Senior Application Security Analyst
Core
Senior technical role leading advanced application security testing, complex vulnerability analysis, and threat modelling for critical applications and services.
Role type
Senior IC Application Security Specialist (Offensive Security & Threat Modelling)
Builds
Security test strategies, automation frameworks, custom tooling, and remediation standards for web, mobile, API, and AI/LLM surfaces.
Domain
Cybersecurity, Application Security, Cloud Security (Kubernetes), AI/LLM Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Advanced application security testing, Threat modelling (STRIDE, PASTA), Penetration testing (Web/Mobile/API), Container/Kubernetes security, AI/LLM security assessment, Offensive security (Business logic abuse, Auth bypass), Automation scripting (Python, Bash), CI/CD security integration
Preferred skills
OSCP, OSWE certifications, Advanced mobile reverse engineering (Frida, Objection), APT/Threat actor tactics knowledge
Technologies
Burp Suite Pro, Postman, SonarQube, TestRail, Jira, Kubernetes, Android/iOS, Python, Bash, MITRE ATT&CK
Responsibilities
Lead advanced security testing and penetration tests; Own threat modelling for new features; Design security test strategies; Act as SME and escalation point for engineering; Oversee scanning tools and CI/CD security; Mentor analysts and specialists; Build automation frameworks and custom tooling; Own security release process and remediation verification; Track and report security metrics.
Seniority
Senior, hands-on IC with mentorship responsibilities
