Application Security Vulnerability Analyst
Software Guidance & Assistance
Software Guidance & Assistance, Inc., (SGA), is searching for an Application Security Vulnerability Analyst for a contractor assignment with one of our premier Insurance Services clients. This is a remote role; candidates must work EST business hours.
Responsibilities:
Required Skills:
Preferred Skills:
Education:
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
Responsibilities:
- Review and analyze vulnerabilities identified through SAST, SCA, AI-based, and related application security tools.
- Perform hands-on review of application source code to validate security findings and determine whether identified vulnerabilities represent legitimate risk.
- Triage findings before engaging development teams, with a focus on identifying false positives and minimizing non-actionable issues.
- Evaluate vulnerabilities beyond vendor-assigned severity scores by considering exploitability, exposure, attack paths, business impact, compensating controls, and application context.
- Validate vulnerability classifications, severity recommendations, and remediation priority.
- Utilize AI tools and effective prompting techniques to analyze security findings, increase confidence in finding credibility, and reduce false positives.
- Assess vulnerability trends and recurring development patterns that may require broader corrective action.
- Explain validated application security findings clearly to developers, architects, technology owners, and business stakeholders.
- Provide actionable remediation guidance and secure coding recommendations.
- Partner with developers and technology owners to drive validated vulnerabilities through remediation and closure within defined SLAs.
- Track remediation progress and escalate aging findings or remediation blockers as appropriate.
- Validate completed remediation activities and make closure recommendations.
- Support vulnerability triage and vulnerability management activities across multiple application security tools.
- Participate in vulnerability review sessions and remediation discussions.
- Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.
- Contribute to application security procedures, reporting, and process improvements.
Required Skills:
- 3+ years of experience in Application Security, Application Vulnerability Management, or a closely related cybersecurity discipline.
- Hands-on experience reviewing and validating application security findings generated by SAST and SCA tools .
- Strong application security vulnerability analysis and triage experience, including the ability to distinguish legitimate vulnerabilities from false positives.
- Hands-on technical ability to review source code and validate security findings at the code/application level before escalating issues to development teams.
- Ability to evaluate vulnerabilities based on actual exploitability, exposure, attack paths, application context, compensating controls, and business risk rather than relying solely on CVSS scores.
- Strong understanding of application security concepts and practices, including:
- OWASP Top 10
- Common Weakness Enumeration (CWE)
- Secure Software Development Lifecycle (SSDLC)
- Exploit Prediction Scoring System (EPSS)
- CVE/CVSS concepts
- Ability to analyze application security findings involving one or more modern enterprise development languages, including Java, TypeScript, JavaScript, C#, Python, Go, Node.js, or similar languages.
- Hands-on experience using AI tools to support application security or vulnerability analysis , including the ability to create effective prompts to validate findings, improve analysis, and reduce false positives.
- Strong written and verbal communication skills with the ability to clearly communicate technical security findings.
- Strong organizational skills with the ability to manage multiple vulnerability analysis and remediation efforts simultaneously.
- Demonstrated ability to work independently and drive issues toward resolution.
Preferred Skills:
- Experience working directly with development teams to explain vulnerabilities, provide remediation guidance, and drive findings through closure.
- Experience with AppScan, Snyk, ZAP , or comparable application security tools.
- Experience with Claude Code or similar AI-assisted security/development tools.
- Secure code review experience.
- Application security testing experience.
- CI/CD security integration experience.
- Experience with SCA tools and software dependency risk analysis.
- Understanding of software architecture and common web application attack patterns.
- Working knowledge of cloud-native applications and APIs.
- Familiarity with enterprise vulnerability management processes, remediation SLAs, and tracking workflows.
- Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, or similar.
Education:
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field preferred, or equivalent relevant professional experience.
