Application Security Analyst - 18 Month Fixed Term Contract
Core
Strengthen application security across a super fund's modern cloud, API, and DevSecOps environments by embedding secure-by-design practices and managing security risks.
Role type
Application Security Analyst (IC)
Builds
Secure software delivery pipelines, cloud-native applications, and APIs for a financial services platform serving millions of members.
Domain
Financial Services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security assessments, DevSecOps, threat modelling, OWASP Top 10, vulnerability management, SAST/DAST/SCA tools, CI/CD integration, API security, secrets detection, secure SDLC, risk-based remediation guidance.
Preferred skills
AWS cloud platforms, microservices architecture, software supply chain security, AI-enabled solution security, OWASP ASVS/SAMM/NIST CSF/APRA CPS 234 frameworks.
Technologies
SAST, DAST, SCA, CI/CD pipelines, AWS, API security testing tools, secrets detection tools.
Responsibilities
Lead application security assessments for web apps, APIs, and cloud services; embed security into solution design via threat modelling; validate and prioritize security findings; drive improvement of security tooling; promote secure SDLC and DevSecOps practices; coordinate penetration testing; develop security standards and guardrails; provide security education to developers; support security incident investigations; deliver security reporting and metrics.
Seniority
Mid-level, hands-on IC
