Security Analyst

ASM
Honolulu, HI, United States
6 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$85,000.0 - $95,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Continuous Integration DevOps Open Web Application Security Secure Coding Software Engineering Software Vulnerability Management
+6 more
Web Applications Software Security Information Technology Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

The Security Analyst conducts security architecture and design reviews, vulnerability assessments, and technical risk analyses; interprets findings; and guides application owners through prioritized mitigation and validation. The role also develops and enforces secure-development procedures, evaluates security tools and automation, and strengthens the organization’s application security posture in a highly regulated federal IT environment., * p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Integrate application security requirements, secure design practices, and security acceptance criteria across planning, development, testing, deployment, and maintenance phases of the software development life cycle.

  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Conduct and support security architecture reviews, threat modeling, secure design reviews, and vulnerability assessments for web applications, APIs, cloud-hosted workloads, services, and supporting infrastructure.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Analyze findings from static application security testing, dynamic application security testing, software composition analysis, dependency scanning, secrets scanning, container scanning, and penetration testing to determine risk and remediation priority.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Partner with development, DevOps, architecture, and operations teams to identify security risks, explain vulnerabilities, and provide practical, actionable mitigation recommendations.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Perform or support secure code reviews and assess applications for authentication and authorization weaknesses, insecure configurations, secrets exposure, common software weaknesses, and other security control gaps.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Track vulnerabilities and corrective actions through remediation, validate evidence of closure, and perform retesting as needed to confirm risk reduction.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Develop and maintain security procedures, technical standards, assessment reports, and risk communications that support informed authorization, remediation, and stakeholder decisions.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Evaluate application-security products and developer-facing tools for coverage, integration feasibility, operational impact, reporting quality, and compatibility with source-control and CI/CD workflows., Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM’s overall compensation and benefits package for employees.

Requirements

  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Bachelor’s degree in Computer Science, Engineering, or another technical discipline, or equivalent relevant experience.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Typically 5-10 years of progressively responsible experience in application security, secure software engineering, vulnerability management, or a closely related cybersecurity discipline.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Demonstrated experience applying secure SDLC practices, including security requirements definition, threat modeling, architecture review, secure design patterns, and security acceptance criteria.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Experience assessing web applications, APIs, services, cloud-hosted workloads, and supporting infrastructure for vulnerabilities, insecure configurations, identity and access control weaknesses, and software security risks.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Ability to interpret, prioritize, and communicate findings from application-security testing, vulnerability scanning, dependency analysis, secrets scanning, container scanning, and penetration testing.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Strong working knowledge of vulnerability triage, risk scoring, exploitability analysis, compensating controls, remediation tracking, and validation of corrective actions.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> U.S. citizenship is required, with the ability to obtain and maintain a Public Trust background investigation., * p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Professional security certification such as CSSLP, Security+, CISSP, a GIAC application-security credential, or a cloud-security certification.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Experience embedding automated security controls, policy gates, and scan-result workflows into CI/CD pipelines and infrastructure-as-code delivery processes.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Experience supporting application security activities within a highly regulated federal, defense, or government environment.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Experience conducting secure architecture reviews, applying threat-modeling methods, and remediating OWASP-aligned application-security risks., The physical requirements described in “Knowledge, Skills and Abilities” above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, “light office duties’ or “lifting up to 50 pounds” or “some travel” required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

About the company

ASM Research, An Accenture Federal Services Company

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all