Application Security Analyst
HealthStream
Application Security Analyst
USA Remote - Nashville, TN 37203
Overview
Position Type Full Time Job Shift Day Education Level 4 Year Degree Travel Percentage Negligible Category Information Security Services
Description
HealthStream is the leader in healthcare workforce solutions. We help organizations work better by helping their people work smarter.
HealthStream provides the leading learning, clinical development, credentialing, and scheduling applications delivered on healthcare's #1 platform. We streamline everyday tasks while improving performance, engagement, and safety – fostering a workplace where people flourish, and care thrives.
Why Join Us
At HealthStream, you'll have the opportunity to make a meaningful impact on the future of healthcare by collaborating with a team of talented professionals dedicated to innovation and excellence. We offer competitive compensation, comprehensive benefits, and a supportive work environment where creativity and collaboration thrive.
Our shared vision is to enhance the quality of healthcare by empowering the people who deliver care – a commitment we have upheld for over 30 years through providing innovative solutions and driving constant growth. Join us in revolutionizing the healthcare industry and shaping the future of patient care. As a HealthStreamer, you will be at the forefront of healthcare technology innovation, making a recurring impact on the industry.
We're proud of our values-forward culture that offers our people:
- Mission-oriented work
- Diverse and inclusive culture
- Competitive Compensation & Bonuses
- Comprehensive Insurance Plans
- Mental and Physical Health Support
- Work-from-home flexibility
- Fitness Center Reimbursements
- Streaming Good time off for volunteering
- Wellness workshops
- Buddy Program for new HealthStreamers
- Collaborative work environment
- Career growth opportunities
- Continuous learning opportunities
- Inspiring workspaces to collaborate and connect with other HealthStreamers
- Free employee parking at our Resource Centers in Nashville and San Diego
At HealthStream, our thriving culture encourages collaboration and values contributions, allowing our team members to continuously solve big problems and grow. We offer flexibility and paid time off to support work-life integration for all employees, including a hybrid work environment and Streaming Good volunteer day. For team members in commutable distance, HealthStream has Resource Centers in Nashville, TN and San Diego, CA. Our resource centers provide an inspiring workspace to collaborate and recharge as well as company-sponsored onsite social events for development, connection, and celebration.
We are committed to driving innovation in healthcare and ensuring that patients receive competent care from qualified professionals. As a HealthStream team member, you will help bring this vision to life. If you want to work for a company committed to its values and vision, HealthStream is the place for you!
HealthStream is an equal opportunity employer. HealthStream prohibits employment practices that discriminate against individual employees or groups of employees on the basis of age, color, disability, national origin, race, religion, sex, sexual orientation, pregnancy, veteran or military status, genetic information or any other category deemed protected by state and/or federal law.
Position Information
Position Overview
The Application Security Analyst plays a hands-on role in supporting and executing the application security program at HealthStream. Working closely with and under the guidance of the Sr. Application Security Architect, this role focuses on identifying, assessing, and helping remediate security vulnerabilities across our software products and cloud environments. The Analyst will partner with Engineering, DevOps, and Product teams to embed security practices into the software development lifecycle (SDLC), operate security tooling, and contribute to a culture of security awareness. This is an excellent opportunity for a motivated security professional looking to grow within a collaborative, mission-driven healthcare technology organization.
Key Responsibilities
You will be responsible for adhering to all HealthStream security policies, procedures, and assigned training.
Application Security Testing & Vulnerability Management
- Operate and manage automated application security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST).
- Triage, validate, and prioritize vulnerability findings from security scans, penetration tests, and bug reports, working with development teams to track remediation to closure.
- Conduct or support manual security assessments and penetration testing of web applications, APIs, and mobile applications.
- Produce clear, actionable vulnerability reports with risk ratings and remediation guidance for development teams.
- Manage and maintain vulnerability findings within the Snyk, Invicti and SonarQube or equivalent vulnerability management platform.
Secure Development Lifecycle (SDLC) Support
- Support the integration of security into CI/CD pipelines and DevSecOps workflows, including automated security gate checks.
- Participate in design and architecture reviews with a security lens, helping identify potential risks early in the development process.
- Assist in threat modeling exercises for new features and systems under the guidance of the AppSec Architect.
- Perform security-focused code reviews and provide developers with clear, constructive feedback and guidance.
- Contribute to the maintenance of a secure code library and reusable security patterns for development teams.
Security Tooling & Cloud Security
- Support the management and configuration of application security tools such as Synk, Invicti, SonarQube and DefectDojo.
- Assist in implementing and monitoring security controls for cloud-based environments, including AWS and Azure.
- Evaluate and test emerging security tools and contribute recommendations to the AppSec team.
- Support API security testing and assist in securing third-party and open-source integrations.
