Information Security Analyst- Applications
Role details
Job location
Tech stack
Job description
The Application Security Analyst is a detail-oriented security professional who works to facilitate and support the application security function across the software development lifecycle. This role will be responsible for performing application security assessments, supporting secure code reviews and penetration testing, and partnering with development and DevOps teams to remediate vulnerabilities and mature secure coding practices.
What You'll Do:
· Perform application security assessments-including SAST, DAST, and software composition analysis (SCA)-across the software development lifecycle (SDLC).
· Support manual and automated security code reviews, providing clear, actionable remediation guidance to development teams.
· Assist with internal and third-party penetration testing engagements; document findings and track remediation progress through closure.
· Manage and prioritize application vulnerabilities within the vulnerability tracking program, ensuring accurate risk ratings and timely remediation follow-up.
· Collaborate with DevOps and engineering teams to integrate security tooling (SAST, secrets scanning, dependency checking) into CI/CD pipelines.
· Contribute to the development and maintenance of AppSec policies, standards, secure coding guidelines, and assessment procedures.
· Participate in developer security training and awareness initiatives; serve as a day-to-day security resource for application teams.
· Support AppSec program reporting, including metrics collection, trend analysis, and contribution to quarterly business reviews (QBR).
· Assist in evaluating and onboarding new application security tools and technologies to mature program capabilities.
· Perform other duties as needed.
Requirements
· B.S. in Computer Science, Information Systems Security, Software Engineering, or a related field.
· 1-3 years of experience in information security, application development, or a combination with a demonstrated security focus.
· Working knowledge of the OWASP Top 10, CWE/CVE frameworks, and common vulnerability classes (injection, broken authentication, IDOR, etc.).
· Hands-on familiarity with security testing tools such as Burp Suite, GitHub CodeQL, Checkmarx, Veracode, Snyk, or comparable platforms.
· Basic understanding of web application architecture, APIs (REST/SOAP), and at least one programming or scripting language (Python, Java, C#, JavaScript, PowerShell, etc.).
· CSSLP, CEH, Security+, GWEB, or other relevant certifications are a plus.
What You're Good At:
· Strong written and verbal communication skills; ability to translate technical vulnerability findings into clear, business-relevant language for developers, project managers, and non-technical stakeholders without sacrificing accuracy.
· A methodical, evidence-based approach to problem-solving-able to investigate ambiguous security signals, connect findings to business risk, and recommend proportionate, pragmatic remediation steps.
· Demonstrated curiosity and a continuous learning mindset; willingness to stay current on emerging threats, CVEs, and evolving application security techniques, and to share that knowledge proactively with teammates and development partners.
· Collaborative work style with the ability to build productive working relationships across engineering, DevOps, GRC, and business teams; comfort operating in environments where influence must be earned rather than mandated.
· Ability to manage multiple concurrent assessments and remediation tracks with appropriate prioritization, visibility, and follow-through-maintaining quality and responsiveness in a fast-paced enterprise environment.
· Integrity and sound judgment; ability to handle sensitive findings, vulnerability data, and security program information with appropriate discretion in accordance with corporate standards.