Senior Application Security Analyst
$98.84k - $148.26kState of Washington Health Benefits Exchange
The mission of Washington Health Benefit Exchange (Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical solutions, an easy‑to‑use customer experience, our values of integrity, respect, equity and transparency, and by providing undeniable value to the health care community. The Exchange is a public‑private partnership that operates Washington Healthplanfinder, the eligibility and enrollment portal used by one in four Washington residents to obtain health and dental coverage. Through this platform, and with support from a Customer Support Center and statewide network of in‑person navigators and brokers, individuals and families can shop, compare and enroll in private, qualified health plans (as defined in the Affordable Care Act) or enroll in Washington Apple Health, the state Medicaid program. Equity is fundamental to the mission of the Washington Health Benefit Exchange. The process of advancing toward equity and becoming anti‑racist is disruptive and demands vigilance to dismantle deeply entrenched systems of privilege and oppression. While systemic racism is a root cause of many societal inequities, we must also use an intersectional approach to address all forms of bias and oppression, which interact and often exacerbate racial inequities. To be successful, we must recognize the socioeconomic drivers of health and focus on people and places where needs are greatest. As we listen to community, we must hold ourselves accountable to responding to recommendations to remedy inequitable policies, systems, or practices within the Exchange’s area of influence. Our goal is that all Washingtonians have full and equal access to opportunities, power and resources to achieve their full potential. SUMMARY The Senior Application Security Analyst plays a key role in protecting WAHBE’s data and applications by ensuring security controls are effectively integrated throughout the Software Development Lifecycle (SDLC) across both cloud and on‑premises environments. Operating under the guidance of the Application Security Lead, this role serves as a senior technical contributor and collaborates closely with delivery teams, DevOps, architects, IT, and external partners to implement and sustain secure software development practices. This position is responsible for executing application security assessments, threat modeling, and vulnerability management, while supporting risk assessments and ensuring alignment with WAHBE’s security policies and regulatory requirements. The Senior Application Security Analyst helps drive the adoption and continuous improvement of the Secure Software Development Lifecycle (SSDLC) by integrating automated security controls, conducting code reviews, and promoting secure coding standards. Key responsibilities include identifying and mitigating application security risks, supporting incident response activities, and providing actionable guidance to delivery teams for remediation. The role also contributes to strengthening overall application security posture by addressing emerging threats, supporting compliance efforts, and ensuring security best practices are consistently applied across the organization. Serve as a senior subject matter expert for application security across Microsoft Azure and cloud‑native architectures including hybrid and multi‑cloud environments Perform and coordinate application security assessments, code reviews to align with WAHBE security policies, industry standards (NIST, OWASP), and regulatory compliance (e.g., Centers for Medicare & Medicaid Services (CMS), Internal Revenue Service (IRS)), including API and microservices security assessments Support the implementation and continuous improvement of the Secure Software Development Lifecycle by integrating security controls and best practices into development and deployment processes Collaborate with the Delivery team, architects, DevOps engineers to embed security into all phases of the SDLC, including participation in threat modeling, security requirement reviews, and architecture discussions Review application and solution architectures to identify security weaknesses, attack surfaces, and insecure design patterns, and provide remediation recommendations Perform security design reviews for web applications, APIs, microservices, containers, and serverless technologies to ensure secure implementation practices are followed Develop, document, and enforce secure coding standards, secure design guidelines, and application security procedures to ensure consistent and secure development practices Enhance and lead the Application Security and Penetration Testing program, including performing security and penetration testing and integrating automated security testing into CI/CD pipelines to ensure continuous and effective validation of application security Conduct vulnerability triage, validation, and risk analysis using security tools, threat intelligence, and manual analysis, including false‑positive review and remediation prioritization Track remediation activities for identified application vulnerabilities and work with development teams to ensure timely resolution or appropriate risk acceptance documentation Provide technical guidance for remediation planning and recommend compensating controls when immediate remediation is not feasible Support monitoring and reporting activities by preparing vulnerability