Application Security Analyst

2 Minutes ago • 5 Years +

Job Summary

Job Description

The Application Security Analyst 3 will identify and remediate application vulnerabilities using tools and code review. They will perform penetration testing, enforce secure development standards, and act as an escalation point. They will lead application security projects, utilize SAST/DAST tools, research new security trends, and prioritize security issue remediation. They will also guide development teams, help new team members and support automated security testing within CI/CD pipelines, delivering secure applications.
Must have:
  • 3 years of experience in software development and implementing security into SDLC processes
  • 2 years relevant architecture experience with expert level knowledge of application systems design and integration
  • Knowledge of testing for the OWASP Top 10 or CWE Top 25, including secure code remediation
  • Excellent interpersonal communication skills
  • Personal passion for security and cutting edge security concepts
  • Strong understanding of Software Security Architecture and Design, SDLC, CI/CD, and the ability to articulate best practices
  • Experience with evaluating, deploying, and managing application security tools (e.g. DAST, SAST, IAST, SCA)
  • Ability to listen for nuances, dig into details to understand systems deeply, and articulate technical details and risks
Good to have:
  • insurance domain

Job Details

Project description

The Application Security Analyst 3 will understand how to identify, exploit, and remediate complex application vulnerabilities through use of tools and code review. They will do this by using penetration testing skills, tools, and methodology to test new applications and services. They will enforce secure development standards and requirements and will specifically act as an escalation point for any non-compliance that could not be resolved at the Analyst 1 or 2 levels. They will hold application security development projects and discussions as needed and will utilize SAST/DAST and other products to identify and document security vulnerabilities. They will perform research on new security trends, tools, and techniques to improve existing processes and will prioritize, track assign, and drive the remediation of security issues. They will act in a leadership capacity when required to Interface with development teams to provide guidance and feedback on identified vulnerabilities. They will also help new team members acclimate to job role and responsibilities and will act as an escalation for any issues not resolved by Application Security Analysts 2.

Responsibilities
bullet icon

Partner with the company's Product, Software Engineering, DevOps, and IT teams.

bullet icon

Perform application security risk assessments, automate security testing, and guide development teams on secure coding practices.

bullet icon

Deliver security products and consult with DevOps, as part of a high-profile security team, supporting automated security testing as part of CI/CD pipelines.

bullet icon

Develop functional and non-functional security requirements, including delivering secure applications and services, that strike a balance of product usability.

bullet icon

Foster and enable a secure by default culture.

Skills

Must have

bullet icon

Minimum of 3 years of experience in software development and implementing security into SDLC processes.

bullet icon

Additional minimum 2 years relevant architecture experience with expert level knowledge of application systems design and integration.

bullet icon

Comprehensive knowledge, experience, & understanding of testing for the OWASP Top 10 or CWE Top 25, including secure code remediation.

bullet icon

Excellent interpersonal communication skills. Can explain very technical topics to all audiences and break down vulnerabilities to both developers and leadership.

bullet icon

Personal passion for security and cutting edge security concepts.

bullet icon

Required Skills:

bullet icon

Strong understanding of Software Security Architecture and Design, SDLC, CI/CD, and the ability to clearly articulate best practices for application security.

bullet icon

Experience with evaluating, deploying, and managing application security tools (e.g. DAST, SAST, IAST, SCA).

bullet icon

Ability to listen for nuances, dig into details in order to understand systems deeply, and articulate technical details and risks.

Nice to have

bullet icon

insurance domain

Other
seniority icon

Languages

English: C1 Advanced

seniority icon

Seniority

Senior

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Mexico

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Empower your future with Luxoft: Innovate, thrive and grow in a software-defined world.

New Delhi, Delhi, India (Remote)

Chennai, Tamil Nadu, India (On-Site)

New York, New York, United States (On-Site)

Gurugram, India (On-Site)

Ukrainka, Kyiv Oblast, Ukraine (Remote)

View All Jobs

Get notified when new jobs are added by luxsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug