Security Analyst
$85k - $95kASM Research, An Accenture Federal Services Company
The Security Analyst integrates application security practices throughout the software development life cycle for enterprise and mission-critical systems. The role partners with software engineering, architecture, DevOps, operations, and client stakeholders to translate security requirements into practical design, development, testing, deployment, and remediation activities.
The Security Analyst conducts security architecture and design reviews, vulnerability assessments, and technical risk analyses; interprets findings; and guides application owners through prioritized mitigation and validation. The role also develops and enforces secure-development procedures, evaluates security tools and automation, and strengthens the organization’s application security posture in a highly regulated federal IT environment.
Key Responsibilities
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Integrate application security requirements, secure design practices, and security acceptance criteria across planning, development, testing, deployment, and maintenance phases of the software development life cycle.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Conduct and support security architecture reviews, threat modeling, secure design reviews, and vulnerability assessments for web applications, APIs, cloud-hosted workloads, services, and supporting infrastructure.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Analyze findings from static application security testing, dynamic application security testing, software composition analysis, dependency scanning, secrets scanning, container scanning, and penetration testing to determine risk and remediation priority.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Partner with development, DevOps, architecture, and operations teams to identify security risks, explain vulnerabilities, and provide practical, actionable mitigation recommendations.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Perform or support secure code reviews and assess applications for authentication and authorization weaknesses, insecure configurations, secrets exposure, common software weaknesses, and other security control gaps.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Track vulnerabilities and corrective actions through remediation, validate evidence of closure, and perform retesting as needed to confirm risk reduction.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Develop and maintain security procedures, technical standards, assessment reports, and risk communications that support informed authorization, remediation, and stakeholder decisions.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Evaluate application-security products and developer-facing tools for coverage, integration feasibility, operational impact, reporting quality, and compatibility with source-control and CI/CD workflows.
Required Qualifications
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Bachelor’s degree in Computer Science, Engineering, or another technical discipline, or equivalent relevant experience.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Typically 5–10 years of progressively responsible experience in application security, secure software engineering, vulnerability management, or a closely related cybersecurity discipline.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Demonstrated experience applying secure SDLC practices, including security requirements definition, threat modeling, architecture review, secure design patterns, and security acceptance criteria.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Experience assessing web applications, APIs, services, cloud-hosted workloads, and supporting infrastructure for vulnerabilities, insecure configurations, identity and access control weaknesses, and software security risks.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Ability to interpret, prioritize, and communicate findings from application-security testing, vulnerability scanning, dependency analysis, secrets scanning, container scanning, and penetration testing.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Strong working knowledge of vulnerability triage, risk scoring, exploitability analysis, compensating controls, remediation tracking, and validation of corrective actions.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> U.S. citizenship is required, with the ability to obtain and maintain a Public Trust background investigation.
Preferred Qualifications
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Professional security certification such as CSSLP, Security+, CISSP, a GIAC application-security credential, or a cloud-security certification.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Experience embedding automated security controls, policy gates, and scan-result workflows into CI/CD pipelines and infrastructure-as-code delivery processes.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Experience supporting application security activities within a highly regulated federal, defense, or government environment.
p]:pt-0 [&> p]:mb-2 [&> p]:my-0"> Experience conducting secure architecture reviews, applying threat-modeling methods, and remediating OWASP-aligned application-security risks.