metrics, remediation status updates, trend analysis, and risk reports for leadership and stakeholders Develop and deliver secure coding awareness sessions, technical guidance, and application security training materials for development and engineering teams Review Requests for Change (RFCs), product enhancements, and system modifications from a security perspective to ensure security impacts and requirements are addressed Continuously monitor the cloud and on‑premise environment for security events, anomalies, and potential threats, and conduct thorough investigations to identify root causes and impacts, containment and recovery from security breaches, and preparation of incident reports, including post‑incident analysis and lessons‑learned Partner with Compliance, Risk Management, Audit, Infrastructure Security, and DevOps teams to support audits, regulatory compliance efforts, and secure cloud adoption initiatives Ensure procedures, processes and technologies align with WAHBE security policies and regulatory compliance (e.g., CMS, IRS) Work closely with delivery teams to ensure security requirements are factored into user stories and case development (including misuse, abuse, and confuse cases within Agile methodology) Assess the security posture of new enterprise solutions to be procured by identifying security risk and providing secure cloud adoption guidance Provide technical security consultation and assessments for cloud environments and containers, with an emphasis on following best practices and conducting comprehensive technical analysis Collaborate with WAHBE DevOps Team to integrate application security into CI/CD pipeline as part of SSDLC and enforce security in deployment workflows Assist in maintaining and updating WAHBE Security policies, procedures, and standards ensuring ongoing SSDLC adoption Collaborate with internal stakeholders, vendors, and external partners to ensure security integration and ongoing compliance, maintaining synchronization with the Security objectives Assist Application Security Lead in reviewing existing security capabilities and assist in defining roadmap and strategy for security enhancements Provide regular briefings to Application Security Lead and Information Security Manager (ISM), escalating issues and blockers as necessary Provide technical guidance on secure development and vulnerability management activities Stay current on industry trends, emerging threats, and relevant technologies, and communicate key insights to the Application Security Lead Perform other duties as assigned within the scope of application security Required Seven (7) years of information security experience in specialized roles such as, but not limited to security architecture and design, security control implementation, penetration testing, application security, vulnerability management, incident response Demonstrated knowledge of secure SDLC, secure architecture design, application security concepts, and cloud‑architecture including DevSecOps practices and shift‑left security integration Experience performing application security code reviews, roles and permissions matrix reviews, and practical application risk assessments, including manual and automated secure code reviews Experience working with common vulnerability assessment tools such as Nessus, Rapid7, Nmap, and Burp Suite, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools Advanced understanding of emerging cybersecurity threats, including application‑layer attacks, API abuse, and software supply chain vulnerabilities Strong analytical and problem‑solving skills with the ability to think outside the box Experience integrating security in infrastructure‑as‑code, CI/CD pipelines, and the software development lifecycle, including implementation of automated controls and continuous monitoring and security gates and pipeline enforcement policies Demonstrates strong interpersonal and collaboration skills, effectively partnering with internal management, staff, and cross‑functional teams as well as external partners and vendors Desired Bachelor’s degree in engineering, security or a technology related or closely allied field Experience working with application security methodologies such as OWASP Experience in information security, data security, privacy, and data management, including secure handling of Personally Identifiable Information (PII), application‑level encryption, and key management Experience defining secure architectural requirements, security controls, and configuration standards in compliance with regulatory requirements Experience working with threat modeling frameworks such as STRIDE and MITRE ATT&CK, including application‑specific threat modeling, attack path analysis, and abuse case analysis Experience developing, reviewing, and updating security standards, procedures, awareness and training, including secure coding standards and developer training programs Demonstrates a solid understanding of the functions and operations of Security Information and Event Management (SIEM) systems, Endpoint Detection & Response Experience managing cyber incident response, including coordination with development teams for rapid patching and hotfix deployment Advanced understanding of emerging cybersecurity threats, including application‑layer attacks, API abuse, and software supply chain vulnerabilities SALARY INFORMATION Full Salary Range: $98,842.00 to $148,263.00 annually, with midpoint at $123,552.00. Hiring Range: $113,668.00 and $123,552.