Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Vulnerability Analyst

Software Guidance & Assistance

Software Guidance & Assistance, Inc., (SGA), is searching for an Application Security Vulnerability Analyst for a contractor assignment with one of our premier Insurance Services clients. This is a remote role; candidates must work EST business hours.


Responsibilities:

  • Review and analyze vulnerabilities identified through SAST, SCA, AI-based, and related application security tools.
  • Perform hands-on review of application source code to validate security findings and determine whether identified vulnerabilities represent legitimate risk.
  • Triage findings before engaging development teams, with a focus on identifying false positives and minimizing non-actionable issues.
  • Evaluate vulnerabilities beyond vendor-assigned severity scores by considering exploitability, exposure, attack paths, business impact, compensating controls, and application context.
  • Validate vulnerability classifications, severity recommendations, and remediation priority.
  • Utilize AI tools and effective prompting techniques to analyze security findings, increase confidence in finding credibility, and reduce false positives.
  • Assess vulnerability trends and recurring development patterns that may require broader corrective action.
  • Explain validated application security findings clearly to developers, architects, technology owners, and business stakeholders.
  • Provide actionable remediation guidance and secure coding recommendations.
  • Partner with developers and technology owners to drive validated vulnerabilities through remediation and closure within defined SLAs.
  • Track remediation progress and escalate aging findings or remediation blockers as appropriate.
  • Validate completed remediation activities and make closure recommendations.
  • Support vulnerability triage and vulnerability management activities across multiple application security tools.
  • Participate in vulnerability review sessions and remediation discussions.
  • Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.
  • Contribute to application security procedures, reporting, and process improvements.

Required Skills:

  • 3+ years of experience in Application Security, Application Vulnerability Management, or a closely related cybersecurity discipline.
  • Hands-on experience reviewing and validating application security findings generated by SAST and SCA tools .
  • Strong application security vulnerability analysis and triage experience, including the ability to distinguish legitimate vulnerabilities from false positives.
  • Hands-on technical ability to review source code and validate security findings at the code/application level before escalating issues to development teams.
  • Ability to evaluate vulnerabilities based on actual exploitability, exposure, attack paths, application context, compensating controls, and business risk rather than relying solely on CVSS scores.
  • Strong understanding of application security concepts and practices, including:
    • OWASP Top 10
    • Common Weakness Enumeration (CWE)
    • Secure Software Development Lifecycle (SSDLC)
    • Exploit Prediction Scoring System (EPSS)
    • CVE/CVSS concepts
  • Ability to analyze application security findings involving one or more modern enterprise development languages, including Java, TypeScript, JavaScript, C#, Python, Go, Node.js, or similar languages.
  • Hands-on experience using AI tools to support application security or vulnerability analysis , including the ability to create effective prompts to validate findings, improve analysis, and reduce false positives.
  • Strong written and verbal communication skills with the ability to clearly communicate technical security findings.
  • Strong organizational skills with the ability to manage multiple vulnerability analysis and remediation efforts simultaneously.
  • Demonstrated ability to work independently and drive issues toward resolution.

Preferred Skills:

  • Experience working directly with development teams to explain vulnerabilities, provide remediation guidance, and drive findings through closure.
  • Experience with AppScan, Snyk, ZAP , or comparable application security tools.
  • Experience with Claude Code or similar AI-assisted security/development tools.
  • Secure code review experience.
  • Application security testing experience.
  • CI/CD security integration experience.
  • Experience with SCA tools and software dependency risk analysis.
  • Understanding of software architecture and common web application attack patterns.
  • Working knowledge of cloud-native applications and APIs.
  • Familiarity with enterprise vulnerability management processes, remediation SLAs, and tracking workflows.
  • Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, or similar.

Education:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field preferred, or equivalent relevant professional experience.
By applying for a job with SGA, you agree to allow SGA to process your application for this and future opportunities in accordance with our Privacy Policy. Also, to ensure timely processing, you agree to be contacted by our AI recruiter via email, text, or phone. Message frequency varies and data rates may apply, but you can reply STOP to any SMS message to opt-out of texts and may contact SGA at to opt-out of AI communications. The choice not to engage with AI will not adversely impact your consideration for placement. AI is not used to make any hiring determinations.


SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .


SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Application Security Vulnerability Analyst in New York, NY vacancy
  • $75k - $85k

     ...IT Security Analyst Who is Gen II? Gen II is a leading fund administration provider focused...  ...and reporting of systems and applications. What you’ll be doing Actively...  ...who fail phishing tests. Review Vulnerability Management Tool findings and work... 
    Application
    Full time
    Work at office
    Flexible hours
    1 day per week

    Gen Ii Careers

    New York, NY
    a month ago
  •  ...Academy is growing rapidly and security is at the forefront of...  ...are seeking a Senior Security Analyst to join our Information Security...  ...around cloud and SaaS based applications, operates networking and in-...  ...across incident response, vulnerability management, identity and... 
    Application
    Work at office
    Immediate start
    Visa sponsorship
    3 days per week

    Success Academy Charter Schools

    New York, NY
    1 day ago
  • $97.59k - $142.99k

     ...have an exciting opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the successful analyst will be part of...  ...remediation efforts with infrastructure teams and application ownersAnalyze threat intelligence reports, write risk analysis... 
    Application
    Full time

    NYU Langone Medical Center

    New York, NY
    3 days ago
  • $117.2k - $176.7k

     ...are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers...  ...AccommodationsIf you need a reasonable accommodation during the application or the recruiting process, please submit a request via... 
    Application
    Full time

    Salesforce

    New York, NY
    4 days ago
  •  ...Network Security Analyst Job Description: Position requires fully on-site reporting...  ...all corporate and enclave firewalls, application delivery controllers, RADIUS, RSA....  ...NAT for external interfaces. Vulnerability review of hardware. Preferred Skills... 
    Application
    Work experience placement
    Local area
    Rotating shift

    3B Staffing LLC

    New York, NY
    2 days ago
  • $145k - $170k

    CLEAR is building THE secure identity company of the future. Our mission is to make experiences...  ...is seeking a Senior Security Operations Analyst III to join our SOC team to help...  ...commission, Restricted Stock Units. Qualified applicants will receive consideration for... 
    Application
    Casual work
    Work at office
    Flexible hours

    Secure Identity

    New York, NY
    3 days ago
  • $191k - $305k

     ...this role:Wells Fargo is seeking a Senior Lead Information Security Analyst in Cybersecurity to join the IAM Strategic Enablement & Adoption...  ....In this role, you will:Partner with Lines of Business, application teams, and IAM product owners to drive adoption and effective... 
    Application
    Full time
    Work experience placement
    Relocation package

    Wells Fargo

    New York, NY
    2 days ago
  •  ...Position Title * Information Security Analyst Position Responsibilities Information Security Analyst New York, NY (Hybrid role),...  ...Responsibilities: Participate in developing and implementing application security governance processes. Participate in the design... 
    Application
    Contract work

    Apex Informatics

    New York, NY
    7 hours ago
  • $103k - $164k

     ...a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships...  ...-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation,... 
    Application
    Full time
    Part time
    Local area
    Worldwide
    Flexible hours

    Mastercard

    New York, NY
    3 days ago
  • Network Security Analyst Austin, Texas, United States Requirement Details: Internal job ID:...  ...intelligence, software security, and vulnerability assessment services. This position also...  ...vulnerability scans of networks and applications to assess effectiveness and identify... 
    Application
    Local area
    Remote work

    TechTalentHunt

    New York, NY
    6 days ago
  • $85k - $105k

    The Oracle Security Analyst position provides technical, functional support and security for Oracle Fusion Cloud and related applications. This is a remote-work position and will be based in the US. This position will provide technical and functional support and security... 
    Application
    Remote work
    Work from home
    Home office

    Cohu

    New York, NY
    5 days ago
  • $99.2k - $148.8k

    DescriptionThe Applications Analyst III supervises and provides technical guidance to the staff in the development of specifications for new...  ...preferred.Five years of solid, diverse work experience in ITEpic Security Certification and experience required.Employer... 
    Application
    Traineeship
    Work experience placement
    Local area
    Remote work

    Mount Sinai Health System

    New York, NY
    4 days ago
  • $76k - $105k

     ...Zero Harm policy What you will do: Investigate and respond to security alerts and incidents, performing root cause analysis and driving...  ..., experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.) All hiring... 
    Application
    Internship
    Remote work

    Johnson Controls

    New York, NY
    3 days ago
  • Security Administration and Operations Candidate must be authorized...  ..., and other agent-based applications running on Databases, Windows...  ...understanding of malware, threats, vulnerabilities, and the complete affect...  ...Additional Skills: Business Analyst. This is a high PRIORITY... 
    Application
    Remote job
    Weekend work
    Afternoon shift

    Samprasoft

    New York, NY
    6 days ago
  •  ...enhance the software delivery lifecycle, the full-time remote Application Security Analyst will integrate security controls into CI/CD pipelines,...  ...with security testing methodologies and tools, including SAST, DAST, and vulnerability management Virtual Vocations Inc
    Application
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    5 days ago
  • Application Security Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security...  ...like a seasoned security professional: identifying vulnerabilities, weighing exploitability, and recommending sound... 
    Application
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    4 days ago
  • $75k - $95k

