> Markdown version of [/jobs/ext/553110-principal-security-analyst](https://www.wearedevelopers.com/jobs/ext/553110-principal-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Analyst - **Company:** IBA InfoTech Inc. - **Location:** Miami, FL, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Microsoft Windows, Software System Penetration Testing, Bash Shell, C Sharp (Programming Language), C++ (Programming Language), Static Program Analysis, Code Review, Databases, Perl (Programming Language), Python (Programming Language), Network Architecture, Nmap, Oracle (Applications), Open Web Application Security, Systems Development Life Cycle, Shell Script, Software Engineering, SQL Injection, SQL Databases, Systems Architecture, Wireshark, Web Applications, WS-Security, Webinspect, Scripting, Software Security, Cross-Site Scripting (XSS), Information Technology, Metasploit, Nessus, Appscan, Vulnerability Analysis - **Published:** June 14, 2026 - **Apply:** https://ibainfotech.com/principal-security-analyst ## About the Role * Minimum of 6 years of general work experience and 3 years of relevant experience in functional responsibility. * Bachelor's Degree, or an equivalent combination of formal education, experience. * Must have a strong technical background and understand system architecture and design, operating systems, network infrastructure, software installation on test platforms, software development, database and operating systems. Requirements: * Security, Software Development, Networking, and/or Systems Administrator Experience * Deep understanding of 3-tiered Web Application Architecture * Manual Penetration Testing Experience (i.e. mapping applications, injecting SQLi, XSS, exploit creation) * Must have Commercial Web Application Tool Experience (i.e. Burp, AppSpider, AppScan, WebInspect) * Network Penetration Testing Tool Experience (i.e. Nmap, Nessus, Wireshark, Metasploit, Hydra) * Exceptional communication skills, with the ability to explain the technical details of OWASP Top 10 and other vulnerabilities with C-levels to developers in a large professional environment * Experienced with Oracle, Windows and SQL. Desired: * Web Services Security Penetration Testing Experience * Database Experience (DBA or security penetration testing) * Software Development and/or Scripting Experience in .NET, C++, Java, C#, perl, python or bash * Source Code Review (aka Static Analysis) Experience * Excellent technical writing skills and attention to detail ## Description * This role may perform any or all of the following: conducts vulnerability assessments; carries out penetration tests, performs social engineering tests; analyzes technical security weaknesses; performs risk analyses; and develops exploits. * Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer and network vulnerabilities, data hiding and encryption. * Develop tools, techniques, training and countermeasures for computer and network vulnerabilities, data hiding and encryption. * Application security architecture - Provide development teams guidance and formal security requirements as part of the SDLC process. * Perform audit related activities as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)