Security Analyst
ASM Research
The Security Analyst integrates application security practices throughout the software development life cycle for enterprise and mission-critical systems. The role partners with software engineering, architecture, DevOps, operations, and client stakeholders to translate security requirements into practical design, development, testing, deployment, and remediation activities.
The Security Analyst conducts security architecture and design reviews, vulnerability assessments, and technical risk analyses; interprets findings; and guides application owners through prioritized mitigation and validation. The role also develops and enforces secure-development procedures, evaluates security tools and automation, and strengthens the organization’s application security posture in a highly regulated federal IT environment.
Key Responsibilities
-
Integrate application security requirements, secure design practices, and security acceptance criteria across planning, development, testing, deployment, and maintenance phases of the software development life cycle.
-
Conduct and support security architecture reviews, threat modeling, secure design reviews, and vulnerability assessments for web applications, APIs, cloud-hosted workloads, services, and supporting infrastructure.
-
Analyze findings from static application security testing, dynamic application security testing, software composition analysis, dependency scanning, secrets scanning, container scanning, and penetration testing to determine risk and remediation priority.
-
Partner with development, DevOps, architecture, and operations teams to identify security risks, explain vulnerabilities, and provide practical, actionable mitigation recommendations.
-
Perform or support secure code reviews and assess applications for authentication and authorization weaknesses, insecure configurations, secrets exposure, common software weaknesses, and other security control gaps.
-
Track vulnerabilities and corrective actions through remediation, validate evidence of closure, and perform retesting as needed to confirm risk reduction.
-
Develop and maintain security procedures, technical standards, assessment reports, and risk communications that support informed authorization, remediation, and stakeholder decisions.
-
Evaluate application-security products and developer-facing tools for coverage, integration feasibility, operational impact, reporting quality, and compatibility with source-control and CI/CD workflows.
Required Qualifications
-
Bachelor’s degree in Computer Science, Engineering, or another technical discipline, or equivalent relevant experience.
-
Typically 5–10 years of progressively responsible experience in application security, secure software engineering, vulnerability management, or a closely related cybersecurity discipline.
-
Demonstrated experience applying secure SDLC practices, including security requirements definition, threat modeling, architecture review, secure design patterns, and security acceptance criteria.
-
Experience assessing web applications, APIs, services, cloud-hosted workloads, and supporting infrastructure for vulnerabilities, insecure configurations, identity and access control weaknesses, and software security risks.
-
Ability to interpret, prioritize, and communicate findings from application-security testing, vulnerability scanning, dependency analysis, secrets scanning, container scanning, and penetration testing.
-
Strong working knowledge of vulnerability triage, risk scoring, exploitability analysis, compensating controls, remediation tracking, and validation of corrective actions.
-
U.S. citizenship is required, with the ability to obtain and maintain a Public Trust background investigation.
Preferred Qualifications
-
Professional security certification such as CSSLP, Security+, CISSP, a GIAC application-security credential, or a cloud-security certification.
-
Experience embedding automated security controls, policy gates, and scan-result workflows into CI/CD pipelines and infrastructure-as-code delivery processes.
-
Experience supporting application security activities within a highly regulated federal, defense, or government environment.
-
Experience conducting secure architecture reviews, applying threat-modeling methods, and remediating OWASP-aligned application-security risks.
