> Markdown version of [/jobs/ext/2707477-security-test-evaluation-analyst](https://www.wearedevelopers.com/jobs/ext/2707477-security-test-evaluation-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Test & Evaluation Analyst - **Company:** Advance Digital Systems - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Application Testing, Microsoft Azure, Cloud Computing Security, Code Review, Databases, Cross-Site Request Forgery, Database Security, Kali Linux, Network Protocols, Fortify (Software), Web Application Security, SQL Injection, Cloud Platform System, Cross-Site Scripting (XSS), Gitlab, Tenable Nessus, Servicenow, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/41b52fc8-bb5c-4d0b-bedd-0e5059eb213c ## About the Role * 5+ years of security testing and evaluation experience using tools such as Tenable Nessus, GitLab, Fortify, Invicti, Mandiant, Kali Linux, and Wiz. * 3+ years of cloud security testing experience across AWS, Azure, ServiceNow, or similar platforms. * Demonstrated experience performing ethical hacking and penetration testing across the full assessment lifecycle. * Hands-on experience implementing AI solutions for security testing and evaluation. * Strong experience identifying, validating, and assessing vulnerabilities across applications, operating systems, networks, databases, APIs, and cloud environments. * Knowledge of common attack vectors and vulnerabilities, including SQL injection, XSS, CSRF, and system/network weaknesses. * Strong understanding of network protocols, security technologies, OS hardening, database security, and web application security. * Experience working in government environments governed by NIST, FISMA, FedRAMP, and OMB guidance preferred. * Strong analytical, problem-solving, communication, and technical documentation skills. ## Description Seeking a Security Test & Evaluation Analyst with hands-on experience applying AI to security testing, vulnerability assessment, control evaluation, and ethical hacking. The ideal candidate combines strong traditional security assessment expertise with experience using AI technologies to enhance testing, identify vulnerabilities, assess risk, and develop scalable security evaluation capabilities across on-premises and cloud environments., * Conduct comprehensive security assessments and ethical hacking activities, including reconnaissance, scanning, exploitation, and post-exploitation. * Perform static and dynamic application testing, code reviews, architecture assessments, and security control evaluations. * Design and implement AI-enabled security testing and assessment solutions and integrate AI capabilities into existing security processes. * Analyze AI-generated and security-tool outputs to identify vulnerabilities, assess exploitability, and recommend remediation strategies. * Conduct authenticated and unauthenticated security testing, including scenario-based and functional assessments. * Develop requirements, technical designs, processes, and artifacts supporting AI-enabled security test and evaluation capabilities. * Assess security risks across on-premises, cloud, applications, networks, and infrastructure. * Collaborate with technical and business stakeholders to prioritize vulnerabilities and develop actionable remediation plans. * Develop technical reports, metrics, and analytical products demonstrating security testing effectiveness. * Ensure security testing and AI implementations comply with applicable NIST, FISMA, FedRAMP, OMB, and organizational requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)