    About the role: We are seeking an Application Security Analyst to build security into how we ship software, and to help our small but growing...  ...interactive testing tools Identify, triage, and prioritize vulnerabilities Integrate security testing into CI/CD pipelines (... 
    Application
    Work at office
    Remote work
    Flexible hours

    FSAStore.com

    New York, NY
    5 days ago
  • Job Title: Information Security Analyst Job Summary: We are seeking a highly motivated Information...  ...'s information systems, networks, applications, and data assets from cyber threats....  ...security events, identifying vulnerabilities, conducting risk assessments, responding... 
    Application
    Full time
    Remote work

    Ova Technologies

    New York, NY
    6 days ago
  • $75k - $110k

     ...policy Ten company-paid holidays per year About the Role The Application Security Analyst helps embed security into the software delivery...  ...principles, secure coding practices, cloud security controls, vulnerability management, and modern DevSecOps methodologies. The... 
    Application
    Local area
    Immediate start
    Remote work
    Flexible hours

    Sound Physicians

    New York, NY
    5 days ago
  • Information Security Analyst 2 Start Date: 09/01/2020 End Date: 03/01/2021 Work Location: Bismark North Dakota 58503 Client: State of North Dakota Pay Rate: $35/hr on w2 all inclusive CYAD Web Application Security Scanning NDIT has 1 contract position open for a Web Application... 
    Application
    Contract work
    Remote work
    Work from home

    Omega Solutions Inc

    New York, NY
    6 days ago
  • $87k - $92k

    Information Security Analyst Posting Details Job # 042836 Department Code 20703-6034 Department...  ...intersection of threat detection, vulnerability management, and forensic...  ...across all operational functions and the application of AI as a solution is a core expectation... 
    Application
    Full time
    Summer work
    Remote work

    Syracuse University

    New York, NY
    4 days ago
  • $169.95k - $179.3k

    Senior Information Security Analyst McKesson is an impact-driven, Fortune 10 company that touches...  ...in the job offered or related field. Applicant must have five (5) years demonstrated...  ..., Linux, and Unix environments. Vulnerability management, penetration testing, and secure... 
    Application
    Remote work

    McKesson

    New York, NY
    4 days ago
  • Information Security Analyst At Gifthealth, we're revolutionizing the way people experience healthcare...  ...monitoring, incident response, vulnerability management, endpoint security, email...  ...providers and other security vendors when applicable. Security Operations and Reporting:... 
    Application
    Full time

    Gifthealth

    New York, NY
    4 days ago
  • $96.57k - $130.65k

     ...Qualifications: Skills: Cyber Risks, Security Compliance, Vulnerability Assessments, Vulnerability...  ...career. The Security & Compliance Analyst will work as part of the CMM Data Modernization...  ...analyses of computer systems and applications during all phases of the system... 
    Application
    Temporary work
    Work at office
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    New York, NY
    6 days ago
  • $137.8k - $180.8k

    The Opportunity As a Mastery Level Security Operations Center (SOC) analyst you'll have an opportunity to be part of a growing team of highly...  ...mining large datasets Understanding of web application vulnerabilities including XSS, CSRF, SQL Injection, command injection... 
    Application
    Temporary work
    Remote work

    Massachusetts Mutual Life Insurance Company

    New York, NY
    6 days ago
  •  ...growing healthcare technology company is looking for an IT & Security Analyst to join its Security team. This is a hands-on role with real...  ...management administration, including SSO/MFA configuration, application access assignments, and periodic access reviews. Support... 
    Application

    Cleartech Recruiting

    New York, NY
    5 days ago
  • Third Party Information Security Analyst This role is located in New York City and will require a hybrid work schedule of at least 2 days...  ...are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to... 
    Application
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Sumitomo Mitsui Trust Bank

    New York, NY
    6 days ago
  • $110.5k - $149.5k

    Information Security Analyst Principal This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Information Security Analyst Principal based in the United States. This is a senior cybersecurity role... 
    Application
    Full time
    Temporary work
    Remote work
    Monday to Friday
    Flexible hours

    Jobgether

    New York, NY
    6 days ago
  • Application Security Risk & Automation Analyst We are seeking an experienced Application Security Risk & Automation Analyst to support the automation and...  ...workflows, reducing developer friction, improving vulnerability remediation, and automating security findings management... 
    Application

    Leading Utilities Organization

    New York, NY
    4 days ago
  • Guardian is seeking an experienced professional to lead vulnerability analysis and risk assessment within its application security program. You will review findings from SAST/SCA tools, evaluate risk beyond CVSS, and provide actionable remediation guidance to developers... 
    Application

    Perennial Resources International

    New York, NY
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Vulnerability Analyst. Be the first to apply!