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
- • Work from remotely or from home • Complete back office support • Zero micro-management We're a perfect fit for top account managers and existing entrepreneurs. Be your own boss, but have the power of a thriving startup. We're a next-generation platform. We are ...SuggestedFull timeRemote workWork from homeFlexible hoursWeekday work
- ...Position: Security Cooperation (SC) Analyst Location: Tampa, FL Job Id: 2027-OAMS - 25P-MO-933 # of Openings: 1 Security Cooperation (SC) Analyst Please note: This position is contingent upon the award of a contract. We will provide...SuggestedDaily paidFull timeContract workTemporary workFor contractorsLocal areaOverseas
$130k - $160k
...expand their attack surface, we are putting cutting-edge offensive security into the hands of defenders. Backed by strong investor support... ...Aptiv. About the Role We are looking for a Security Analyst to join our security research team. You will work hands-on with...SuggestedFull timeRemote work- ...To enhance security governance and compliance, the full-time remote Security Analyst I will perform cybersecurity risk assessments, maintain information security policies, and support audits while collaborating with various stakeholders across the organization. Key responsibilities...SuggestedFull timeRemote work
- ...Security Analyst Company: Northwestern Medicine Work Type: Remote Employment: Full Time Location: US Seniority: Entry Level Technologies: Windows, Linux/UNIX, TCP/IP, Security controls, Proxies, IPS, IDS, Firewalls, Endpoint protection, Scripting languages Requirements...SuggestedFull timeRemote work
- ...Passionate about applying AI to cybersecurity, the fully remote Security Analyst will monitor and protect the organization's environments, applications, services, endpoints, and networks while managing access control policies, overseeing device management, and responding...Remote work
- ...About the job Security Analyst Security Analyst ~ Contract - 4 months ~100% Remote ~ Due to our government client requirements, we can only consider US Citizens or Green Card Holders for this position. Must have lived in the US 3 of the past...Permanent employmentContract workH1bRemote workVisa sponsorship
$104k - $156k
...midstream service provider. Safety first. Sustainable operations. Environmentally responsible. Employee focused. JOB SUMMARY The Security Analyst III serves as a senior technical contributor within the Enterprise Security Tools & Architecture team. This position is...Work at officeLocal area- ...Security Analyst Sacramento, CA 18+ months Mandatory Qualifications: A minimum of seven (7) years’ experience within the last 10 years, providing security vulnerability and risk assessment services directly or through a partner relationship. At least three...
- ...Title: Security Analyst - Advanced Location: Columbia SC - 29210 On-site/Remote/Hybrid: Hybrid (1 days onsite per week) Duration: 12 Months Interview Process: 1 Round - Video Conference Note: Candidate must be a CURRENT SC resident. No relocation...Work experience placementWork at officeRemote workRelocation1 day per week
- ...Description **This position requires Secret Security Clearance** COMPANY OVERVIEW Founded in 2008, LNO, Inc. is a rapidly growing... ..., and Technology and Business Training. Senior Security Analyst LNO is seeking an Information Cloud Security Analyst to...Work at officeLocal areaWorldwide
- ...Security Analyst II PM MC provides integrated system-of-system solutions to Army and Joint warfighters, whose products include computer hardware, software, communications and network management infrastructure. The Mission Command Support Center (MCSC), under PM MC,...For contractorsInterim roleWork at officeWorldwide2 days per week3 days per week
- Security Analyst Location: Tallahassee, FL (Hybrid) Hire Type: Contract (12+ months) Client: State of Florida Job Description Need Security Analyst Skills: Healthcare, NIST, Build & Release Management Experience: 8+ YearsContract work
- ...Title: Security Analyst - Project Lead (8780) Work Location: 1201 Main Street, Suite 600, Columbia, SC 29201 Work Mode: Hybrid (3 days onsite per week required) Contract Duration: 12 months (Extension possible) Interview Process: 1 round, virtual video...Contract workWork at officeRemote workRelocation3 days per week
- ...Security Analyst II Corporate Headquarters - Chattanooga, TN 37402 Overview Position Type Full Time Job Shift M - F 8:00 - 4:45 Education Level 4 Year Degree Category Banking Description JOB SUMMARY: The Security Analyst II is responsible for advancing...Full timeWork experience placementShift work
- ...SAP Security Administrator Design, build, implement and support SAP security roles, profiles and authorizations to SAP ECC, with the possibility of CRM, SCM, Fiori, GRC, BI, GTS, BI4 and HANA environments and clients ensuring appropriate safeguards are in place...Remote work
- ...FMS Program Security AnalystVTG is seeking an FMS Program Security Analyst in Huntsville, AL. What will you do?Serve as an FMS analyst responsible for developing and managing the execution of case lines as assigned for their respective country.Responsibilities will require...Work at office
- RESPONSIBILITIES: Kforce has a client that is seeking a Security Analyst in Utah Valley, UT. Summary: We are seeking a Security Analyst to help build and mature a growing cybersecurity program within a technology-driven organization. This role will be responsible...Hourly payContract work
$58.67k - $80.67k
...Security Analyst II Location: Larkin Bldg @ Exchange Street Location of Job : US:NY:Buffalo Work Type : Full-Time Shift 1 Job Description Responsible, on a 24 hour, 7 day-per-week basis, for support to professionals involved in planning, design,...Bi-weekly payFull timeShift workWeekend work- ...Our client is strengthening its security operations as its network and business systems grow across multiple states. They are seeking an experienced Security Analyst II to investigate and respond to security events across email, identity, endpoint, and network systems...
