Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Analyst

$98.84k - $148.26k

Washington Health Benefit Exchange

Job Description

Job Description:\n\n The mission of Washington Health Benefit Exchange (Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical solutions, an easy-to-use customer experience, our values of integrity, respect, equity and transparency, and by providing undeniable value to the health care community. The Exchange is a public-private partnership that operates Washington Healthplanfinder, the eligibility and enrollment portal used by one in four Washington residents to obtain health and dental coverage. Through this platform, and with support from a Customer Support Center and statewide network of in-person navigators and brokers, individuals and families can shop, compare and enroll in private, qualified health plans (as defined in the Affordable Care Act) or enroll in Washington Apple Health, the state Medicaid program. The Exchange embraces the following equity statement adopted by our Board of Directors: Equity is fundamental to the mission of the Washington Health Benefit Exchange. The process of advancing toward equity and becoming anti-racist is disruptive and demands vigilance to dismantle deeply entrenched systems of privilege and oppression. While systemic racism is a root cause of many societal inequities, we must also use an intersectional approach to address all forms of bias and oppression, which interact with and often exacerbate racial inequities. To be successful, we must recognize the socioeconomic drivers of health and focus on people and places where needs are greatest. As we listen to community, we must hold ourselves accountable to responding to recommendations to remedy inequitable policies, systems, or practices within the Exchange s area of influence. Our goal is that all Washingtonians have full and equal access to opportunities, power and resources to achieve their full potential. SUMMARY The Senior Application Security Analyst plays a key role in protecting WAHBE’s data and applications by ensuring security controls are effectively integrated throughout the Software Development Lifecycle (SDLC) across both cloud and on-premises environments. Operating under the guidance of the Application Security Lead, this role serves as a senior technical contributor and collaborates closely with delivery teams, DevOps, architects, IT, and external partners to implement and sustain secure software development practices. This position is responsible for executing application security assessments, threat modeling, and vulnerability management, while supporting risk assessments and ensuring alignment with WAHBE’s security policies and regulatory requirements. The Senior Application Security Analyst helps drive the adoption and continuous improvement of the Secure Software Development Lifecycle (SSDLC) by integrating automated security controls, conducting code reviews, and promoting secure coding standards. Key responsibilities include identifying and mitigating application security risks, supporting incident response activities, and providing actionable guidance to delivery teams for remediation. The role also contributes to strengthening overall application security posture by addressing emerging threats, supporting compliance efforts, and ensuring security best practices are consistently applied across the organization. DUTIES AND RESPONSIBILITIES • Serve as a senior subject matter expert for application security across Microsoft Azure and cloud-native architectures including hybrid and multi-cloud environments • Perform and coordinate application security assessments, code reviews to align with WAHBE security policies, industry standards (NIST, OWASP), and regulatory compliance (e.g., Centers for Medicare & Medicaid Services (CMS), Internal Revenue Service (IRS)), including API and microservices security assessments • Support the implementation and continuous improvement of the Secure Software Development Lifecycle by integrating security controls and best practices into development and deployment processes • Collaborate with the Delivery team, architects, DevOps engineers to embed security into all phases of the SDLC, including participation in threat modeling, security requirement reviews, and architecture discussions • Review application and solution architectures to identify security weaknesses, attack surfaces, and insecure design patterns, and provide remediation recommendations • Perform security design reviews for web applications, APIs, microservices, containers, and serverless technologies to ensure secure implementation practices are followed • Develop, document, and enforce secure coding standards, secure design guidelines, and application security procedures to ensure consistent and secure development practices • Enhance and lead the Application Security and Penetration Testing program, including performing security and penetration testing and integrating automated security testing into CI/CD pipelines to ensure continuous and effective validation of application security • Conduct vulnerability triage, validation, and risk analysis using security tools, threat intelligence, and manual analysis, including false-positive review and remediation prioritization • Track remediation activities for identified application vulnerabilities and work with development teams to ensure timely resolution or appropriate risk acceptance documentation • Provide technical guidance for remediation planning and recommend compensating controls when immediate remediation is not feasible • Support monitoring and reporting activities by preparing vulnerability metrics, remediation status updates, trend analysis, and risk reports for leadership and stakeholders • Develop and deliver secure coding awareness sessions, technical guidance, and application security training materials for development and engineering teams • Review Requests for Change (RFCs), product enhancements, and system modifications from a security perspective to ensure security impacts and requirements are addressed • Continuously monitor the cloud and on-premise environment for security events, anomalies, and potential threats, and conduct thorough investigations to identify root causes and impacts, containment and recovery from security breaches, and preparation of incident reports, including post-incident analysis and lessons-learned • Partner with Compliance, Risk Management, Audit, Infrastructure