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$85,000 – $95,000
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
$132.5k - $221.3k
...Technology, Test & Evaluation, Program Mission Support, Engineering & Analysis, and Training.ResponsibilitiesAs The Security Specialist Security Operations Analyst, you will:Apply structured analysis, business modeling, and process evaluation to improve security operations...SuggestedFor contractorsWork experience placement$62k - $141k
COMSEC Security Program AnalystThe Opportunity:Provide technical and financial analytic support to the client’s Communications Security (COMSEC), Cryptographic, and Cybersecurity programs and efforts to ensure requirements align with Navy, Joint, and DoD strategic COMSEC...SuggestedCivilian ContractorFull timeContract workPart timeWork at officeLocal areaRemote work$112.2k - $196.4k
...you to achieve your full potential. Unleash your talent and redefine what’s possible.Job Description:Parsons is seeking a Security Cooperation Analyst to support the Office of the Deputy Assistant Secretary of War for Cyber Operations Policy (DASW COP) in developing,...SuggestedFull timeWork at officeFlexible hours- ...State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian seeks a Mid-Level InfoSec Mobile Device Security Analyst Consultant focusing on Cyber-Security/Information Security (INFOSEC) and IT Effectiveness Solution related issues, to support...SuggestedFull timeFor contractorsWork experience placementInternshipWork at officeMonday to FridayShift work
- DescriptionSAIC is seeking a Security and Facilities Specialist with an active TS/SCI to provide security, facility, and customer support for a diverse team of government, contractor, and SAIC personnel. Complete understanding and wide application of principles, concepts...SuggestedFor contractorsWork at office
$145k - $200k
Washington, D.C.Information Security /Full-time /On-siteA World-Changing CompanyPalantir builds the world’s leading software for data-driven... ...missing children, and more.The RoleAs a Defensive Security Analyst, you are responsible for the security of Palantir’s people and...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package$99k - $225k
Security Specialist & Counterintelligence AnalystThe Opportunity: Deliver mission-critical insight to inform senior-level decisions and ensure protection of U.S. forces, infrastructure, and sensitive operations against foreign intelligence threats. Apply analytical tradecraft...Full timeContract workPart timeWork at officeLocal areaRemote work- ...What You Will Do:Guidehouse is looking for an experienced professional with experience in building, controlling, and supporting the secure configurations of information systems for federal organizations. Your duties will include supporting and controlling secure...Full timeFlexible hours
- ...Description **This position requires Secret Security Clearance** COMPANY OVERVIEW Founded in 2008, LNO, Inc. is a rapidly growing... ..., and Technology and Business Training. Senior Security Analyst LNO is seeking an Information Cloud Security Analyst to...Work at officeLocal areaWorldwide
$75k - $90k
...Security Analyst I Job Locations US-VA-Alexandria | US-VA-Arlington Job ID 2026-6986 Type Full-Time Salaried Company Nakupuna Consulting Additional Locations US-VA-Arlington Overview Nakupuna Companies is seeking...Full timeContract workFor contractorsWork at officeRelocationOverseas- ...Location Riverdale, MD Our client is seeking a Security Analyst with a strong security background to lead security assessments, manage and maintain our SOC 2 compliance program, and oversee our vulnerability management lifecycle. This role will be hands-on and highly...Permanent employmentFull timeTemporary work
- ...solutions, tested leadership, and trusted results to enable national security missions worldwide.Job Description*** This position is contingent upon contract award ***OverviewSOSi is seeking a Security Analyst - Forensics/Malware Analysis to support cyber defense and...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...objectives. The ProSidian Federal Govt. Client’s Mortgage Backed Securities (MBS) programs help to channel funds from the nation's capital... ...economic and industry trends, and customer demand. Financial analysts provide this information by gathering and analyzing data. They...Full timeFor contractorsBank staffInternshipWork at office
$107.9k - $195.05k
The C5ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber operations organization supporting the Department... ...an immediate opportunity for an experienced Endpoint Security Analyst to support a highly visible, strategic Cybersecurity Task Order...Full timeImmediate start$104k - $166k
ResponsibilitiesPeraton is currently seeking to hire an experienced Forensics / Malware Security Analyst for its Federal Strategic Cyber Group.Location: Chandler, AZ or Washington DC.Role & Responsibilities: You will support a 24x7 Security Operations Center (SOC) by conducting...Contract workCurrently hiringShift work- Avalore, LLC seeks a Management Analyst to analyze War Data Platform (WDP) program operations, processes, resources, and performance to support program management and strategic decision-making. You will conduct cost-benefit analyses, risk assessments, and develop reports...