- ...Security Analyst - Identity & Access Management Location: San Antonio, TX or Plano, TX (On-site) About the Role Join a forward-thinking security team as a Security Analyst focused on driving enterprise-level account discovery and identity visibility initiatives...
$75k - $85k
...Description Security Analyst II **THIS IS NOT A REMOTE POSITION** Annual pay range $75,000 to $85,000 (Non-Exempt, Hourly) WE ARE A CONTRACTED FEDERAL DRUG-FREE WORKPLACE All shifts available in 24/7 Operations Center (Day, Swing, Grave) About ISSE...Hourly payAll shifts- ...Security Analyst Full-time Onsite - NYC No 3rd parties please. This role is not eligible for employment-based immigration sponsorship. Applicants must be legally authorized to work in the United States without employer sponsorship, now or in the future....Full timeVisa sponsorship
- ...learn more about Trulieve and our mission, please visit Requisition ID: 21173 Remote Work Available: No Job Title: Security Analyst Department: Security Reports To: Security Manager Job Summary: The Security Analyst (SA) will support...Work experience placementWork at officeLocal areaRemote work
- ...Personnel Security AnalystAs a Personnel Security Analyst, you will provide personnel security support and resolution of issues of low and medium complexity in a collaborative team office environment. In this role, you will assist the Government in operating a responsive...Work at office
- » » Security Analyst – IntermediateLocationSouth Carolina, Columbia### Description**Job Description:**Develops and manages security for more than one IT functional area (e.g., data, systems, network and/or Web) across the enterprise. Assists in the development and implementation...
- ...Security Analyst Artech Information Systems is the #1 Largest Women-Owned IT Staffing Company in the U.S. and an employer of choice for over 7,200 consultants. We recruit world-class talent for IT, engineering, and other professional jobs at 70+ Fortune and Global...Contract work
- ...Security Analyst In this role, you will work collaboratively with the Cybersecurity GRC team along with stakeholders across the business to assess, review, verify, and audit technology controls related to GRC Compliance. The GRC Compliance Specialist will be responsible...
- ...Position: IAM Remediation & Identity Security Analyst Location: Remote (working PST hours) Contract: 6+Months Overview We are seeking an experienced Identity & Access Management (IAM) professional to support remediation efforts following a recent...Contract workRemote work
$75k - $90k
...Overview Nakupuna Companies is seeking a full-time Mid-Level Security Analyst to join our team of talented consultants supporting the Department of War. The position provides security analysis, program support, administrative coordination, and customer service across...Full timeContract workFor contractorsWork at officeRelocationOverseas
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst. Be the first to apply!
- entry level information security analyst United States
- junior security analyst United States
- application security analyst United States
- IT security analyst United States
- network security analyst United States
- information security compliance analyst United States
- security analyst remote United States
- information security analyst United States
- work from home security analyst United States
- national security analyst United States