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Application Security Vulnerability Analyst in New York, NY vacancy
$75k - $85k
...IT Security Analyst Who is Gen II? Gen II is a leading fund administration provider focused... ...and reporting of systems and applications. What you’ll be doing Actively... ...who fail phishing tests. Review Vulnerability Management Tool findings and work...ApplicationFull timeWork at officeFlexible hours1 day per week- ...Academy is growing rapidly and security is at the forefront of... ...are seeking a Senior Security Analyst to join our Information Security... ...around cloud and SaaS based applications, operates networking and in-... ...across incident response, vulnerability management, identity and...ApplicationWork at officeImmediate startVisa sponsorship3 days per week
$97.59k - $142.99k
...have an exciting opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the successful analyst will be part of... ...remediation efforts with infrastructure teams and application ownersAnalyze threat intelligence reports, write risk analysis...ApplicationFull time$117.2k - $176.7k
...are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers... ...AccommodationsIf you need a reasonable accommodation during the application or the recruiting process, please submit a request via...ApplicationFull time- ...Network Security Analyst Job Description: Position requires fully on-site reporting... ...all corporate and enclave firewalls, application delivery controllers, RADIUS, RSA.... ...NAT for external interfaces. Vulnerability review of hardware. Preferred Skills...ApplicationWork experience placementLocal areaRotating shift
$145k - $170k
CLEAR is building THE secure identity company of the future. Our mission is to make experiences... ...is seeking a Senior Security Operations Analyst III to join our SOC team to help... ...commission, Restricted Stock Units. Qualified applicants will receive consideration for...ApplicationCasual workWork at officeFlexible hours$191k - $305k
...this role:Wells Fargo is seeking a Senior Lead Information Security Analyst in Cybersecurity to join the IAM Strategic Enablement & Adoption... ....In this role, you will:Partner with Lines of Business, application teams, and IAM product owners to drive adoption and effective...ApplicationFull timeWork experience placementRelocation package- ...Position Title * Information Security Analyst Position Responsibilities Information Security Analyst New York, NY (Hybrid role),... ...Responsibilities: Participate in developing and implementing application security governance processes. Participate in the design...ApplicationContract work
$103k - $164k
...a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships... ...-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation,...ApplicationFull timePart timeLocal areaWorldwideFlexible hours- Network Security Analyst Austin, Texas, United States Requirement Details: Internal job ID:... ...intelligence, software security, and vulnerability assessment services. This position also... ...vulnerability scans of networks and applications to assess effectiveness and identify...ApplicationLocal areaRemote work
$85k - $105k
The Oracle Security Analyst position provides technical, functional support and security for Oracle Fusion Cloud and related applications. This is a remote-work position and will be based in the US. This position will provide technical and functional support and security...ApplicationRemote workWork from homeHome office$99.2k - $148.8k
DescriptionThe Applications Analyst III supervises and provides technical guidance to the staff in the development of specifications for new... ...preferred.Five years of solid, diverse work experience in ITEpic Security Certification and experience required.Employer...ApplicationTraineeshipWork experience placementLocal areaRemote work$76k - $105k
...Zero Harm policy What you will do: Investigate and respond to security alerts and incidents, performing root cause analysis and driving... ..., experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.) All hiring...ApplicationInternshipRemote work- Security Administration and Operations Candidate must be authorized... ..., and other agent-based applications running on Databases, Windows... ...understanding of malware, threats, vulnerabilities, and the complete affect... ...Additional Skills: Business Analyst. This is a high PRIORITY...ApplicationRemote jobWeekend workAfternoon shift
- ...enhance the software delivery lifecycle, the full-time remote Application Security Analyst will integrate security controls into CI/CD pipelines,... ...with security testing methodologies and tools, including SAST, DAST, and vulnerability management Virtual Vocations IncApplicationFull timeRemote work
- Application Security Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security... ...like a seasoned security professional: identifying vulnerabilities, weighing exploitability, and recommending sound...ApplicationHourly payOngoing contractContract workFreelanceRemote workFlexible hours