Security, and DevOps teams to support audits, regulatory compliance efforts, and secure cloud adoption initiatives • Ensure procedures, processes and technologies align with WAHBE security policies and regulatory compliance (e.g., CMS, IRS) • Work closely with delivery teams to ensure security requirements are factored into user stories and case development (including misuse, abuse, and confuse cases within Agile methodology) • Assess the security posture of new enterprise solutions to be procured by identifying security risk and providing secure cloud adoption guidance • Provide technical security consultation and assessments for cloud environments and containers, with an emphasis on following best practices and conducting comprehensive technical analysis • Collaborate with WAHBE DevOps Team to integrate application security into CI/CD pipeline as part of SSDLC and enforce security in deployment workflows • Assist in maintaining and updating WAHBE Security policies, procedures, and standards ensuring ongoing SSDLC adoption • Collaborate with internal stakeholders, vendors, and external partners to ensure security integration and ongoing compliance, maintaining synchronization with the Security objectives • Assist Application Security Lead in reviewing existing security capabilities and assist in defining roadmap and strategy for security enhancements • Provide regular briefings to Application Security Lead and Information Security Manager (ISM), escalating issues and blockers as necessary • Provide technical guidance on secure development and vulnerability management activities • Stay current on industry trends, emerging threats, and relevant technologies, and communicate key insights to the Application Security Lead • Perform other duties as assigned within the scope of application security QUALIFICATIONS Required: • Seven (7) years of information security experience in specialized roles such as, but not limited to security architecture and design, security control implementation penetration testing, application security, vulnerability management, incident response • Demonstrated knowledge of secure SDLC, secure architecture design, application security concepts, and cloud- architecture including DevSecOps practices and shift-left security integration • Experience performing application security code reviews, roles and permissions matrix reviews, and practical application risk assessments, including manual and automated secure code reviews • Experience working with common vulnerability assessment tools such as Nessus, Rapid7, Nmap, and Burp Suite, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools • Advanced understanding of emerging cybersecurity threats, including application-layer attacks, API abuse, and software supply chain vulnerabilities • Strong analytical and problem-solving skills with the ability to “think outside the box” • Experience integrating security in infrastructure-as-code, CI/CD pipelines, and the software development lifecycle, including implementation of automated controls and continuous monitoring and security gates and pipeline enforcement policies • Demonstrates strong interpersonal and collaboration skills, effectively partnering with internal management, staff, and cross-functional teams as well as external partners and vendors Desired: • Bachelor’s degree in engineering, security or a technology related or closely allied field • Experience working with application security methodologies such as OWASP • Demonstrated experience in information security, data security, privacy, and data management, including secure handling of Personally Identifiable Information (PII), application-level encryption, and key management • Experience defining secure architectural requirements, security controls, and configuration standards in compliance with regulatory requirements • Experience working with threat modeling frameworks such as STRIDE and MITRE ATT&CK, including application-specific threat modeling, attack path analysis, and abuse case analysis • Experience developing, reviewing, and updating security standards, procedures, awareness and training, including secure coding standards and developer training programs • Demonstrates a solid understanding of the functions and operations of Security Information and Event Management (SIEM) systems, Endpoint Detection & Response • Demonstrated experience in managing cyber incident response, including coordination with development teams for rapid patching and hotfix deployment • Advanced understanding of emerging cybersecurity threats, including application-layer attacks, API abuse, and software supply chain vulnerabilities APPLICATION INSTRUCTIONS This position will be open until we find a suitable number of candidates to review. If interested, please submit an application with a cover letter as soon as possible. The Exchange reserves the right to close the recruitment at any time. SALARY INFORMATION Full Salary Range: $98,842.00 to $148,263.00 annually, with midpoint at $123,552.00. Hiring Range: $113,668.00 and $123,552.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer. The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum. BENEFITS Take a peek at our benefits package. WORKING CONDITIONS Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in-person collaboration. While a hybrid remote and on-site schedule may be considered, the position will require flexibility to allow for in-office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location. The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. SPECIAL REQUIREMENTS A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The incumbent in this role will also be required to complete a federal fingerprint background check. The results of these background screens must meet the Exchange’s eligibility standards. OTHER INFORMATION The above statements are intended to describe the general nature and levels of work being performed. They are not intended to be construed as an exhaustive list of responsibilities, duties and skills of personnel so classified. This is not an employment agreement or contract. Management has the exclusive right to alter this job description at any time without notice. The Washington Health Benefit Exchange is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, marital status, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. We participate in E-Verify. You can view the Department of Justice's Right to Work poster here.

