Security Analyst, AppSec
TradeStation Security Analyst, AppSec
- Work with the Application Security team to improve the security of company application assets
- Perform periodic security assessments of applications, incorporating SAST, DAST, SCA, IaC scanning, and other testing methodologies as appropriate
- Perform analysis and validation of security test findings and communicate regularly with engineering staff including developers, managers, product owners, etc. on security test findings and remediation tracking
- Review, update and develop required security documentation, including Information Security policies and standards
- Develop and compile metrics, dashboards, and analytics for executive-level audiences, using SQL and/or reporting tools (Excel data function, Excel pivot table, PowerBI)
- Assist with MBI (Material Business Initiative) security reviews across the development lifecycle, including pre-development, pre-release, and privacy assessments
- Assist with the integration of security scanning and policy gating into CI/CD pipelines (e.g., GitLab CI, GitHub Actions) to enforce security requirements at build time
- Assist to design, build, and maintain security automation tooling and scripts (Python, JavaScript, etc.) — including CI/CD pipeline integrations — to reduce manual review overhead and improve scan coverage and consistency
- Stay current on IT compliance trends and news related to security (NIST, Cobit, PCI, SOX, GDPR…) and make recommendations to the security team
- Assist with configuring, installing and administering security tools and systems
- Assist with the evaluation of new and existing security tools, platforms, and technologies, including in-depth reviews of third-party tools, SaaS integrations, and MCP (Model Context Protocol) servers prior to organizational adoption, using established review frameworks and checkpoint standards
- Conduct continuous health monitoring of security tooling and control implementations
- Support project assignments with strong and effective communication, time management and collaboration skills
- Assist with other security-related initiatives as they arise
- Self-driven, organized, details-oriented with an ownership attitude
- Excellent English verbal and written communication skills
- Able to effectively interact with all levels of the organization
- Strong analytical, problem-solving, and troubleshooting skills
- Able to multitask and prioritize work in a quickly changing business environment
- Knowledge or experience developing documentation and conducting reviews.
- Solid understanding of core security principles (e.g., Segregation of Duties, Least Privilege) and familiarity with relevant compliance and standards frameworks (PCI-DSS, SOX, GDPR, OWASP, NIST, etc.)
- Solid understanding of security concepts such as Segregation of Duties, Data Classification or Least Privilege
- Demonstrated personal initiative in maintaining a continuous level of professional knowledge in areas of technology and security
- Experience with Microsoft Office products, especially Excel and excel functions (TRIM, VLOOKUP and other data functions), Word, and PowerPoint and PowerBI
- Desire to learn new security technologies and practices
- Proficiency in at least one scripting or programming language (e.g., Python, JavaScript) for building automation and tooling to support security operations
- Knowledge or experience with SQL and reporting tool(s) is a plus
- Excellent skills with Microsoft Office and Atlassian tools (Jira and Confluence)
- Working knowledge of the Software Development Life Cycle (SDLC) and secure coding practices, with the ability to communicate findings effectively to development teams
- Experience as a software developer and/or Quality assurance tester is a plus
- Knowledge or experience with Microsoft Azure and Amazon Web Services environments is a plus
- An acknowledged industry security certification such as Security+, or CySA+ is a plus
- Demonstrated progression toward security career goals and willing to pursue relevant professional designations (ex. CISA, CISM, CISSP) preferred
- Hands-on experience with application security testing methodologies and tools, including SAST, DAST, SCA, and tools such as Checkmarx, OWASP ZAP, Burp Suite, Nmap, or equivalents
- Experience with software development programming and scripting languages preferred
- Experience with distributed and scalable cloud architecture, containerization, Docker, and/or Kubernetes. Kubernetes certification(s) are a plus
- Experience with Microsoft Azure and Amazon Web Services (AWS) environments. AWS, Azure certification(s) are a plus
- Experience integrating security scanning and controls into CI/CD pipelines (e.g., GitLab CI, GitHub Actions) is a plus
- Must be in Costa Rica and able to work core US Eastern Time hours
- Bachelor's Degree in Computer Science/Information Technology/Information Security or equivalent work experience required
- Minimum of 3 years of Information Technology and/or Information Security work experience is required
- Ability to travel to company offices, including international offices, or other locations occasionally as needed for meetings, training, to perform work tasks, etc.
- Collaborative work environment
- Competitive Salaries
- Yearly bonus
- Comprehensive benefits for you and your family starting Day 1
- Unlimited Paid Time Off
- Flexible working environment
- TradeStation Account employee benefits, as well as full access to trading education materials