> Markdown version of [/jobs/ext/2999096-principal-application-security-analyst](https://www.wearedevelopers.com/jobs/ext/2999096-principal-application-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Application Security Analyst - **Company:** WPS Health Solutions - **Location:** Monona, WI, United States (Remote available) - **Experience:** Expert - **Salary:** $135,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), User Authentication, Cloud Computing, Cyber Security, Information Systems, Continuous Integration, Data Security, Ethernet Physical Layer, Open Web Application Security, Session Management, Software Engineering, Enterprise Software Applications, Software Security, Mitre Att&ck, Cyber Threat Analysis, GWAPT, Information Technology, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 19, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88386877/1 ## About the Role * U.S. Citizenship is required for this position due to Department of Defense restrictions. * Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Systems, or a related field or equivalent combination of education and relevant work experience. * 5 or more years of progressive experience in application security, software security, DevSecOps, or a related technical security discipline. * Hands-on experience with application-security testing technologies (SAST and DAST), the ability to tune tools and independently validate findings, and experience translating cybersecurity standards and technical requirements into practical developer guidance and secure-coding training. * Proficient knowledge of common application vulnerabilities and attack techniques, that could include: Authentication / Authorization, Injection, Session management, API security, Insecure dependencies, etc. * Knowledge of modern software-development methodologies, CI/CD pipelines, APIs, and cloud-based application environments, sufficient to integrate security testing into the development lifecycle. * Excellent analytical skills in distinguishing exploitable vulnerabilities from false positives and prioritizing remediation based on actual risk. * Strong communication, problem solving, anddecision-makingskills. Preferred Qualifications * Knowledge of OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and MITRE ATT&CK. * Professional certification such as CSSLP, GWAPT, GWEB, or OSWE. Remote Work Requirements * Wired (ethernet cable) internet connection from your router to your computer. * High speed cable or fiber * Minimum of 10 Mbps downstream and at least 1 Mbps upstream internet connection (can be checked at https://speedtest.net). ## Description application-security testing, triage, and developer engagement independently, while partnering with Cyber Trust & Architecture on standards interpretation and with the Manager, Cyber Threat Management on program priorities. Salary Range - $135,000 ~ $165,000 The base pay offered for this position may vary within the posted range based on your job-related knowledge, skills, experience and may fall outside of this range. Work Location Our first consideration will be to have this employee be able to take advantage of Hybrid work and collaboration, living within the state of Wisconsin. Employees within 45 miles of WPS Headquarters (1717 W. Broadway in Madison, WI, 53713) will be expected to be able to work in office 3 days a week on a regular basis. How do I know this opportunity is right for me? If you: * Can operate, tune, and continuously improve enterprise application-security testing capabilities (SAST, DAST, SCA, API and secrets scanning), distinguishing exploitable weaknesses from false positives and integrating testing into the development and CI/CD lifecycle. * Want to partner with Cyber Trust & Architecture to translate enterprise application-security standards and secure-by-design requirements into practical developer guidance, testing criteria, and implementation practices across the software-development lifecycle. * Have built and delivered a developer-focused secure-coding education program, using real vulnerability trends and hands-on guidance to strengthen developers' ability to meet enterprise security standards. * Enjoy developing and maintaining technical, managerial, and executive reporting that translates application-security findings, vulnerability trends, and standards adoption into actionable, risk-based information. * Thrive when coordinating the remediation of application vulnerabilities with developers and system owners, prioritizing based on actual exploitability and business risk, and validating fixes through retesting. * Want to apply current threat intelligence and attacker techniques to application-security testing and priorities, partnering with Cyber Trust & Architecture, Cyber Risk & Assurance, and development teams to strengthen security outcomes., This position may from time to time provide support to federal health care programs and other governmental or regulated industries. In accordance with law and/or contractual requirements, individuals in this role are or may be subject to all applicable federal regulations, agency contract requirements, and WPS internal policies, including but not limited to standards for data security, privacy, confidentiality, and program integrity. WPS and its personnel are subject to mandatory enhanced screening and background investigation prior to being granted access to information systems and/or sensitive data in order to safeguard regulated information and government resources that provide critical services. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)