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Senior Application Security Analyst in Washington DC vacancy
  •  ...Federal Govt. Client’s Mortgage Backed Securities (MBS) programs help to channel funds from...  ...trends, and customer demand. Financial analysts provide this information by gathering...  ...opportunity employer and considers qualified applicants for employment without regard to race,... 
    Senior
    Full time
    For contractors
    Bank staff
    Internship
    Work at office

    Prosidian Consultng

    Washington DC
    3 days ago
  • DescriptionSAIC is looking for a Senior Information Systems Security Analyst to join our team supporting an important US government agency in the National...  ...hardware, software, baselines, connections, or applications.Review and assess POA&M outputs, recommending additional... 
    Senior
    Work at office
    2 days per week

    Science Applications International Corporation

    Washington DC
    3 days ago
  •  ...about our employer brand at makpar.com/careers . The Senior Information Security Analyst will perform the core cybersecurity assessment and...  ...support status, shared systems, responsible entities, applicable checklists, and FTI system interactions. • Prepare scope... 
    Senior
    Full time
    Start working today
    Flexible hours

    Makpar Corporation

    Washington DC
    16 hours ago
  •  ...and grow professionally? We can help! We are seeking a Senior Security Operations Analyst to provide on-demand Cybersecurity and IT services to support...  ...is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to age, race... 
    Senior
    Full time
    Part time

    Terrestris Global Solutions

    Washington DC
    4 days ago
  •  ...to relocate from elsewhere in the US as a very last resort. Qualifications Required: ~5+ years of relevant information security experience (or 3+ years in IT systems administration with 2 years security responsibilities). ~ Cloud security experience with GCP... 
    Senior
    Local area
    Relocation

    Saxon Global

    Washington DC
    3 days ago
  •  ...in D.C., Qmulos you’ll work with industry trailblazers and global private-sector and public-sector clients to help solve national security problems. Job Description Research, verify and document information security controls using the Federal Certification and Accreditation... 
    Senior

    Qmulos

    Washington DC
    16 hours ago
  • $160k - $180k

     .... Responsibilities Economic security is an area of intense attention and...  ...SYSTEMS is currently looking to hire a Senior Economic Security Analyst to support OUSW(R&E). This position...  ...CFIUS cases and export license applications, coordinating with other technical... 
    Senior
    For contractors
    Currently hiring
    Work at office
    Remote work
    Flexible hours

    AMERICAN SYSTEMS

    Alexandria, VA
    1 day ago
  • $102.83k - $190.97k

     ...schedule (3 days onsite) out of our DC office. THE JOB The Senior Information Security Risk Analyst will support the assessment of information security...  ...require adjustments or accommodations during the job application and/or recruitment process, please visit our... 
    Senior
    Contract work
    Temporary work
    Work at office
    Local area

