Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Analyst

$75k - $110k

Sound - Our People Make The Difference

Application Security Analyst

Founded in 2001 and headquartered in Nashville, TN, Sound Physicians is a nationally respected, physician-led medical group practicing in 400+ hospitals across 45 states. Our team of 4,000+ clinicians and 1,000+ business professionals across the country is united by one mission: to build exceptional clinical partnerships that unlock quality, affordable, dignified care for everyone – no matter who they are or where they live. With physician-led clinical teams and more than two decades of operational expertise, we've refined what it takes to consistently deliver exceptional care in hospital medicine, emergency medicine, critical care, anesthesia, and telemedicine.

Why join us?

  • A remote-first culture that values flexibility and collaboration
  • Opportunities to grow your career while making a real impact
  • A team that champions inclusivity, innovation, and excellence

Whether working virtually or onsite at one of our practices, you'll be part of a purpose-driven organization shaping the future of healthcare.

Sound Physicians offers a competitive benefits package inclusive of the items below, and more:

  • Medical insurance, dental insurance, and vision insurance
  • Health care and dependent care flexible spending account
  • 401(k) retirement savings plan with a company match
  • Paid time off (PTO) begins accruing immediately upon start date at a rate of 15 days per year, in accordance with Sound's PTO policy
  • Ten company-paid holidays per year

About the Role

The Application Security Analyst helps embed security into the software delivery lifecycle by partnering with development, platform, cloud, and security teams to build secure-by-default processes. This role focuses on reducing risk through automation, continuous testing, secure configuration, and practical guidance that enables teams to ship software quickly and safely. The ideal candidate possesses a strong understanding of application security principles, secure coding practices, cloud security controls, vulnerability management, and modern DevSecOps methodologies.

Essential Duties and Responsibilities

  • Integrate security controls and automated checks into CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secret scanning, container security scanning, and Infrastructure-as-Code (IaC) validation.
  • Partner with developers and platform engineers to identify, prioritize, and remediate application, API, container, and cloud security risks early in the development lifecycle.
  • Perform application security assessments, architecture reviews, and threat modeling exercises for new and existing applications.
  • Support vulnerability management by validating findings, reducing false positives, tracking remediation, and helping define risk-based service-level expectations.
  • Conduct secure code reviews and provide guidance on secure coding practices aligned with OWASP Top 10, CWE, and industry standards.
  • Perform security reviews for application architecture, deployment patterns, third-party components, and cloud configurations.
  • Develop and maintain secure pipeline standards, reusable guardrails, and policy-as-code checks that improve consistency without creating unnecessary delivery friction.
  • Collaborate with engineering, infrastructure, and security operations teams on incident response, root cause analysis, and hardening activities related to software delivery platforms.
  • Create and maintain documentation, standards, playbooks, and training materials related to application security, secure development, and DevSecOps practices.
  • Track vulnerability trends, security metrics, and recurring issues to improve security maturity across build, release, and runtime workflows.
  • Stay current on emerging threats, attack techniques, vulnerabilities, and security technologies relevant to application and cloud security.

The Details: A successful candidate will have a demonstrated track record of a combination of these values, knowledge, experience, and competencies:

Values

  • Collaborative: Demonstrates the ability to work well with others to accomplish a goal and get the work done; takes opinions of others into consideration; includes others in the decision-making process.
  • Eager to Learn: Proactively seeks out information, embraces learning new things and enjoys the learning process.
  • Intellectually curious: Demonstrates a genuine interest in learning new things and wants to know the reason "why" behind the way things are done.
  • Committed: Demonstrates dedication to the job, project, organization, customer/clients and co-workers.
  • Resourceful: Proactive willingness to utilize available information and tools to figure things out.

