Security Vulnerability Analyst

PRI Technology
New York, NY, United States
3 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$156,000.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Artificial Intelligence C Sharp (Programming Language) Code Review Cyber Security Continuous Delivery Continuous Integration Corona (Software Development Kit) Github Internet Security Python (Programming Language)
+15 more
Node.Js Open Web Application Security Systems Development Life Cycle Secure Coding Software Engineering SonarQube TypeScript Software Vulnerability Management Scripting Software Security Veracode Checkmarx Static Application Security Testing Vulnerability Analysis Golang

Job description

My name is Bill Stevens, and I have a new remote six month plus Application Security Vulnerability Analyst opportunity available for a major firm located in Midtown, Manhattan that could be of interest to you, please review my specification below and I am available at any time to speak with you so please feel free to call me. The ideal candidate must be capable of working on Eastern Standard Time.

The ideal candidate should also possess a green card or be of citizenship. No Visa entanglements and no H1-B holding company submittals.

This position pays $75.00 per hour on a w-2 hourly basis or $85.00 per hour on a Corp basis. The Corp rate is for independent contractors only and not third-party firms. No Visa entanglements and no H1-B holding companies.

The successful candidate will analyze vulnerabilities within the context of the affected application, business function, compensating controls, exploitability, and overall organizational risk. The analyst will be expected to translate technical findings into concise, actionable guidance that developers, technology owners, and business stakeholders can understand and act upon.

The ideal candidate will combine strong application security knowledge, practical understanding of modern software development, and the ability to work collaboratively with engineering teams to drive timely remediation and risk reduction. This position requires independent analysis, sound judgment, and a results-oriented mindset. These responsibilities are consistent with Security Assurance expectations for reviewing technical findings, prioritizing realistic risk, and driving findings to closure

Responsibilities: Vulnerability Analysis & Risk Assessment: Review vulnerabilities identified through AI-based SAST, SCA, and related application security tools. Evaluate vulnerabilities beyond vendor-assigned severity scores by considering: Exploitability, Exposure, Attack paths, Business impact, Compensating controls, Application context Distinguish between theoretical findings and vulnerabilities that present realistic risks. Validate vulnerability classifications and severity recommendations. Identify false positives, duplicate findings, and opportunities for risk-based prioritization. Ability to utilize AI to develop prompts to increase confidence in finding credibility and reduce false positives Assess vulnerability trends and recurring development patterns requiring broader corrective action. These responsibilities align with Security Assurance practices for prioritizing realistic risks rather than relying solely on finding volume or scanner output

Developer Engagement & Remediation Coordination: Explain findings clearly to developers, architects, technology owners, and business stakeholders. Provide actionable remediation guidance and secure coding recommendations. Assist application teams in understanding root causes and recommended fixes. Partner with developers and technology owners to establish remediation plans. Track remediation progress and follow up to ensure issues are resolved within the firms defined SLAs. Escalate aging findings and remediation blockers as appropriate. Support validation of completed remediation activities and closure recommendations. Remediation coordination and driving vulnerabilities through closure is a core expectation within the firms vulnerability management operating model.

Application Security Operations Support: Support vulnerability triage activities across multiple application security tools. Participate in vulnerability review sessions and remediation discussions. Contribute to documentation, procedures, and process improvements. Identify opportunities to improve consistency, efficiency, and quality in vulnerability review processes. Assist with application security reporting and stakeholder communications. Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.

Requirements

More than three years of experience in Application Security, Vulnerability Management, Security Risk Management, or a related cybersecurity discipline. Strong understanding of: OWASP Top 10, Common software security weaknesses (CWEs), Software vulnerability management practices, Secure software development lifecycle (SSDLC), Exploit Prediction Scoring System (EPSS) Experience interpreting and validating findings from application security tools. Experience using AI Based Security Tools. Ability to evaluate findings in the context of exploitability, exposure, and business risk rather than relying solely on CVSS scores. Experience working directly with development teams to remediate vulnerabilities. Strong written and verbal communication skills with the ability to translate technical findings into business-relevant language. Strong organizational skills with the ability to manage multiple workstreams and remediation efforts simultaneously. Demonstrated ability to work independently and drive outcomes with limited supervision. These qualifications align closely with Security Assurance expectations for reviewing technical findings, making risk-based decisions, and influencing remediation outcomes.

Required Technical Skills: Experience reviewing or working with applications developed in one or more of the following languages: Java, TypeScript, JavaScript, C#, Python, Go, Node.js Experience with one or more of the following is preferred: SAST tools (SonarQube, Snyk Code, Checkmarx, Veracode, GitHub Advanced Security, etc.) SCA tools and dependency risk analysis CI/CD security integration Secure coding reviews, Analysis Skills, Applications Security, Artificial Intelligence (AI), Code Reviews, Communication Skills, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Corrective Action, Documentation, Establish Priorities, GitHub, Go Programming Language (Golang), Internet Security, Java, JavaScript, Management Strategy, Microsoft C# (C Sharp), Node.js, Operational Support, Organizational Skills, Presentation/Verbal Skills, Problem Solving Skills, Procedure Development, Process Improvement, Process Quality, Python Programming/Scripting Language, Risk, Risk Analysis, Risk Management, Secure Coding, Security Analysis, Service Level Agreement (SLA), Software Development, Software Development Lifecycle (SDLC), Team Player, Technical Recruiting, Time Management, Trend Analysis, Writing Skills

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all