages, Python Programming/Scripting Language, SQL (Structured Query Language), Scripting (Scripting Languages), Secure Coding, Security Analysis, Software Development, Software Development Lifecycle (SDLC), Test Tools, Testing, U.S. National Institute of Standards and Technology (NIST) ## Description Application Security & Testing * Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing * Analyze vulnerabilities and recommend secure coding fixes * Demonstrate vulnerabilities to development teams * Drive remediation efforts to closure DevSecOps & Tooling * Work within CI/CD pipelines using tools such as: * Jenkins, GitLab, GitHub Actions, TeamCity * Checkmarx, GitHub Advanced Security, Burp Suite * Integrate security controls into development workflows WAF & Security Controls * Lead Web Application Firewall (WAF) deployment for new and existing apps * Implement application security policies, controls, and standards Collaboration & Enablement * Partner with development, platform, and supplier teams * Provide clear remediation guidance * Train teams on secure coding and application security practices * Develop training materials Assessment & Reporting * Conduct security assessments using standard tools * Track and report: * Risks * Milestones * Deliverables * Status updates * Recommend strategies based on application risk posture ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)