Security Awareness & Collaboration
- Collaborate with cross-functional teams including Engineering, DevOps, and Product to promote security best practices and a shift-left mindset.
- Deliver security awareness content and assist in conducting security training sessions for development staff.
- Stay current on emerging security threats, vulnerabilities (CVEs), and attack techniques, sharing relevant intelligence with the team.
- Assist in maintaining security documentation, standards, runbooks, and internal knowledge base articles.
- Support compliance-related activities, including evidence gathering for audits related to HIPAA, SOC 2, HITRUST or other applicable frameworks. FedRAMP experience is a plus.
- Other Duties as assigned.
Qualifications
Requirements
- Bachelor's degree in information security, Computer Science, Software Engineering, or a related field. Equivalent practical experience will be considered.
- 2 to 4 years of experience in application security, information security, or software development with a security focus.
- Working knowledge of the OWASP Top 10, common web application vulnerabilities, and secure coding principles.
- Hands-on experience with application security testing tools such as SAST, DAST, or IAST (e.g., Synk, Invicti, Checkmarx, SonarQube, Burp Suite, or similar).
- Familiarity with cloud security concepts and hands-on exposure to AWS or Azure environments.
- Understanding of CI/CD pipelines and experience integrating security checks into DevOps workflows.
- Experience with API security testing and a solid understanding of RESTful service security.
- Proficiency in at least one scripting or programming language such as Python, JavaScript, Java, or Go for automation and security tooling purposes.
- Strong analytical and problem-solving skills with attention to detail.
- Excellent written and verbal communication skills, with the ability to explain security concepts to both technical and non-technical audiences.
- Ability to manage multiple tasks and vulnerabilities simultaneously, prioritizing effectively in a fast-paced environment.
Qualifications
- Relevant security certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), GWAPT, eWPT, or equivalent.
- Experience using vulnerability management platforms such as Snyk, Invicti, or similar.
- Familiarity with security frameworks and standards including OWASP SAMM, NIST, or CIS Controls.
- Exposure to healthcare industry security and privacy regulations, including HIPAA.
- Experience with secure methods of integration with third-party platforms and open-source components.
- Participation in bug bounty programs, Capture the Flag (CTF) competitions
- ...Security Applications Analyst Sacramento, CA 12+ months Required Skills/Experience: Implement, configure, and maintain Information Security and Risk Management software platforms and computing systems. Provide customer service support to applicable software...Suggested
$38 - $60 per hour
...Application Security Analyst $38-60/hr Remote Freelance CODING About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems — and we need security professionals who understand how software actually breaks in the real world...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours- ...Application Security Analyst What if your security expertise could help the next generation of AI systems understand how software actually breaks in the real world? We're partnering with leading AI research labs to build training data that teaches AI how to think...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Looking For Toyota Financial Services (TFS) Technology team is looking for a highly motivated person to fill a role as an Application Security Analyst. Your responsibilities will be to ensure the security of company software applications, web services, and APIs. You will...SuggestedRelocation packageEarly shift
- ...Description We are seeking an Application Security Analyst to join our team in a junior position focused on helping secure the business applications that support the organization. This role will support application and AI registers, perform application risk assessments...Suggested
- ...Join to apply for the Application Security Analyst role at Charles Schwab . At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry...Full timeInternshipWork at officeShift work
$98.84k - $148.26k
...Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical... ...resources to achieve their full potential. SUMMARY The Senior Application Security Analyst plays a key role in protecting WAHBE’s data and applications...Work at officeImmediate startRemote workMonday to FridayShift work$67.98k - $108.77k
...0 N Field Drive Lake Forest, IL 60045, USA Join a Great Place to Work certified company - our Information Security Team is seeking an Application Security Analyst ! Are you passionate about securing applications and helping development teams build software that is resilient...Temporary workWork at officeLocal area3 days per week- ...Alignerr is looking for an experienced Application Security Analyst to work with leading AI research labs. Your expertise will shape how AI systems reason about application risk and exploitability. You will analyze various application security scenarios and identify vulnerabilities...FreelanceRemote work10 hours per weekFlexible hours
- ...Consumers Credit Union, Illinois is seeking an Application Security Analyst to strengthen their application security program. The candidate will perform static and dynamic application security testing and work closely with developers to identify vulnerabilities. Preferred...