Knowledge, Skills, and Abilities

  • Strong understanding of application security concepts, secure coding practices, and common attack vectors.
  • Knowledge of security testing methodologies including SAST, DAST, SCA, penetration testing, secret scanning, and IaC security assessments.
  • Familiarity with cloud platforms such as Azure and AWS.
  • Familiarity with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab CI, or Jenkins.
  • Knowledge of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and NIST Cybersecurity Framework.
  • Experience with application security platforms such as Veracode, Checkmarx, Fortify, SonarQube, Snyk, Mend, Burp Suite, Rapid7 InsightAppSec, or similar tools.
  • Familiarity with scripting and automation using Python, Powershell, Bash, or similar languages.
  • Experience securing containerized applications and platforms (Docker, Kubernetes, OpenShift, AKS, EKS, or GKE), including container image scanning, runtime security monitoring, admission controls, and Kubernetes security best practices.
  • Knowledge of container technologies, source control workflows, and modern software delivery practices.
  • Familiarity with common static and dynamic application security tools.
  • Ability to analyze security findings, assess risk, and communicate remediation recommendations effectively to technical and non-technical stakeholders.
  • Familiarity with AI-assisted development processes and appropriate security controls.
  • Strong written and verbal communication skills.
  • Ability to translate technical issues into clear guidance and action plans
  • Knowledge of cloud-native security controls.
  • Familiarity with Kubernetes, Terraform, and similar Infrastructure-as-Code tools.
  • Familiarity with secrets management, PKI, certificate management, and cryptographic controls.
  • Knowledge of compliance frameworks such as NIST CSF, NIST 800-53, HIPAA, PCI DSS, SOC 2, ISO 27001, and HITRUST.

Education and Experience

  • Bachelor's degree in Computer Science, Information Security, or related field, with industry-recognized certifications such as CSSLP (Certified Secure Software Lifecycle Professional), GWAPT (GIAC Web Application Penetration Tester), OSWE (Offensive Security Web Expert), CEH (Certified Ethical Hacker)
  • 4+ years of experience in application security, DevOps, cloud security, security engineering, or a related cybersecurity role.
  • Knowledge of scripting and programming languages such as Python, PowerShell, Java, JavaScript, C#, or Go is highly desirable and considered a plus.
  • Experience supporting regulated environments such as healthcare, financial services, or other compliance-driven industries.

Salary Range

  • This position offers an annual salary range of $75,000 to $110,000. Exact salary will depend on the candidate's experience, education, and geographic location.

Sound Physicians is an Equal Employment Opportunity (EEO) employer and is committed to diversity, equity, and inclusion at the bedside and in our workforce. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, gender identity, sexual orientation, age, marital status, veteran status, disability status, or any other characteristic protected by federal, state, or local laws.

This job description reflects the present requirements of the position. As duties and responsibilities change and develop, the job description will be reviewed and subject to amendment.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Application Security Analyst in United States vacancy
  • $52 - $58 per hour

     ...remediation plans for vulnerabilities from network based and application-based assessments. Remediation plan must be made actionable for...  ...Required Skills and Qualifications We are seeking an application security engineer in a 100% remote role. Experienced candidates will... 
    Suggested
    Contract work
    Temporary work
    Remote work

    TEKsystems

    Tampa, FL
    1 day ago
  •  ...personality? Are you never satisfied with good enough? Does solving complex problems and ensuring top-quality security excite you? If so, being an Application Security Analyst II with Frost could be for you.At Frost, it’s about more than a job. It’s about having a flourishing... 
    Suggested
    Full time

    Frost Bank

    San Antonio, TX
    13 hours ago
  •  ...Overview Title: Application Security Analyst Duration: 12 Months Location: Plano, TX Pay Rate: $65/hr on W2 (H4, USC, GC, TN) Hybrid: 3 day onsite, 2 day remote Interview process: 1st round virtual & 2nd round onsite Job Description: We are seeking a skilled and proactive... 
    Suggested
    Remote work
    Shift work

    IVID TEK INC

    Plano, TX
    4 days ago
  •  ...Join to apply for the Application Security Analyst role at Charles Schwab . At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry... 
    Suggested
    Full time
    Internship
    Work at office
    Shift work

    Charles Schwab

    Omaha, NE
    4 days ago
  • $67.98k - $108.77k

     ...Application Security AnalystJoin a Great Place to Work certified company - our Information Security Team is seeking an Application Security Analyst!Are you passionate about securing applications and helping development teams build software that is resilient against evolving... 
    Suggested
    Temporary work
    Work at office
    Local area
    3 days per week