    Warner Media, LLC

    Washington DC
    4 days ago
  •  ...Candidates will be notified as funding and hiring timelines are confirmed. We encourage all qualified applicants to apply. We are currently seeking a Senior Security Operations Analyst to support cybersecurity operations within a federal environment in Washington, DC. This role... 
    Senior
    Full time
    Local area
    Shift work

    Otoe Missouria Group

    Washington DC
    2 days ago
  • $102.06k - $158.18k

     ...responsibilities include assisting in the development and implementation of security standards, procedures and guidelines for multiple platforms...  ...infrastructure, software, hardware, architecture, and/or applications are developed and deployed in a secure manner. The incumbent... 
    Senior
    Night shift

    National Education Association

    Washington DC
    3 days ago
  • DescriptionPersonnel Security Analyst / Adjudicator - SeniorThe Senior Security Analyst is a subject matter expert who independently applies ICD 704 and EO 12968 to the most complex cases involving significant derogatory information. Requiring rare guidance from Senior... 
    Senior

    Xcelerate Solutions

    McLean, VA
    4 days ago
  • $99k - $225k

    ISSO Security Analyst, SeniorThe Opportunity:As a Security Analyst on our team, you’ll use your experience to work with Veterans Affairs...  ...of excellent verbal and written communication skills Vetting:Applicants selected will be subject to a government investigation and may... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $102.5k - $188.9k

     ...confidence, and proactively manage to secure success.Cyber threats...  .... As a Cyber Exploitation Analyst, you will support cyber defense...  ...Monitor networks, systems, and applications for indicators of compromise...  ...entry-level employees to senior leaders, we believe there’s always... 
    Work at office

    Deloitte

    Rosslyn, VA
    3 days ago
  •  ...Program Advisor to oversee international security assistance trainings aimed at addressing...  ...State, interagency, foreign governments, and senior nuclear industry executives on CTR...  ...Government security clearance. For the Senior Analyst Level: Bachelor’s degree and a minimum of... 
    Senior
    For contractors
    Work at office

    General Dynamics Information Technology

    Washington DC
    5 hours ago
  • $117.5k - $176.3k

     ...history.Northrop Grumman is seeking a Sr. Principal Industrial Security Analyst/CSSO. This position will report directly to the Corporate...  ...program compliant with the 32 CFR Part 117 (NISPOM) and all other applicable security requirements.Develops, and administers security... 
    Senior
    Full time
    Contract work
    For subcontractor
    Relocation
    Shift work

    Northrop Grumman

    Falls Church, VA
    1 day ago
  •  ...guidance, and translating requirements into actionable security plans. Our team supports cloud and on-premises...  ...collaboration with technical and Government stakeholders. Senior Security Governance and Policy Analyst Serve as a principal security policy advisor to... 
    Senior

    One Federal Solution

    Washington DC
    27 days ago
  • $102k - $138k

     ...Qualifications: Skills: International Security, National Security, Nonproliferation,...  ...State, interagency, foreign governments, and senior nuclear industry executives on CTR...  ...Government security clearance. For the Senior Analyst Level: Bachelor's degree and a minimum of... 
    Senior
    Full time
    Temporary work
    Part time
    For contractors
    Work at office
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Washington DC
    4 days ago
  • $99k - $130k

     ...THE TEAMThe Counterintelligence (CI) and Security Investigations (SI) Team’s safeguards...  ...mitigate threats. The Security Vetting Analyst will provide analytical support to people...  ...policy, please visit . By submitting your application, you consent to Anduril Industries using... 
    Full time
    For contractors
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    4 days ago
  •  ...Job Description Job Description **CONTINGENT UPON CONTRACT AWARD**Overview: Job Title: Security Operations Analyst – Senior Location : Washington, DC (Due to the nature of the work and contract requirements, U.S. Citizenship is required. ) Description:... 
    Senior
    Contract work

