133 application security analyst jobs at 105 companies in United States
🚀PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yrOn-SiteFull Time
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
ToyotaNYSE: TM: Designs and manufactures vehicles and provides automotive financial services.
3+ YOE3-6 years in application security; experience with SAST/DAST/SCA; code review; CI/CD; cloud security; IaC; strong QA of web, APIs, and mobile apps.
Sound Physicians: Physician-led medical group providing comprehensive hospital-based clinical services.
4+ YOE4+ years application security or related experience, bachelor’s in CS/InfoSec or related, knowledge of SAST/DAST/SCA/IaC, cloud and CI/CD security, scripting, and vulnerability management.
Consumers Credit Union: Provides member-owned banking and personal financial services.
2+ YOE2+ years application security or secure development experience; SAST/DAST testing, vulnerability analysis, WAF configuration, API security, strong communication; bachelor's preferred or 4+ years experience in lieu; CSSLP/CASE/GWEB preferred.
Veracode, Checkmarx, Burp Suite, Web Application Firewall (WAF), OAuth, OWASP Top 10, SANS CWE Top 25
Federal Reserve System: The central bank of the United States.
0+ YOEIdentify and remediate application security issues across the SDLC; perform penetration testing; knowledge of application security controls, cloud platforms, and OWASP Top 10; varying degree/experience combinations for associate and analyst levels.
Open Web Application Security Project (OWASP) Top 10
HealthStreamNASDAQ: HSTM: Provides workforce management and provider solutions for healthcare organizations.
2+ YOEBachelor's degree or equivalent experience; 2+ years in application security or security-focused software development; knowledge of OWASP Top 10, SAST/DAST/IAST tools, cloud security (AWS/Azure), CI/CD integration, API security, and scripting (Python, JavaScript, Java, Go).
Washington Health Benefit Exchange: Operates Washington state's health insurance enrollment marketplace.
7+ YOE7+ years in information security with application security, secure SDLC, DevSecOps, cloud/Azure experience; experience with code reviews, threat modeling, vulnerability management, and tools like Nessus, Rapid7, Nmap, and Burp Suite.
Washington State Department of Ecology: Provides environmental regulation and conservation services for Washington state.
7+ YOE7+ years information security experience in application security, vulnerability management, penetration testing or related areas; strong secure SDLC, cloud/DevSecOps, threat modeling, code review, and remediation skills; familiarity with NIST/OWASP and regulatory requirements.
Microsoft Azure, Nessus, Rapid7, Nmap, Burp Suite, SAST, DAST, SCA, STRIDE, MITRE ATT&CK, Security Information and Event Management (SIEM), Endpoint Detection & Response (EDR)
Intercontinental ExchangeNYSE: ICE: Operates global financial exchanges, clearing houses, and mortgage platforms.
Requires software engineering experience (Java, C++, .NET), SAST/DAST/Software Composition tool expertise, CI/CD integration experience, familiarity with cloud application development, and a university degree in a related discipline.
Robbinsdale or Maple Grove or Minnesota or Wisconsin
$42-$63/hrHybridFull Time
North Memorial Health: Provides hospital care and clinical medical services.
5+ YOERequires 5+ years in an Epic senior analyst role, certification/associate degree or 3 years related app use, bachelor\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000preferred; expertise in application design/configuration, user security, databases, reporting, and strong analytical and customer service skills.
International Monetary Fund: Fosters global monetary cooperation and secures international financial stability.
6+ YOEApply application security knowledge to support vulnerability remediation, integrate security tools into CI/CD, and collaborate with engineering teams; requires experience in application security, familiarity with OWASP/NIST, and programming knowledge.
SAST, DAST, SCA, CI/CD, Java, Python, .NET, ServiceNow, Azure DevOps, Microsoft Azure, Power BI, OWASP Top 10, NIST
International Monetary Fund: Provides loans and policy advice to stabilize global economies.
4+ YOE4+ years application security and vulnerability management experience (or 10+ with a bachelor), knowledge of OWASP/NIST/ISO frameworks, hands-on SAST/DAST/SCA, scripting (Java, Python, .NET, PowerShell), and stakeholder communication.
ServiceNow, Microsoft Azure, Microsoft Azure DevOps, Microsoft Power BI, Burp Suite, Sonatype Nexus Lifecycle, Checkmarx, Fortify, HCL AppScan, Veracode, Java, Python, .NET, PowerShell, SAST, DAST, SCA
iRhythm TechnologiesNASDAQ: IRTC: Provides wearable heart monitors and AI-driven cardiac data analytics.
8+ YOE5-8+ years in cybersecurity with focus on application and infrastructure security; regulated healthcare/medical devices experience; strong knowledge of NIST; FDA 510(k) experience preferred.
Workday/UKG Security Application Analyst, Hybrid, Jacksonville, Baptist Medical Center
Jacksonville, Florida, United States
HybridFull Time
Baptist Health: Operates hospitals and clinics providing comprehensive medical care.
2+ YOE2+ years supporting Workday or UKG security, strong IAM/RBAC/SoD knowledge, Bachelor's degree, Workday/UKG security certification preferred, experience with integrations, testing, and strong communication skills.