Senior Application Security Analyst

Posted 111ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Application Security Analyst protecting applications and systems at Triumph. Collaborating to identify risks and reduce vulnerabilities in a cybersecurity defense team.

Responsibilities:

  • Analyze application architectures to identify security risks and potential attack paths
  • Perform secure code reviews and vulnerability assessments, recommending effective remediation
  • Integrate security tools and automated checks into CI/CD and DevOps pipelines
  • Use static and dynamic scanning tools to identify, prioritize, and track security findings
  • Partner with developers and operations teams to embed security throughout the SDLC
  • Document and report application security issues, including remediation guidance and validation
  • Support new application and technology launches to prevent misconfigurations and data exposure
  • Collaborate with red teams, threat intelligence, and risk teams to reduce overall attack surface
  • Communicate security risks clearly to both technical and non-technical audiences
  • Support internal and external audits focused on compliance and risk reduction
  • Help define metrics and KPIs that demonstrate the effectiveness of the application security program
  • Participate in change management discussions and continuous improvement initiatives

Requirements:

  • 3–5+ years of experience in application security, with exposure to secure software development practices
  • Solid understanding of application architecture, APIs, microservices, and web and mobile security
  • Experience with static and dynamic application security testing and vulnerability management tools
  • Working knowledge of DevSecOps concepts and CI/CD security integration
  • Ability to script or work with languages such as Python, Bash, PowerShell, or Perl
  • Familiarity with OWASP Top 10, CVSS, MITRE ATT&CK, and the software development lifecycle
  • Comfortable reviewing code and understanding security risks across different programming languages
  • Bachelor's degree in Information Security, Computer Science, Information Systems, or equivalent experience
  • Security certifications such as GWEB, CSSLP, or GPEN are a plus

Benefits:

  • Medical
  • Dental
  • Vision
  • Paid Time Off
  • 401k and much more.