Application Security Vulnerability Analyst

PRI Technology

  • New York, NY
  • 2 days ago
  • $75 Per Hour

Highlights

The ideal candidate will combine strong application security knowledge, practical understanding of modern software development, and the ability to work collaboratively with engineering teams to drive timely remediation and risk reduction. Strong understanding of: OWASP Top 10, Common software security weaknesses (CWEs), Software vulnerability management practices, Secure software development lifecycle (SSDLC), Exploit Prediction Scoring System (EPSS).

Numbers & Facts

LocationNew York, NY

Description

Application Security Vulnerability Analyst

My name is Bill Stevens, and I have a new remote six month plus Application Security Vulnerability Analyst opportunity available for a major firm located in Midtown, Manhattan that could be of interest to you, please review my specification below and I am available at any time to speak with you so please feel free to call me. The ideal candidate must be capable of working on Eastern Standard Time.

The ideal candidate should also possess a green card or be of citizenship. No Visa entanglements and no H1-B holding company submittals.

This position pays $75.00 per hour on a w-2 hourly basis or $85.00 per hour on a Corp basis. The Corp rate is for independent contractors only and not third-party firms. No Visa entanglements and no H1-B holding companies.

The successful candidate will analyze vulnerabilities within the context of the affected application, business function, compensating controls, exploitability, and overall organizational risk. The analyst will be expected to translate technical findings into concise, actionable guidance that developers, technology owners, and business stakeholders can understand and act upon.

The ideal candidate will combine strong application security knowledge, practical understanding of modern software development, and the ability to work collaboratively with engineering teams to drive timely remediation and risk reduction. This position requires independent analysis, sound judgment, and a results-oriented mindset. These responsibilities are consistent with Security Assurance expectations for reviewing technical findings, prioritizing realistic risk, and driving findings to closure

Responsibilities:
Vulnerability Analysis & Risk Assessment:
Review vulnerabilities identified through AI-based SAST, SCA, and related application security tools.
Evaluate vulnerabilities beyond vendor-assigned severity scores by considering: Exploitability, Exposure, Attack paths, Business impact, Compensating controls, Application context
Distinguish between theoretical findings and vulnerabilities that present realistic risks.
Validate vulnerability classifications and severity recommendations.
Identify false positives, duplicate findings, and opportunities for risk-based prioritization.
Ability to utilize AI to develop prompts to increase confidence in finding credibility and reduce false positives
Assess vulnerability trends and recurring development patterns requiring broader corrective action. These responsibilities align with Security Assurance practices for prioritizing realistic risks rather than relying solely on finding volume or scanner output

Developer Engagement & Remediation Coordination:
Explain findings clearly to developers, architects, technology owners, and business stakeholders.
Provide actionable remediation guidance and secure coding recommendations.
Assist application teams in understanding root causes and recommended fixes.
Partner with developers and technology owners to establish remediation plans.
Track remediation progress and follow up to ensure issues are resolved within the firms defined SLAs.
Escalate aging findings and remediation blockers as appropriate.
Support validation of completed remediation activities and closure recommendations.
Remediation coordination and driving vulnerabilities through closure is a core expectation within the firms vulnerability management operating model.

Application Security Operations Support:
Support vulnerability triage activities across multiple application security tools.
Participate in vulnerability review sessions and remediation discussions.
Contribute to documentation, procedures, and process improvements.
Identify opportunities to improve consistency, efficiency, and quality in vulnerability review processes.
Assist with application security reporting and stakeholder communications.
Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.

Required Qualifications:
More than three years of experience in Application Security, Vulnerability Management, Security Risk Management, or a related cybersecurity discipline.
Strong understanding of: OWASP Top 10, Common software security weaknesses (CWEs), Software vulnerability management practices, Secure software development lifecycle (SSDLC), Exploit Prediction Scoring System (EPSS)
Experience interpreting and validating findings from application security tools.
Experience using AI Based Security Tools.
Ability to evaluate findings in the context of exploitability, exposure, and business risk rather than relying solely on CVSS scores.
Experience working directly with development teams to remediate vulnerabilities.
Strong written and verbal communication skills with the ability to translate technical findings into business-relevant language.
Strong organizational skills with the ability to manage multiple workstreams and remediation efforts simultaneously.
Demonstrated ability to work independently and drive outcomes with limited supervision. These qualifications align closely with Security Assurance expectations for reviewing technical findings, making risk-based decisions, and influencing remediation outcomes.

Required Technical Skills:
Experience reviewing or working with applications developed in one or more of the following languages: Java, TypeScript, JavaScript, C#, Python, Go, Node.js
Experience with one or more of the following is preferred: SAST tools (SonarQube, Snyk Code, Checkmarx, Veracode, GitHub Advanced Security, etc.)
SCA tools and dependency risk analysis
CI/CD security integration
Secure coding reviews

The interview process will include an initial phone or virtual interview screening.

Please let me know your interest in this position, availability to interview and start for this position along with a copy of your recent resume or please feel free to call me at any time with any questions.

Regards
Bill Stevens
Senior Technical Recruiter
PRI Technology
Denville, New Jersey 07834
P: 973-732-5454 x21
P: 973-354-2799

Bill.Stevens@PRITechnology.com



Similar Jobs