Application Security Analyst
Jobgether United States · $75K–$95K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
The analyst will embed security throughout the software development lifecycle, including code scanning, threat modeling, and CI/CD integration. They will also partner with engineering teams to remediate vulnerabilities and manage security controls across cloud and AI/ML environments.
What they look for
Requirements
Candidates must have at least 2 years of professional experience in application or product security with hands-on knowledge of SCA and SAST tools. Proficiency in scripting languages like Python or Bash and a strong understanding of OWASP Top 10 and DevSecOps principles are required.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Analyst based in the United States.
This is a hands-on application security role within a small and growing information security team. You’ll help embed security throughout the software development lifecycle, from code scanning and threat modeling to CI/CD and runtime protections. The role combines application security, cloud security, identity, API protection, and emerging AI/ML security challenges. You’ll work closely with engineering teams to identify vulnerabilities, prioritize risks, and drive practical remediation. You’ll also contribute to security automation, incident response, and audit readiness in regulated environments. Because the team is lean, you’ll have broad ownership and the opportunity to take on diverse security challenges. This role is ideal for a security-minded professional who enjoys building, problem-solving, collaborating, and continuously improving how software is secured.
\n
Accountabilities
- Perform application security assessments using SCA, SAST, secrets management, and interactive application testing tools.
- Identify, triage, prioritize, and communicate application vulnerabilities based on risk and business impact.
- Integrate security testing and controls into CI/CD pipelines, helping strengthen DevSecOps practices across development teams.
- Assess security risks in AI/ML-enabled applications, including model exposure, inference endpoints, and emerging AI-specific attack vectors.
- Secure APIs, plugins, microservices, and third-party integrations against common and emerging threats.
- Configure and continuously improve security controls across technologies such as WAF, EDR, MDM, and cloud platforms.
- Conduct threat modeling and secure design reviews for applications, APIs, cloud solutions, and AI-enabled use cases.
- Review and strengthen identity and access management flows, applying least-privilege principles and appropriate security controls.
- Partner directly with developers to remediate vulnerabilities, improve secure coding practices, and integrate security into everyday development workflows.
- Automate repetitive security activities using scripting and other tools to increase efficiency and allow the security team to focus on higher-value work.
- Monitor security events and participate in an on-call rotation for incident response and security investigations.
- Contribute to security and compliance readiness for frameworks and requirements relevant to regulated environments, including PCI, HIPAA, and HITRUST.
Requirements
- 2+ years of professional experience in Application Security, Product Security, or a closely related security discipline.
- Hands-on experience with application security and code-scanning technologies, particularly SCA and SAST tools.
- Strong understanding of the OWASP Top 10 and common application security vulnerabilities.
- Experience securing APIs, microservices, and third-party integrations.
- Familiarity with CI/CD pipelines and the principles of DevSecOps.
- Basic understanding of AI/ML systems and the security risks associated with AI-enabled applications.
- Experience with cloud security and modern cloud-based application environments.
- Scripting ability in Python, Bash, or a comparable language, with the ability to automate repetitive security tasks.
- Strong analytical and problem-solving skills, with a security mindset focused on identifying how systems could fail or be exploited.
- Clear communication skills and the ability to explain security concepts and recommendations to both technical and non-technical stakeholders.
- Ability to collaborate effectively with engineers, developers, and other business teams while building trust and encouraging secure development practices.
- Experience with ML frameworks, AI threat models, WAF or API security solutions is a plus.
- Experience in e-commerce, healthcare, or another highly regulated industry is advantageous.
- Ability to work remotely while maintaining Eastern Time (ET) working hours.
Benefits
- $75,000–$95,000 USD base salary.
- Eligibility for a discretionary annual bonus of up to 10%.
- 100% remote work within the United States.
- Medical, dental, and vision insurance.
- 401(k) plan with company match.
- Dependent Care, FSA, and HSA accounts.
- Paid parental and bonding leave.
- Flexible paid time off and office closure on major holidays.
- Monthly wellness and internet reimbursements.
- Professional development opportunities, including certification support and leadership coaching.
- Mental health and wellbeing resources.
- Opportunity to work across application security, cloud security, DevSecOps, API security, and emerging AI/ML security.
- Broad responsibilities and hands-on ownership within a small, growing information security team.
- Collaborative environment with opportunities to partner closely with engineering and other technical teams.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Security Engineer, (Product Security Team) Manila, Night-Shift
SolarWinds Manila, Metro Manila, Philippines
-
Senior Cyber Security Engineer
Co-op Manchester, England, United Kingdom · £60K–£66K/yr
-
Information Security Engineer (Endpoint Security, Firewalls, Risk Assessment) for NATO with security clearance
WLG Ramstein-Miesenbach, Rhineland-Palatinate, Germany
-
Sr.Client Security Engineer
Scopely Shanghai, Shanghai, China
-
Senior Cyber Security Engineer
Ciklum Mexico, Chihuahua, Mexico
-
Security Engineer, GKE
Google Seattle, Washington, United States · $174K–$252K/yr