Cyber Security AnalystThis is a remote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role focuses on identifying, analyzing, and mitigating security risks across software development pipelines using SAST, DAST, and SCA tools.
The ideal candidate combines hands-on technical expertise with knowledge of modern security practices and emerging technologies, including AI/ML.ResponsibilitiesPerform static (SAST), dynamic (DAST), and software composition analysis (SCA) to identify vulnerabilities in applications and third-party componentsAnalyze scan results, triage findings, and prioritize remediation efforts based on riskPartner with development teams to remediate vulnerabilities and improve secure coding practicesConduct regular security assessments and vulnerability scans across applications and environmentsValidate and reproduce vulnerabilities, including false positive eliminationTrack and report vulnerability metrics, risk trends, and remediation progressConfigure, deploy, and maintain security scanning tools (e.g., Checkmarx, Veracode, Fortify, Snyk, Burp Suite, OWASP ZAP)Automate security testing processes using scripting or APIsImprove scanning efficiency and coverage through tuning and optimizationQualificationsBachelor's Degree and 6 years of experience in Information Security OR High School Diploma or GED and 10 years of experience in Information SecurityRequired QualificationsHands-on experience with: SAST, DAST, and SCA toolsWeb application security testing (OWASP Top 10, API security)Strong understanding of: Secure software development lifecycle (SDLC / DevSecOps)Common vulnerabilities (e.g., injection, XSS, authentication flaws)Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)Experience interpreting and prioritizing scan results and remediation plansPreferred QualificationsExperience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)Familiarity of container and cloud security (AWS, Azure, GCP)Familiarity with AI/ML concepts and security implicationsIndustry certifications such as: CEH, Security+, SSCP, GIAC or comparable.Key SkillsStrong analytical and problem-solving skillsProvide risk-based recommendations to stakeholdersAbility to communicate technical findings to both technical and non-technical stakeholdersExperience working cross-functionally with development and engineering teamsAttention to detail with a risk-based security mindsetNice-to-Have ExperienceAPI security testing tools (Postman, SoapUI)AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)AI/ML & Emerging Technologies Leverage AI/ML-based security tools for enhanced detection and analysisAssess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)Participate in securing AI-driven applications and data pipelinesThreat Analysis & Risk Management Assess potential threats and attack vectors relevant to applications and APIsApply threat modeling techniques (e.g., STRIDE) during development lifecycle
Cyber Security Analyst III - App Security and Vulnerability (Remote) in az at Unknown Company
This position is listed as full time and able to be worked remotely.