> Markdown version of [/jobs/ext/2835688-security-vulnerability-analyst](https://www.wearedevelopers.com/jobs/ext/2835688-security-vulnerability-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Vulnerability Analyst - **Company:** PRI Technology - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $156,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, C Sharp (Programming Language), Code Review, Cyber Security, Continuous Delivery, Continuous Integration, Corona (Software Development Kit), Github, Internet Security, Python (Programming Language), Node.Js, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, SonarQube, TypeScript, Software Vulnerability Management, Scripting, Software Security, Veracode, Checkmarx, Static Application Security Testing, Vulnerability Analysis, Golang - **Published:** September 10, 2026 - **Apply:** https://www.careerbuilder.com/job-details/application-security-vulnerability-analyst-new-york-ny--02d97b0c-66c5-4638-bc48-b6ef6037afd7 ## About the Role More than three years of experience in Application Security, Vulnerability Management, Security Risk Management, or a related cybersecurity discipline. Strong understanding of: OWASP Top 10, Common software security weaknesses (CWEs), Software vulnerability management practices, Secure software development lifecycle (SSDLC), Exploit Prediction Scoring System (EPSS) Experience interpreting and validating findings from application security tools. Experience using AI Based Security Tools. Ability to evaluate findings in the context of exploitability, exposure, and business risk rather than relying solely on CVSS scores. Experience working directly with development teams to remediate vulnerabilities. Strong written and verbal communication skills with the ability to translate technical findings into business-relevant language. Strong organizational skills with the ability to manage multiple workstreams and remediation efforts simultaneously. Demonstrated ability to work independently and drive outcomes with limited supervision. These qualifications align closely with Security Assurance expectations for reviewing technical findings, making risk-based decisions, and influencing remediation outcomes. Required Technical Skills: Experience reviewing or working with applications developed in one or more of the following languages: Java, TypeScript, JavaScript, C#, Python, Go, Node.js Experience with one or more of the following is preferred: SAST tools (SonarQube, Snyk Code, Checkmarx, Veracode, GitHub Advanced Security, etc.) SCA tools and dependency risk analysis CI/CD security integration Secure coding reviews, Analysis Skills, Applications Security, Artificial Intelligence (AI), Code Reviews, Communication Skills, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Corrective Action, Documentation, Establish Priorities, GitHub, Go Programming Language (Golang), Internet Security, Java, JavaScript, Management Strategy, Microsoft C# (C Sharp), Node.js, Operational Support, Organizational Skills, Presentation/Verbal Skills, Problem Solving Skills, Procedure Development, Process Improvement, Process Quality, Python Programming/Scripting Language, Risk, Risk Analysis, Risk Management, Secure Coding, Security Analysis, Service Level Agreement (SLA), Software Development, Software Development Lifecycle (SDLC), Team Player, Technical Recruiting, Time Management, Trend Analysis, Writing Skills ## Description My name is Bill Stevens, and I have a new remote six month plus Application Security Vulnerability Analyst opportunity available for a major firm located in Midtown, Manhattan that could be of interest to you, please review my specification below and I am available at any time to speak with you so please feel free to call me. The ideal candidate must be capable of working on Eastern Standard Time. The ideal candidate should also possess a green card or be of citizenship. No Visa entanglements and no H1-B holding company submittals. This position pays $75.00 per hour on a w-2 hourly basis or $85.00 per hour on a Corp basis. The Corp rate is for independent contractors only and not third-party firms. No Visa entanglements and no H1-B holding companies. The successful candidate will analyze vulnerabilities within the context of the affected application, business function, compensating controls, exploitability, and overall organizational risk. The analyst will be expected to translate technical findings into concise, actionable guidance that developers, technology owners, and business stakeholders can understand and act upon. The ideal candidate will combine strong application security knowledge, practical understanding of modern software development, and the ability to work collaboratively with engineering teams to drive timely remediation and risk reduction. This position requires independent analysis, sound judgment, and a results-oriented mindset. These responsibilities are consistent with Security Assurance expectations for reviewing technical findings, prioritizing realistic risk, and driving findings to closure Responsibilities: Vulnerability Analysis & Risk Assessment: Review vulnerabilities identified through AI-based SAST, SCA, and related application security tools. Evaluate vulnerabilities beyond vendor-assigned severity scores by considering: Exploitability, Exposure, Attack paths, Business impact, Compensating controls, Application context Distinguish between theoretical findings and vulnerabilities that present realistic risks. Validate vulnerability classifications and severity recommendations. Identify false positives, duplicate findings, and opportunities for risk-based prioritization. Ability to utilize AI to develop prompts to increase confidence in finding credibility and reduce false positives Assess vulnerability trends and recurring development patterns requiring broader corrective action. These responsibilities align with Security Assurance practices for prioritizing realistic risks rather than relying solely on finding volume or scanner output Developer Engagement & Remediation Coordination: Explain findings clearly to developers, architects, technology owners, and business stakeholders. Provide actionable remediation guidance and secure coding recommendations. Assist application teams in understanding root causes and recommended fixes. Partner with developers and technology owners to establish remediation plans. Track remediation progress and follow up to ensure issues are resolved within the firms defined SLAs. Escalate aging findings and remediation blockers as appropriate. Support validation of completed remediation activities and closure recommendations. Remediation coordination and driving vulnerabilities through closure is a core expectation within the firms vulnerability management operating model. Application Security Operations Support: Support vulnerability triage activities across multiple application security tools. Participate in vulnerability review sessions and remediation discussions. Contribute to documentation, procedures, and process improvements. Identify opportunities to improve consistency, efficiency, and quality in vulnerability review processes. Assist with application security reporting and stakeholder communications. Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)