Cyber Security Analyst - App Security & Vulnerability
Core
Perform static, dynamic, and software composition analysis to uncover and remediate vulnerabilities in web applications, APIs, and third-party components.
Role type
Senior IC application security engineer (AppSec)
Builds
Secure web applications and APIs
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis
Required skills
SAST, DAST, SCA tooling, OWASP Top 10, API security, secure SDLC, DevSecOps, vulnerability triage, remediation planning, Python/Java/JavaScript/Bash scripting, risk-based reporting
Preferred skills
CI/CD integration (Jenkins, GitHub Actions, Azure DevOps), container/cloud security (AWS, Azure, GCP), AI/ML security concepts, API testing (Postman, SoapUI), threat modeling (STRIDE), regulatory frameworks (NIST, ISO 27001, SOC 2)
Technologies
Checkmarx, Veracode, Fortify, Snyk, Burp Suite, OWASP ZAP, Jenkins, GitHub Actions, Azure DevOps, AWS, Azure, Google Cloud Platform, Python, Java, JavaScript, Bash, Postman, SoapUI
Responsibilities
Perform static, dynamic, and software composition analysis to uncover vulnerabilities. Analyze scan findings, triage issues, and prioritize remediation based on risk. Partner with development teams to fix vulnerabilities and strengthen secure coding practices. Conduct ongoing security assessments and vulnerability scans across applications and environments. Validate and reproduce vulnerabilities, including confirming false positives. Configure, deploy, and maintain security scanning tools. Automate security testing workflows using scripting or APIs. Tune and optimize scanning processes to improve efficiency and coverage. Assess threats and attack vectors relevant to applications and APIs. Support the security of AI-driven applications and data pipelines. Leverage AI/ML-based security tools to improve detection and analysis.
Seniority
Senior, hands-on IC