Назад
Company hidden
7 дней назад

Application Security Analyst

93 500 - 155 500$
Формат работы
remote (только USA)
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Analyst (Application Security): Embedding security into the software development lifecycle and assessing modern applications, APIs, cloud-native services, and software supply chains with an accent on threat modeling, security testing, and risk-based remediation. Focus on validating exploitable weaknesses, guiding code-level fixes, and improving CI/CD security controls across engineering teams.

Location: Remote in Alabama, Florida, Georgia, or Illinois

Salary range: $93,500–$155,500 annually

Company

hirify.global is a specialized insurance company providing products and services for customers with evolving needs.

What you will do

  • Integrate security requirements and threat modeling across architecture, development, testing, release, and exception processes.
  • Perform and validate SAST, DAST, SCA, API, mobile, and manual security testing.
  • Review security designs and architectures for web, API, cloud-native, containerized, and distributed applications.
  • Partner with developers on code-level and design-level remediation and verify closure.
  • Improve CI/CD security controls, scanning integrations, secure coding standards, and developer enablement.
  • Prioritize vulnerabilities and security debt using exploitability, asset criticality, and business context.

Requirements

  • Hands-on experience with application security testing, secure code review, and vulnerability validation.
  • Strong knowledge of OWASP Top 10 and API risks, authentication and authorization, session management, cryptography, input validation, and web attack techniques.
  • Working knowledge of SAST, DAST, SCA, API testing, secrets scanning, and CI/CD security tooling.
  • Understanding of REST and GraphQL APIs, containers, cloud services, modern software architectures, and software supply-chain dependencies.
  • Experience with secure SDLC, threat modeling, architecture reviews, risk-based exceptions, and application-risk prioritization.
  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.

Culture & Benefits

  • Full-time employment with a focus on professional development and technical challenge.
  • Healthy work-life balance and a diverse, supportive workplace.
  • Benefits package including medical, dental, vision, paid time off, and 401(k).
  • Equal opportunity employment and commitment to workplace diversity and equality.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →