> Markdown version of [/jobs/ext/2859338-application-security-analyst-i](https://www.wearedevelopers.com/jobs/ext/2859338-application-security-analyst-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Analyst I - **Company:** Transaction Network Services Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $75,000.0 - $83,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Computing Platforms, Microsoft Azure, Business Software, Cyber Security, Continuous Integration, DevOps, Github, Information Security Management, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Software Security, Gitlab, GWAPT, Information Technology, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 12, 2026 - **Apply:** https://tnsi.wd1.myworkdayjobs.com/Search/job/USA---Virtual---Virginia/Application-Security-Analyst-I_R3131 ## About the Role Preferred * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. * 5+ years of Application Security or Secure Development experience. * Experience with SAST, SCA, DAST, ASPM, container security, and CI/CD security controls. * Hands-on experience with GitLab, GitHub, Azure DevOps, or similar development platforms. * Knowledge of OWASP Top 10, threat modeling, secure SDLC, and vulnerability management. * Strong communication and stakeholder management skills. * Relevant certifications such as CISSP, CSSLP, GSEC, GWAPT, or GIAC certifications preferred. ## Description The Senior Application Security Engineer is responsible for advancing the organization's secure software development program by integrating security throughout the software development lifecycle (SDLC). This role partners closely with application development, DevOps, infrastructure, and security teams to identify, assess, and remediate application security risks while enabling secure delivery of business applications. The position leads application security initiatives including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Application Security Posture Management (ASPM), CI/CD security integrations, container security scanning, vulnerability management, and security automation. The engineer will support security assessments, threat modeling, secure code review processes, and security tooling integrations across multiple business units. Responsibilities also include managing AppSec intake processes, developing operational runbooks, driving remediation activities, and supporting strategic security transformation initiatives. These responsibilities align with the work currently owned by the departing Application Security resource, including ArmorCode ASPM implementation, SAST/SCA integrations, AppSec automation, GitLab container scanning initiatives, and management of high-priority application security activities. Responsibilities This role partners closely with application development, DevOps, infrastructure, and security teams to identify, assess, and remediate application security risks while enabling secure delivery of business applications. The position leads application security initiatives including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Application Security Posture Management (ASPM), CI/CD security integrations, container security scanning, vulnerability management, and security automation. The engineer will support security assessments, threat modeling, secure code review processes, and security tooling integrations across multiple business units. Responsibilities also include managing AppSec intake processes, developing operational runbooks, driving remediation activities, and supporting strategic security transformation initiatives. These responsibilities align with the work currently owned by the departing Application Security resource, including ArmorCode ASPM implementation, SAST/SCA integrations, AppSec automation, GitLab container scanning initiatives, and management of high-priority application security activities., * Lead application security assessments and vulnerability management activities. * Implement and manage SAST, SCA, container, and CI/CD security controls. * Drive ASPM platform adoption and security tool integrations. * Partner with development teams to remediate security findings and improve secure coding practices. * Develop and maintain AppSec automation, workflows, and operational runbooks. * Support threat modeling, architecture reviews, and secure design consultations. * Prioritize and manage remediation efforts for critical and high-risk vulnerabilities. * Provide application security guidance across multiple business units and technology teams. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)