$3,000 per month
...and help protect critical government missions? Join Acuity's cybersecurity team supporting the U.S. Department of State. As a Security Analyst, you will support day-to-day cybersecurity operations by monitoring security events, managing user access, tracking vulnerabilities...Contract workWork from home- ...given the means and mentorship needed to succeed, and your creativity will be rewarded.About the PositionDexis is seeking a Security Assistance Analyst to support anticipated programming with the Department of State. This opportunity will provide program analysis,...Contract work
$62k - $141k
...benefits that your life and work. Innovate with intention Build mission-ready tech that protects the nation. Crisis Response and Security Program Analyst The Opportunity: As a Crisis Response and Embassy Security Program Analyst, yousupport executive-level leadership and...Full timeContract workPart timeWork at officeLocal areaRemote workOverseas- Personnel Security Analyst Position Summary: Position Description: Personnel Security Analyst Location: Washington, DC Work Posture: On-site Travel: Occasional Deployment: No Drug screening: Yes Security Clearance: Citizenship: Secret Must be a U.S. Citizen...Contract workWork at office
- Advanced Decision Vectors LLC seeks a Foreign Military Sales (FMS) Analyst Logistics Analyst II to support DSCA OPSGEX in Arlington, VA. The role focuses on FMS case activities, DoD Security Cooperation program actions, and coordination with DSCA components and partner...Work at officeRemote work
$98.15k - $108.21k
Mid-Level Security Analyst (6005) Location Crystal City, VA Job Code 6005 # of Openings 1 Apply Now ( Bennett Aerospace Inc., a subsidiary of Three Saints Bay, LLC, and a Federal Government Contractor industry leader, isseeking a Mid-Level Security Analysts to provide...For contractorsWork at officeLocal area- DLH Corp in Bethesda, Maryland is seeking a Security Assessment & Authorization Analyst to develop and maintain ATO packages and support RMF lifecycle across assigned systems. You will work with customers to understand technologies, document security controls, and manage...
- Advanced Decision Vectors, LLC seeks a Foreign Military Sales (FMS) Analyst - Logistics Analyst II to support DSCA OPS/GEX. This hybrid... ...two days remote. The ideal candidate will have 5+ years in DoD security cooperation, an active Secret clearance, and experience with...Work at officeRemote work3 days per week
- ...Contingent Upon Proposal Award About Essnova Essnova Solutions, Inc. is seeking an experienced Security Authorization / Information System Security Officer (ISSO) Analyst to support federal cybersecurity authorization, compliance, security documentation, and audit-...Full timeContract workLocal areaRemote work
- ...contractor that provides services and solutions in: National Security Programs Professional, Administrative, and Management... ...Time Position Status: Contingent Position Title: Security Analyst Location:Arlington, VA Security Clearance:Secret Duties...Full timeFor contractors
- ...When it comes to excellence, we deliver. Learn more about our employer brand at makpar.com/careers . The Senior Information Security Analyst will perform the core cybersecurity assessment and compliance work for IRS Safeguards. The role supports computer security...Full timeStart working todayFlexible hours
- ...NextGen Federal Systems is seeking an Information Security Analyst to join our work supporting our DHS customer in Washington, DC. The ISA will report to the ISSM and provide security and compliance duties to assigned systems stakeholders. Duties include but are not...Full timeWork at office
- Job Summary: The Security Analyst Consultant will support an ongoing cybersecurity project, providing expertise in security analysis and risk management. This role requires full onsite presence in Columbia, South Carolina, and adherence to security clearance residency...Full time
$87.1k - $157.45k
...Leidos is seeking an experienced Tier 2 Security Operations Center (SOC) Analyst to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting...Contract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst. Be the first to apply!
- entry level information security analyst Washington DC
- junior security analyst Washington DC
- application security analyst Washington DC
- IT security analyst Washington DC
- network security analyst Washington DC
- information security compliance analyst Washington DC
- security analyst remote Washington DC
- information security analyst Washington DC
- work from home security analyst Washington DC
- national security analyst Washington DC



