Application Security Analyst

Summary

The Application Security Analyst assesses and improves application security by validating SAST/DAST results, auditing infrastructure, and collaborating with development teams to remediate vulnerabilities. The role focuses on maintaining security compliance and documentation while utilizing tools like Black Duck and Coverity.

Application Security Analyst / Application Security Specialist

Overview

The Application Security Specialist is responsible forassessing, validating, and improving the security posture of applications andsupporting infrastructure. The role involves working closely with development,DevSecOps, and infrastructure teams to identify, analyze, and remediatesecurity vulnerabilities while ensuring compliance with security standards andbest practices.

Key Responsibilities

  • Review and validate results from Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools.
  • Audit operating systems, containers, and database vulnerability scan reports to identify security risks and misconfigurations.
  • Assess the effectiveness of security hardening measures across application components, including web servers, APIs, containers, and databases.
  • Collaborate with application development and DevSecOps teams to drive remediation of identified vulnerabilities and security gaps.
  • Maintain audit documentation, including findings, remediation tracking, risk assessments, and compliance status.
  • Evaluate adherence to secure coding practices and application security policies.
  • Support internal and external security audits related to applications and underlying infrastructure.
  • Monitor emerging threats, vulnerabilities, and industry security trends to enhance security posture.
  • Conduct or support Vulnerability Assessment and Penetration Testing (VAPT) activities.
  • Provide guidance on vulnerability mitigation and remediation best practices.

Required Skills & Experience

  • Strong understanding of Application Security principles and best practices.
  • Hands-on experience with SAST and DAST tools.
  • Experience reviewing and analyzing vulnerability assessment reports.
  • Good understanding of the OWASP Top 10 and common web application security risks.
  • Experience with Software Composition Analysis (SCA) tools such as Black Duck or equivalent.
  • Experience with SAST tools such as Coverity or equivalent.
  • Knowledge of container, operating system, database, and infrastructure security.
  • Familiarity with secure software development lifecycle (SSDLC) and DevSecOps practices.
  • Experience working with development teams to validate and remediate security findings.
  • Strong documentation, audit, and reporting skills.

Preferred Qualifications

  • Industry-recognized security certifications such as OSCP, CREST, CEH, CISSP, GIAC, or equivalent.
  • Experience in penetration testing and security assessments.
  • Knowledge of cloud security and container security best practices.
  • Understanding of regulatory and compliance requirements related to application security.

Desired Competencies

  • Strong analytical and problem-solving skills.
  • Effective stakeholder management and cross-functional collaboration.
  • Ability to communicate security findings and remediation recommendations clearly.
  • Continuous learning mindset with awareness of evolving cybersecurity threats and technologies.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available