    C3EL

    Washington DC
    20 days ago
  •  ...seeks a Mid-Level InfoSec Mobile Device Security Analyst Consultant focusing on Cyber-Security/...  ...in writing, with elected officials, senior staff, information systems professionals...  ...Management (MDM) environment.-Review applications and provide recommendations on whether... 
    Full time
    For contractors
    Work experience placement
    Internship
    Work at office
    Monday to Friday
    Shift work

    Prosidian Consultng

    Washington DC
    3 days ago
  •  ...About the PositionDexis is seeking a Security Assistance Analyst to support anticipated programming with...  ...products for program managers and senior leaders. Excellent written and verbal...  ...recommendations. Proficiency with Microsoft 365 applications, including Excel, Word, PowerPoint,... 
    Contract work

    Dexis Consulting Group

    Washington DC
    1 day ago
  • DescriptionSAIC is seeking a Security and Facilities Specialist with an active TS/SCI to provide security, facility, and customer support...  ..., and SAIC personnel. Complete understanding and wide application of principles, concepts, practices, and standards. Full knowledge... 
    For contractors
    Work at office

    Science Applications International Corporation

    Arlington, VA
    3 days ago
  • $125k - $195k

     ...detail oriented and diligent analyst to provide comprehensive support...  ...a project centered around secure financials. The ideal candidate...  ...Access requestsDelivering applicable security education and training...  ...expected to go directly for senior reviewAble to demonstrate a capability... 
    Contract work
    For contractors
    Work experience placement
    H1b

    SMX

    Arlington, VA
    11 hours ago
  •  ..., and trusted results to enable national security missions worldwide.Job Description*** This...  ...***OverviewSOSi is seeking a Security Analyst - Forensics/Malware Analysis to support cyber...  ...timeFunction: OtherExperience level: Mid-Senior LevelIndustry: Information Technology And... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    3 days ago
  • $132.5k - $221.3k

     ...and Training.ResponsibilitiesAs The Security Specialist Security Operations Analyst, you will:Apply structured...  ...decision papers, and recommendations for senior stakeholders.Maintain data sets,...  ...eligibility; must be able to meet any applicable Special Access Program eligibility... 
    For contractors
    Work experience placement

    AMERICAN SYSTEMS

    Arlington, VA
    2 days ago
  • $104k - $166k

    ResponsibilitiesPeraton is currently seeking to hire an experienced Forensics / Malware Security Analyst for its Federal Strategic Cyber Group.Location: Chandler, AZ or Washington DC.Role & Responsibilities: You will support a 24x7 Security Operations Center (SOC) by conducting... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Washington DC
    3 days ago
  • $145k - $200k

    Washington, D.C.Information Security /Full-time /On-siteA World-Changing CompanyPalantir...  ...and more.The RoleAs a Defensive Security Analyst, you are responsible for the security of...  ...disabilities. Palantir is committed to making the application and hiring process accessible to... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    3 days ago
  •  ...Compensation: $50.88/HR on W2 Security Clearance: Ability to obtain...  ...malware-related issues, providing senior-level support. Coordinate...  ...Security Operations Analyst (preferred). System One, and...  ...Opportunity Employer. All qualified applicants will receive consideration... 
    Senior
    Contract work
    Local area

    System One

    Washington DC
    22 days ago
  •  ...attitude in the delivery of superior customer service. Senior Security Governance and Policy Analyst The Senior Security Governance and Policy Analyst...  ...CDO is an equal opportunity employer. All qualified applicants will receive consideration for employment without... 
    Senior
    Full time
    Temporary work
    Flexible hours
    Night shift

    CDO Technologies Inc

    Washington DC
    13 days ago
  • $145k - $168k

     ...SENIOR SECURITY GOVERNANCE AND POLICY ANALYST Concurrent Technologies Corporation Washington DC Metro Area Minimum Clearance Required : TS/...  ...policies align with NIST, FISMA, RMF, CNSS, ICD, and other applicable federal standards. Support governance activities... 
    Senior
    Full time
    Temporary work

    Concurrent Technologies Corporation

    Washington DC
    11 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Analyst. Be the first to apply!