    Consumers Credit Union

    Lake Forest, IL
    2 days ago
  •  ...environment. Toyota does not offer support or sponsorship of job applicants for employment-‑based visas or any other work authorization...  ...a highly motivated person to fill a role as a Application Security Analyst. Your responsibilities will be to ensure the security of... 
    H1b
    Relocation package
    Early shift

    JobCubby

    Plano, TX
    4 days ago
  •  ...Transmission Company, part of Marmon Holdings, seeks an Enterprise Applications Business Analyst to optimize enterprise apps, Microsoft 365, and Entra ID...  ...integrations with ERP/WMS, and contribute to governance, security, and process improvements across the enterprise. #J-18808... 

    Marmon Holdings, Inc.

    Bellows Falls, VT
    2 days ago
  •  ...This role focuses on identifying, analyzing, and mitigating application security vulnerabilities throughout the SDLC. It supports a broader “Shift Left” cybersecurity strategy, ensuring security is integrated early in development and reinforced through DevSecOps practices... 
    Shift work

    Stellantis

    Auburn, AL
    3 days ago
  • $88.27k - $102.64k

     ...Application Security Analyst Vernon, BC or Remote Kal Tire is seeking an Application Security Analyst to join our Cybersecurity team. In this role, you'll help protect our applications, systems, and data by identifying security risks, supporting secure software... 
    Permanent employment
    Full time
    Part time
    Remote work

    Kal Tire

    United States
    3 days ago
  • $63.3k - $84.4k

     ...rather than hands-on implementation, supporting secure architecture practices, overseeing the security posture of applications (including cloud and AI solutions), and...  ...career. SUMMARY: The Application Security Analyst is responsible for ensuring the security of homegrown... 
    Temporary work
    Work at office
    Remote work
    Work from home
    Shift work

    DHL

    United States
    4 days ago
  • $99.2k - $148.8k

    DescriptionThe Applications Analyst III supervises and provides technical guidance to the staff in the development of specifications for new...  ...preferred.Five years of solid, diverse work experience in ITEpic Security Certification and experience required.Employer... 
    Traineeship
    Work experience placement
    Local area
    Remote work

    Mount Sinai Health System

    New York, NY
    2 days ago
  • $98.84k - $148.26k

     ...Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical...  ...resources to achieve their full potential.\n SUMMARY\n The Senior Application Security Analyst plays a key role in protecting WAHBE’s data and applications... 
    Contract work
    Work at office
    Immediate start
    Remote work
    Monday to Friday
    Shift work

    Washington Health Benefit Exchange

    Washington DC
    8 days ago
  •  ...Job Description Job Description AWS Application Security Analyst * Job Title: AWS Application Security Analyst * Job Category: Software Development/ Engineering Job Type: Permanent Full Time Location: Various, , United States No.Openings: 1 Description... 
    Permanent employment
    Full time

    System One

    Knoxville, TN
    2 days ago
  • $67.98k - $108.77k

     ...N Field Drive Lake Forest, IL 60045, USA Join a Great Place to Work certified company - our Information Security Team is seeking an Application Security Analyst ! Are you passionate about securing applications and helping development teams build software that is resilient... 
    Temporary work
    Work at office
    Local area
    3 days per week

    Myconsumers

    Lake Forest, IL
    2 days ago
  • Join to apply for the Application Security Analyst role at Paycom Join to apply for the Application Security Analyst role at Paycom Description The Application Security Analyst I position exists to protect the security posture of the Paycom application through tasks such... 
    Full time

    Paycom

    Oklahoma City, OK
    2 days ago
  •  ...Backed by a publicly traded parent company and undergoing a digital modernization effort. A highly skilled Information Security team focused on application security, DevSecOps, threat detection, and vulnerability remediation. A tech-forward organization prioritizing... 
    Full time

    AccruePartners

    Fort Mill, York County, SC
    2 days ago
  • $67.98k - $108.77k

    Myconsumers in Lake Forest, IL, is seeking an Application Security Analyst to join its Information Security Team. This hybrid role requires the candidate to work three days a week at the Lake Forest office. The analyst will be responsible for performing application security... 
    Work at office
    3 days per week

    Myconsumers

    Lake Forest, IL
    2 days ago
  • Capgemini Government Solutions (CGS) LLC seeks an Application Discovery Analyst to support enterprise modernization, application rationalization...  ...communication skills, and US citizenship with an active security clearance. #J-18808-Ljbffr Capgemini Government Solutions... 