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer. The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum. BENEFITS Benefits: Take a peek at our benefits package. WORKING CONDITIONS Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in‑person collaboration. While a hybrid remote and on‑site schedule may be considered, the position will require flexibility to allow for in‑office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location. The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Special Requirements A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The result of this background screen must meet the Exchanges eligibility standards. EEO Statement The Washington Health Benefit Exchange is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, marital status, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. We participate in E-Verify. You can view the Department of Justice's Right to Work poster. #J-18808-Ljbffr
$98.84k - $148.26k
...Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical... ...resources to achieve their full potential. SUMMARY The Senior Application Security Analyst plays a key role in protecting WAHBE’s data and applications...SeniorContract workWork at officeImmediate startRemote workMonday to FridayShift work$30 per hour
...industry's broadest and deepest suite of AI-powered cloud applications. The following facts and figures highlight some of the... ...Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management...SuggestedHourly payTemporary workInternshipFlexible hours$50 - $60 per hour
DataAnnotation is committed to creating high-quality AI. Enjoy the flexibility of remote work and the freedom to set your own schedule. This is an opportunity to work with us as an independent contractor. We're currently expanding into an exciting new area – teaching...SeniorHourly payContract workFor contractorsWork experience placementRemote work$110.7k - $178.2k
A leading technology company in Olympia is looking for a professional to optimize their Quote to Cash workstream. The role involves analyzing existing processes and collaborating with technical teams to implement improvements. Candidates should have deep expertise in Quote...SeniorRemote work- ...shouldn't your opportunities be, too? The Opportunity The Senior Actuarial Analyst is responsible for developing and supporting a robust... ...to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard...SeniorPermanent employmentWork experience placementWork at officeRemote workFlexible hours
$145k - $205k
...and innovate in healthcare. You will conduct penetration tests, oversee red and purple team engagements, and collaborate to evolve security measures. The ideal candidate has a Bachelor's degree in Computer Science or related field along with at least 8 years of...Senior$130.9k - $154k
...range (excluding equity and bonus): $130,900—$154,000 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles...SeniorLocal area$102.5k - $187.9k
A global consulting firm is seeking a ServiceNow Senior Consultant to lead transformation teams in IT and Operational Technology Asset Management. This role involves collaborating with clients to gather requirements, designing user interfaces, and leading a multidisciplinary...Senior$80.2k - $111.3k
...Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts... ...governance, and influences broader security architecture and operations based on emerging... ...coaching to incident handlers and SOC analysts, elevating investigative techniques, documentation...SeniorContract workWork experience placementWork at office- ...Senior Systems Analyst Benefits include Medical/Vision/Dental Insurance; FSA/DCAP; Life/AD&D Insurance; LTD Insurance; EAP; Retirement; DCP... ...Assessment Assesses malfunctions of network hardware and software applications (e.g. firewalls, routers, DNS, antivirus, workstations,...SeniorWork at office
$98k - $125k
...The Sr Program Financial Analyst demonstrates deep expertise in... ...interface with the Program Manager, senior technical staff on the... ...for work under DOD contract Application deadline: June 8, 2026 #LI-... .... From priority national security initiatives for the DoD to highly...SeniorContract workWork experience placementFor subcontractorH1bWork at officeRemote work$120k - $150k
...mission to make the world's health data secure, accessible and actionable, we provide... ...a highly skilled and experienced Senior Systems Analyst - Oracle HCM to join our HRIT team. This... ...employer and all qualified applicants will receive consideration for employment...Senior$85 per hour
...Senior Systems Analyst - Hexagon SmartPlant Materials Req number: R7895 Employment type: Full time Worksite flexibility:... ...of custom software development experience across the full application lifecycle ~ Experience with PL/SQL and JavaScript ~ Strong...SeniorHourly payFull timeContract workApprenticeshipWork experience placementWork at officeLocal areaRemote workWorldwide$70.6k - $141.2k
...(OCI) is growing rapidly, and we are looking for a financial analyst to support our Supply Chain organization. This role focuses... ...or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates...SeniorTemporary workFlexible hours$70.6k - $141.2k
...clouds, OCI supports diverse workloads and serves as the foundational layer for Oracle's Autonomous Database, as well as platform and application services. Position Summary: In OCI Finance, the Spotlights Team plays a critical role in driving financial excellence...SeniorTemporary workFlexible hours$70.6k - $141.2k
