Application Security Analyst I

Transaction Network Services Inc.
United States
13 days ago
Apply on tnsi.wd1.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$75,000.0 - $83,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Computing Platforms Microsoft Azure Business Software Cyber Security Continuous Integration DevOps Github Information Security Management Open Web Application Security Systems Development Life Cycle Secure Coding
+9 more
Software Engineering Software Vulnerability Management Software Security Gitlab GWAPT Information Technology Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

The Senior Application Security Engineer is responsible for advancing the organization’s secure software development program by integrating security throughout the software development lifecycle (SDLC). This role partners closely with application development, DevOps, infrastructure, and security teams to identify, assess, and remediate application security risks while enabling secure delivery of business applications. The position leads application security initiatives including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Application Security Posture Management (ASPM), CI/CD security integrations, container security scanning, vulnerability management, and security automation. The engineer will support security assessments, threat modeling, secure code review processes, and security tooling integrations across multiple business units. Responsibilities also include managing AppSec intake processes, developing operational runbooks, driving remediation activities, and supporting strategic security transformation initiatives. These responsibilities align with the work currently owned by the departing Application Security resource, including ArmorCode ASPM implementation, SAST/SCA integrations, AppSec automation, GitLab container scanning initiatives, and management of high-priority application security activities.

Responsibilities

This role partners closely with application development, DevOps, infrastructure, and security teams to identify, assess, and remediate application security risks while enabling secure delivery of business applications. The position leads application security initiatives including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Application Security Posture Management (ASPM), CI/CD security integrations, container security scanning, vulnerability management, and security automation. The engineer will support security assessments, threat modeling, secure code review processes, and security tooling integrations across multiple business units. Responsibilities also include managing AppSec intake processes, developing operational runbooks, driving remediation activities, and supporting strategic security transformation initiatives. These responsibilities align with the work currently owned by the departing Application Security resource, including ArmorCode ASPM implementation, SAST/SCA integrations, AppSec automation, GitLab container scanning initiatives, and management of high-priority application security activities., * Lead application security assessments and vulnerability management activities.

  • Implement and manage SAST, SCA, container, and CI/CD security controls.
  • Drive ASPM platform adoption and security tool integrations.
  • Partner with development teams to remediate security findings and improve secure coding practices.
  • Develop and maintain AppSec automation, workflows, and operational runbooks.
  • Support threat modeling, architecture reviews, and secure design consultations.
  • Prioritize and manage remediation efforts for critical and high-risk vulnerabilities.
  • Provide application security guidance across multiple business units and technology teams.

Requirements

Preferred

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field.
  • 5+ years of Application Security or Secure Development experience.
  • Experience with SAST, SCA, DAST, ASPM, container security, and CI/CD security controls.
  • Hands-on experience with GitLab, GitHub, Azure DevOps, or similar development platforms.
  • Knowledge of OWASP Top 10, threat modeling, secure SDLC, and vulnerability management.
  • Strong communication and stakeholder management skills.
  • Relevant certifications such as CISSP, CSSLP, GSEC, GWAPT, or GIAC certifications preferred.

Benefits & conditions

For this role, we anticipate paying $75,000 - $83,000 annually. Any compensation range provided for a role is an estimate determined by available market data. The actual amount may be higher or lower than the range provided considering each candidate’s knowledge, skills, abilities, and geographic location. TNS offers a competitive benefit package including medical and dental coverage, life insurance, paid holidays and vacations, and a 401K plan with company match.

If you are passionate about technology, love personal growth and opportunity, come see what TNS is all about!

About the company

An extraordinarily talented group of individuals work together every day to drive TNS’ success, from both professional and personal perspectives. Come join the excellence!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on tnsi.wd1.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all