Application Security Analyst
HIGHLIGHTS
Location: Remote –West Coast or Central time zone preferred
Position Type: 6 month Contract to hire
Additional Compensation: Bonus eligible
REMOTE –CANDIDATES in West coast or Central time preferred
Our client is looking for an Application Security Analyst to join their team!
Position Description:
The Application Security Analyst will support an enterprise information security program with a primary focus on integrating application security tools into CI/CD pipelines, managing application vulnerabilities, and partnering with development teams to incorporate security into their processes.
This individual will help mature the organization’s DevSecOps practices, reduce its overall attack surface, and strengthen its application security program. The successful candidate must be comfortable working directly with developers and website owners and explaining security risks and technical concepts to nontechnical stakeholders.
Required Skills:
- Three or more years of hands-on experience in DevSecOps, Application Security, Product Security, DevOps, or a closely related role.
- Previous professional experience working specifically within a DevSecOps environment.
- Hands-on experience configuring and integrating security tools into CI/CD pipelines.
- Experience conducting application security reviews and communicating findings.
- Experience using DAST tools to scan web applications and identify security vulnerabilities.
- Hands-on experience configuring, managing, and tuning Azure Front Door and Web Application Firewall policies.
- Experience using GitHub Advanced Security, including CodeQL, Secret Scanning, and Dependency Review.
- Experience triaging application security findings and partnering with development teams to remediate vulnerabilities.
- Experience working directly with software developers, application teams, and website owners.
- Ability to explain complex security risks and technical concepts clearly to nontechnical employees and business leaders.
- Strong written and verbal communication skills.
- Strong collaboration, customer service, organization, and project-management skills.
Responsibilities:
- Support and monitor enterprise application security systems and tools.
- Manage daily operations for application security products, including incident and support-ticket resolution.
- Integrate SAST, DAST, and other application security tools into CI/CD pipelines and developer workflows.
- Perform security reviews of applications, Terraform configurations, and reusable infrastructure modules.
- Validate infrastructure changes for security, compliance, and alignment with established cloud architecture standards.
- Monitor code platforms and application resources for security threats and vulnerabilities.
- Investigate security incidents and document findings.
- Respond to security-tool findings and coordinate remediation with developers, application teams, and website owners.
- Configure, manage, and tune Azure Front Door Web Application Firewall policies and rulesets.
- Maintain and upgrade application security platforms.
- Write SIEM queries and analyze the results.
- Help improve application security procedures, protocols, and technical documentation.
- Contribute to application security projects and related initiatives.
Qualifications:
- Experience working with cloud platforms such as Microsoft Azure, AWS, Google Cloud, or OCI.
- Experience with GitHub Actions, Azure DevOps Pipelines, or comparable CI/CD and developer-workflow automation tools.
- Experience developing or reviewing Terraform used to deploy Azure infrastructure, including reusable modules.
- Experience with PowerShell for administration and automation.
- Demonstrated ability to collaborate effectively with technical and nontechnical stakeholders at all organizational levels.
- West Coast or Central time-zone candidates are preferred, although qualified candidates located in any U.S. Time zone will be considered.
"We are GTN –The Go To Network"