    Capgemini Government Solutions LLC

    San Antonio, TX
    2 days ago
  • $125k

    Join us as an Application Security Analyst for Barclays, where you will support the delivery and continuous enhancement of Application Security and DevSecOps capabilities, bringing practical experience in one or more of the following areas: SAST, SCA, DAST, API security... 
    Hourly pay

    Barclays

    Whippany, NJ
    1 day ago
  • Remote Must-Have Skills / Prior Experience Hands-on experience with API security testing and vulnerability management. Strong knowledge of DAST tools (e.g., Burp Suite, OWASP ZAP). Experience with container security (Docker, Kubernetes, image scanning tools such as... 
    Remote work
    Worldwide

    Dexian

    Charlotte, NC
    4 days ago
  • Toyota Financial Services (TFS) Technology team seeks an Application Security Analyst to protect software applications, web services, and APIs. You will work with developers to identify vulnerabilities and embed security controls early in the SDLC. You will lead security... 
    Shift work

    JobCubby

    Plano, TX
    5 days ago
  • Consumers Credit Union is looking for an Application Security Analyst to join its Information Security Team in Lake Forest, IL. This role involves securing applications and helping development teams to identify vulnerabilities and implement best practices. You will work... 

    Consumers Credit Union

    Lake Forest, IL
    2 days ago
  • The Information Security Application and Compliance Analyst is responsible for designing, evaluating, and establishing AI security framework, standards, tool sets and governance controls to support secure AI application development and use. This role anchors the firm’s... 
    Work experience placement
    Work at office
    Work from home

    Vinson & Elkins

    Houston, TX
    2 days ago
  •  ...Job Description Be Part Of A High-Performing Team Join the information security organization of a major global financial institution with a strong focus on protecting enterprise applications, technology platforms, and sensitive financial data. This role sits within... 

    Axiom Path

    Charlotte, NC
    8 days ago
  • A leading IT consulting firm is seeking an IT Applications Security Engineer/Analyst for an 11-month contract in Atlanta, GA. This position focuses on identifying and mitigating security risks in client applications while ensuring secure software development practices.... 
    Contract work
    Local area
    Immediate start

    360 IT Professionals

    Atlanta, GA
    5 days ago
  • IT Applications Security Engineer/Analyst Contract 360 IT Professionals is a California base Minority Business Enterprise specializing in the field of IT Consulting and Staffing. Since our Inception we have been providing industry leading IT solutions for Staffing and... 
    Contract work
    Local area
    Immediate start

    360 IT Professionals

    Atlanta, GA
    5 days ago
  • $102.5k - $188.9k

     ...with confidence, and proactively manage to secure success.Cyber threats continue to evolve...  ...operations. As a Cyber Exploitation Analyst, you will support cyber defense efforts...  ...responsible for…Monitor networks, systems, and applications for indicators of compromise and analyze... 
    Work at office

    Deloitte

    Rosslyn, VA
    13 hours ago
  •  ...motivated candidate to join our talented Team. Job Title: Security Engineer/Cyber Security Analyst. Location: Chantilly, VA. Role SummaryWe are...  ...Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without... 

    Ampcus

    Chantilly, Loudoun County, VA
    2 days ago
  • $115k - $200k

     ...solo. Our Radio Products Team is seeking a hybrid Software Security Analyst. You would be a member of the Cyber Security Team working...  ...may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject... 
    Work experience placement
    Work at office
    Worldwide

    TrellisWare Technologies

    San Diego, CA
    7 days ago
  • $100k - $140k

    Job Reference: 6054 To Apply for this Job Click Here Our Client is looking for three Software Security Analysts based in Orange County, CA. This is an onsite position (hybrid is possible) for US Citizens and Green Card holders. If you need visa sponsorship now or in the... 
    Full time
    Relocation
    Visa sponsorship

    Tiro Security

    California, MO
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Analyst. Be the first to apply!