Application Security Vulnerability Analyst

SGA Inc.

  • New York, NY
  • 2 days ago
  • Remote
  • $79.71–$91.67 Per Hour

Highlights

Hands-on experience using AI tools to support application security or vulnerability analysis , including the ability to create effective prompts to validate findings, improve analysis, and reduce false positives. Ability to evaluate vulnerabilities based on actual exploitability, exposure, attack paths, application context, compensating controls, and business risk rather than relying solely on CVSS scores.

Numbers & Facts

LocationNew York, NY (
Remote
)
Salary$79.71–$91.67 Per Hour

Description

Software Guidance & Assistance, Inc., (SGA), is searching for an Application Security Vulnerability Analyst for a contractor assignment with one of our premier Insurance Services clients. This is a remote role; candidates must work EST business hours.

Responsibilities:

  • Review and analyze vulnerabilities identified through SAST, SCA, AI-based, and related application security tools.
  • Perform hands-on review of application source code to validate security findings and determine whether identified vulnerabilities represent legitimate risk.
  • Triage findings before engaging development teams, with a focus on identifying false positives and minimizing non-actionable issues.
  • Evaluate vulnerabilities beyond vendor-assigned severity scores by considering exploitability, exposure, attack paths, business impact, compensating controls, and application context.
  • Validate vulnerability classifications, severity recommendations, and remediation priority.
  • Utilize AI tools and effective prompting techniques to analyze security findings, increase confidence in finding credibility, and reduce false positives.
  • Assess vulnerability trends and recurring development patterns that may require broader corrective action.
  • Explain validated application security findings clearly to developers, architects, technology owners, and business stakeholders.
  • Provide actionable remediation guidance and secure coding recommendations.
  • Partner with developers and technology owners to drive validated vulnerabilities through remediation and closure within defined SLAs.
  • Track remediation progress and escalate aging findings or remediation blockers as appropriate.
  • Validate completed remediation activities and make closure recommendations.
  • Support vulnerability triage and vulnerability management activities across multiple application security tools.
  • Participate in vulnerability review sessions and remediation discussions.
  • Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.
  • Contribute to application security procedures, reporting, and process improvements.

Required Skills:

  • 3+ years of experience in Application Security, Application Vulnerability Management, or a closely related cybersecurity discipline.
  • Hands-on experience reviewing and validating application security findings generated by SAST and SCA tools.
  • Strong application security vulnerability analysis and triage experience, including the ability to distinguish legitimate vulnerabilities from false positives.
  • Hands-on technical ability to review source code and validate security findings at the code/application level before escalating issues to development teams.
  • Ability to evaluate vulnerabilities based on actual exploitability, exposure, attack paths, application context, compensating controls, and business risk rather than relying solely on CVSS scores.
  • Strong understanding of application security concepts and practices, including:
    • OWASP Top 10
    • Common Weakness Enumeration (CWE)
    • Secure Software Development Lifecycle (SSDLC)
    • Exploit Prediction Scoring System (EPSS)
    • CVE/CVSS concepts
  • Ability to analyze application security findings involving one or more modern enterprise development languages, including Java, TypeScript, JavaScript, C#, Python, Go, Node.js, or similar languages.
  • Hands-on experience using AI tools to support application security or vulnerability analysis, including the ability to create effective prompts to validate findings, improve analysis, and reduce false positives.
  • Strong written and verbal communication skills with the ability to clearly communicate technical security findings.
  • Strong organizational skills with the ability to manage multiple vulnerability analysis and remediation efforts simultaneously.
  • Demonstrated ability to work independently and drive issues toward resolution.

Preferred Skills:

  • Experience working directly with development teams to explain vulnerabilities, provide remediation guidance, and drive findings through closure.
  • Experience with AppScan, Snyk, ZAP, or comparable application security tools.
  • Experience with Claude Code or similar AI-assisted security/development tools.
  • Secure code review experience.
  • Application security testing experience.
  • CI/CD security integration experience.
  • Experience with SCA tools and software dependency risk analysis.
  • Understanding of software architecture and common web application attack patterns.
  • Working knowledge of cloud-native applications and APIs.
  • Familiarity with enterprise vulnerability management processes, remediation SLAs, and tracking workflows.
  • Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, or similar.

Education:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field preferred, or equivalent relevant professional experience.
By applying for a job with SGA, you agree to allow SGA to process your application for this and future opportunities in accordance with our Privacy Policy. Also, to ensure timely processing, you agree to be contacted by our AI recruiter via email, text, or phone. Message frequency varies and data rates may apply, but you can reply STOP to any SMS message to opt-out of texts and may contact SGA at

info@sgainc.com

to opt-out of AI communications. The choice not to engage with AI will not adversely impact your consideration for placement. AI is not used to make any hiring determinations.

SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at https://sgainc.com/ .

SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company EEO page to request an accommodation or assistance regarding our policy.

Similar Jobs

See more jobs