- ...save time applying, Toyota does not offer sponsorship of job applicants for employment-based visas or any other work authorization... ...for a highly motivated person to fill a role as a Application Security Analyst. Your responsibilities will be to ensure the security of...Relocation packageEarly shift
- ...Application Security Analyst Your ability to spot what actually breaks in production not just what looks risky on paper is exactly what the next generation of AI needs. At Alignerr, we partner with the world's leading AI research labs to build smarter, safer AI systems...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$67.98k - $108.77k
Description Join a Great Place to Work certified company - our Information Security Team is seeking an Application Security Analyst ! Are you passionate about securing applications and helping development teams build software that is resilient against evolving cyber...Temporary workWork at officeLocal area3 days per week- ...Application Security Analyst Duration: 12 Months Location: Plano, TX Pay Rate: $65/hr on W2 (H4, USC, GC, TN) Hybrid: 3 day onsite, 2 day remote Interview process: 1st round virtual & 2nd round onsite Job Description What we're looking for: We...Remote workShift work
- ...Stellantis is seeking a dedicated Application Security specialist to focus on identifying and mitigating application security vulnerabilities. This role, based in Auburn Hills, MI, requires strong involvement in DevSecOps practices and collaboration with development teams...
- ...Backed by a publicly traded parent company and undergoing a digital modernization effort. A highly skilled Information Security team focused on application security, DevSecOps, threat detection, and vulnerability remediation. A tech-forward organization prioritizing...Full time
$55k - $128.8k
Fairygodboss is offering a Security Analyst position focusing on application security and risk assessment in Strongsville, Ohio. The role emphasizes collaboration, communication, and analytical skills with a preference for familiarity in Agile methodologies and security...- Toyota Deutschland GmbH in Plano, Texas, is seeking an Application Security Analyst to ensure the security of software applications, web services, and APIs. You will collaborate with development teams to identify vulnerabilities, recommend solutions, and integrate security...
$67.98k - $108.77k
Myconsumers in Lake Forest, IL, is seeking an Application Security Analyst to join its Information Security Team. This hybrid role requires the candidate to work three days a week at the Lake Forest office. The analyst will be responsible for performing application security...Work at office3 days per week- Join to apply for the Application Security Analyst role at Paycom Join to apply for the Application Security Analyst role at Paycom Description The Application Security Analyst I position exists to protect the security posture of the Paycom application through tasks such...Full time
- A leading IT staffing company in Charlotte, NC is seeking candidates with strong skills in API security testing and vulnerability management. The ideal candidate will possess hands-on experience with DAST tools and container security, strong communication and stakeholder...Remote job
- ...Fairygodboss is seeking a Security Analyst to enhance the security posture of the organization. This role involves analyzing security processes... ...medical coverage, 401(k) matching, and paid time off. Applicants should be familiar with Agile concepts and possess hands-on...
- Consumers Credit Union is looking for an Application Security Analyst to join its Information Security Team in Lake Forest, IL. This role involves securing applications and helping development teams to identify vulnerabilities and implement best practices. You will work...
$89.6k - $194k
...SAP Application Security and GRC Analyst (Sr.) - U.S. Citizenship Required Category: ERP/CRM/Tools Main location: United States, Virginia, Fairfax Alternate Location(s): United States, Louisiana, Lafayette United States, Virginia, Lebanon United States, Tennessee...Full timeContract workWork at officeLocal area2 days per week- ...Strong experience in Application Security, Security Architecture, or Information Security Consulting . Experience conducting security architecture reviews, threat modeling, and risk assessments . Knowledge of secure software development practices and...Remote work
- IT Applications Security Engineer/Analyst Contract 360 IT Professionals is a California base Minority Business Enterprise specializing in the field of IT Consulting and Staffing. Since our Inception we have been providing industry leading IT solutions for Staffing and...Contract workLocal areaImmediate start
- A leading IT consulting firm is seeking an IT Applications Security Engineer/Analyst for an 11-month contract in Atlanta, GA. This position focuses on identifying and mitigating security risks in client applications while ensuring secure software development practices....Contract workLocal areaImmediate start
$115k - $185k
...solutions. Our Radio Products Team is seeking a hybrid Software Security Analyst . You would be a member of the Cyber Security Team working... ...may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject...Work experience placementWork at officeWorldwide$115k - $185k
...solo. Our Radio Products Team is seeking a hybrid Software Security Analyst. You would be a member of the Cyber Security Team working on... ...clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject...Work experience placementWork at officeWorldwide$72k - $133.5k
...capacity tuning, and support of third-party infrastructures, applications, and appliances (i.e., transaction, collaboration, communications... ...AI-enabled capabilities—are aligned with UPS IT, Information Security, and AI governance standards, supporting secure, compliant,...Permanent employmentTemporary workWork experience placementWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Analyst. Be the first to apply!
- software development analyst United States
- rpg programmer analyst United States
- application security analyst United States
- clinical applications analyst United States
- cash application analyst United States
- software test analyst United States
- engineering business analyst United States
- junior application support analyst United States
- software analyst United States
- engineering change analyst United States