$75k - $95k
About the role: We are seeking an Application Security Analyst to build security into how we ship software, and to help our small but growing... ...interactive testing tools Identify, triage, and prioritize vulnerabilities Integrate security testing into CI/CD pipelines (...ApplicationWork at officeRemote workFlexible hours- Job Title: Information Security Analyst Job Summary: We are seeking a highly motivated Information... ...'s information systems, networks, applications, and data assets from cyber threats.... ...security events, identifying vulnerabilities, conducting risk assessments, responding...ApplicationFull timeRemote work
$75k - $110k
...policy Ten company-paid holidays per year About the Role The Application Security Analyst helps embed security into the software delivery... ...principles, secure coding practices, cloud security controls, vulnerability management, and modern DevSecOps methodologies. The...ApplicationLocal areaImmediate startRemote workFlexible hours- Information Security Analyst 2 Start Date: 09/01/2020 End Date: 03/01/2021 Work Location: Bismark North Dakota 58503 Client: State of North Dakota Pay Rate: $35/hr on w2 all inclusive CYAD Web Application Security Scanning NDIT has 1 contract position open for a Web Application...ApplicationContract workRemote workWork from home
$87k - $92k
Information Security Analyst Posting Details Job # 042836 Department Code 20703-6034 Department... ...intersection of threat detection, vulnerability management, and forensic... ...across all operational functions and the application of AI as a solution is a core expectation...ApplicationFull timeSummer workRemote work$169.95k - $179.3k
Senior Information Security Analyst McKesson is an impact-driven, Fortune 10 company that touches... ...in the job offered or related field. Applicant must have five (5) years demonstrated... ..., Linux, and Unix environments. Vulnerability management, penetration testing, and secure...ApplicationRemote work- Information Security Analyst At Gifthealth, we're revolutionizing the way people experience healthcare... ...monitoring, incident response, vulnerability management, endpoint security, email... ...providers and other security vendors when applicable. Security Operations and Reporting:...ApplicationFull time
$96.57k - $130.65k
...Qualifications: Skills: Cyber Risks, Security Compliance, Vulnerability Assessments, Vulnerability... ...career. The Security & Compliance Analyst will work as part of the CMM Data Modernization... ...analyses of computer systems and applications during all phases of the system...ApplicationTemporary workWork at officeImmediate startRemote workWorldwideFlexible hours$137.8k - $180.8k
The Opportunity As a Mastery Level Security Operations Center (SOC) analyst you'll have an opportunity to be part of a growing team of highly... ...mining large datasets Understanding of web application vulnerabilities including XSS, CSRF, SQL Injection, command injection...ApplicationTemporary workRemote work- ...growing healthcare technology company is looking for an IT & Security Analyst to join its Security team. This is a hands-on role with real... ...management administration, including SSO/MFA configuration, application access assignments, and periodic access reviews. Support...Application
- Third Party Information Security Analyst This role is located in New York City and will require a hybrid work schedule of at least 2 days... ...are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to...ApplicationWork at officeWork from homeFlexible hours2 days per week
$110.5k - $149.5k
Information Security Analyst Principal This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Information Security Analyst Principal based in the United States. This is a senior cybersecurity role...ApplicationFull timeTemporary workRemote workMonday to FridayFlexible hours- Application Security Risk & Automation Analyst We are seeking an experienced Application Security Risk & Automation Analyst to support the automation and... ...workflows, reducing developer friction, improving vulnerability remediation, and automating security findings management...Application
- Guardian is seeking an experienced professional to lead vulnerability analysis and risk assessment within its application security program. You will review findings from SAST/SCA tools, evaluate risk beyond CVSS, and provide actionable remediation guidance to developers...Application
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Vulnerability Analyst. Be the first to apply!
Related searches
- clinical applications analyst New York, NY
- application security analyst New York, NY
- epic application analyst New York, NY
- application support analyst New York, NY
- sql database developer analyst New York, NY
- engineering business analyst New York, NY
- software analyst New York, NY
- software configuration analyst New York, NY
- software development analyst New York, NY
- application analyst New York, NY


