> Markdown version of [/jobs/ext/3027493-devsecops-application-security-analyst](https://www.wearedevelopers.com/jobs/ext/3027493-devsecops-application-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps/Application Security Analyst - **Company:** CareerCircle - **Location:** Charlotte, NC, United States (Remote available) - **Salary:** $83,200.0 - $93,600.0 - **Contract:** Temporary to permanent - **Skills:** Kubernetes Security, 3d Models, Active Directory, Agile Methodology, Artificial Intelligence, Building Information Modeling, Cyber Security, Continuous Integration, DevOps, Document Management Systems, Logic Synthesis of Circuits, Github, Supervisory Control and Data Acquisition (SCADA), Integrated Development Environments, Microsoft SQL Server, Windows Servers, MySQL, Oracle (Applications), Windows PowerShell, Secure Coding, Software Engineering, Software Vulnerability Management, Scripting, Cyberark, Sybase, Software Security, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 22, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/nc/charlotte/5a293421-c261-4acb-8372-ed7ea380ac46 ## About the Role Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors., Visionary Leadership Management Automation Mentorship Innovation 3D Modeling Coordinating Communication Digital Design Problem Solving Project Delivery Design Technology Project Management Influencing Skills Workflow Management Process Improvement Digital Transformation Project Implementation Engineering Design Process Document Management Systems Building Information Modeling Troubleshooting (Problem Solving) Desktop Deployment Planning Services +0 Google Project Management Protection & Control Engineer (Remote) Actalent Charlotte, NC*Remote Relays Visionary Scheduling Innovation Scalability Retrofitting Professionalism Circuit Breakers Electrical Substation Electrical Engineering Transformers (Electrical) Engineering Design Process Professional Engineer (PE) License Supervisory Control And Data Acquisition (SCADA) ## Description Github DevSecOps Operations Management Positivity Secure Coding Prioritization Security Controls Business Valuation Container Security Engineering Support Pull/Merge Requests Security Engineering Software Development Application Security Full Stack Development Business Transformation Security Administration Physical Security Operations Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST), We are building a brand-new DevSecOps and Application Security program and is seeking a DevSecOps/Application Security Analyst to help establish security standards across the organization's software development environment. This role will work directly with the DevSecOps Lead to implement secure CI/CD pipelines, manage application security scanning, drive vulnerability remediation efforts, and partner closely with development teams to strengthen the organization's overall security posture. This is an excellent opportunity for someone who enjoys building processes from the ground up and wants to have a direct impact on a growing security program. Serve as a day-to-day operator of the DevSecOps program, responsible for application security findings management, GitHub security administration, CI/CD security controls, pull request security reviews, repository onboarding, and developer engagement. Work closely with the DevSecOps Lead, security engineering resources, and development teams to keep findings actionable, exceptions tracked, security controls operational, and program metrics current. Support the Security Champions program and contribute to secure coding initiatives. This is a hands-on role operating at the intersection of software development, security operations, and application security. Essential Duties - Scan Triage & Findings Management Triage daily findings from SAST, DAST, SCA, secrets detection, IaC, container security, and repository security tools. Validate findings, classify severity, and manage false-positive disposition with documented rationale. Review pull requests for security findings and work with developers to explain vulnerabilities and remediation approaches. Monitor CI/CD security gate results and escalate blocked builds when exceptions or engineering support are required. Track and maintain the security exception register. Manage the security findings backlog, including ticket creation, prioritization, assignment, SLA tracking, remediation validation, escalation of overdue items, and closure verification., MySQL DevOps CyberArk Scripting Operations Management Automation Governance Scalability Self-Starter Active Directory Cloud Management Agile Methodology Sybase (Software) SQL Server Oracle Windows PowerShell Business Valuation Financial Services Credential Manager Enterprise Security Lifecycle Management Full Stack Development Artificial Intelligence Technical Documentation Business Transformation Privileged Access Management Microsoft Windows Server Administration +0 BIM / VDC Digital Delivery Actalent Charlotte, NC*Remote ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)