...Job Description Sr. Financial Analyst, IaaS Workload Health Job location: US Nationwide, Remote Oracle Cloud Infrastructure... ...customer or client-facing roles may be required to comply with applicable requirements, such as immunization/occupational health...SeniorTemporary workRemote workFlexible hours- ...Repayment Program (up to $50,000, for existing loans) ~ Health care benefits available ~ VA home loans ~ Bonuses, if applicable ~ Most non-prior service candidates will earn between $200 and $250 per drill weekend, subject to change Requirements...Part timeWeekend work
$145.3k - $181.6k
...on LinkedIn. The Business Applications team is part of IT and is responsible... ...s business processes. The Senior Manager, Enterprise Apps,... ...and mentorship to HRIS analysts or other team members. Data... ...Writer. ~ Deep understanding of security roles, data governance, and...SeniorWorldwideFlexible hours- ...The State of Washington is looking for a Senior IT Business Analyst Specialist to oversee and guide the development of critical IT projects. This role requires collaboration with various teams to ensure technology solutions meet business needs and an expertise in user...SeniorWork at officeRemote work
$86.5k - $142.7k
...Architect who designs, prototypes and builds modern, AI‑enabled applications and digital products. You will spend the majority of your time... ...to accelerate development while enforcing clean architecture, security and maintainability. Review AI‑generated code, tests and...SeniorSummer holidayFlexible hours$86.5k - $142.7k
...Architect who designs, prototypes and builds modern, AI‑enabled applications and digital products. You will spend the majority of your time... ...to accelerate development while enforcing clean architecture, security and maintainability. • Review AI‑generated code, tests and...SeniorSummer holidayFlexible hours$50 - $60 per hour
DataAnnotation is committed to creating high-quality AI. Join our team to help train the next generation of AI while enjoying the flexibility of remote work and the freedom to set your own schedule. This role is designed to fit a variety of lifestyles — whether you’re ...Hourly payContract workWork experience placementRemote workFlexible hours$118.3k - $306.4k
...Job Description Manage a team that designs, develops, troubleshoots and debugs software programs for databases, applications, tools, networks etc. Responsibilities As a manager of the software engineering division, you will apply your knowledge of software architecture...SeniorTemporary workFlexible hours- ...amount of time and utilizes established investigative techniques to secure covert video footage Conduct investigations such as securing... ...license Possess a current private investigator license (if applicable) Must be dependable and able to meet deadlines Must be a...Flexible hours
$118.3k - $306.4k
...of a startup while delivering the scale, security, and reliability expected from one of... ...Mentor and develop engineering managers and senior engineers through coaching, performance... ...roles may be required to comply with applicable requirements, such as immunization/occupational...SeniorTemporary workRelocation packageFlexible hours$140k
...Maximus is currently seeking a Senior IT Project Manager to lead and track the development... ...projects, development groups, and/or application support functions. Oversee the development... ...to identify high risk and software security postures for improvements, remediation,...SeniorTemporary workFor subcontractorRemote work- ...Officer (IO) reporting to the Assistant Senior Investment Officer (ASIO). This is an opportunity... ...broader WSIB objectives. COMPETITIVE APPLICANTS WILL HAVE: Bachelor’s degree in finance,... ...Master’s degree or Chartered Financial Analyst (CFA) designation may substitute for up...Work at office
- ...IT Application Development – Senior Manager (ITAD-SM/ETS) This IT Application Development – Senior Manager is a career-defining opportunity for... ...wide IT service management (ITSM) capabilities are stable, secure, scalable, and aligned with ETS and HCA business...SeniorRemote workShift work1 day per week
- Ernst & Young Oman is seeking a dedicated professional to lead SAP DMC initiatives, focusing on delivering quality solutions and managing client relationships. In this role, you will handle program management and guide diverse teams while building strong client connections...SeniorFlexible hours
$71.2k - $158.2k
...Job Description The Senior Federal Information Systems Security Engineer (ISSE) serves as a technical integrator responsible for ensuring that system... ...client-facing roles may be required to comply with applicable requirements, such as immunization/occupational health...SeniorContract workTemporary workWork experience placementRelocationFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Analyst. Be the first to apply!
- senior brand designer Olympia, WA
- senior business analyst contract Olympia, WA
- senior database analyst Olympia, WA
- legal senior counsel family office Olympia, WA
- senior aws cloud engineer Olympia, WA
- senior financial analyst remote Olympia, WA
- senior cloud engineer Olympia, WA
- senior manager financial planning & analysis Olympia, WA
- senior vmware engineer Olympia, WA
- senior consulting engineer Olympia, WA



