Remote Jobs

GuidePoint Security logo

Application Security Analyst

GuidePoint Security

Location
United States of America
Posted

Assist in delivering Application Security services at GuidePoint Security by performing DevSecOps assessments, architecture reviews, threat modeling, and designing secure pipelines. Contribute to client engagements, deliver comprehensive reports, and strengthen application security capabilities while staying updated with industry trends and tools.

GuidePoint Security logo

Application Security Engineer

GuidePoint Security

Location
United States of America
Posted

As an Application Security Engineer, you will work with tools like Burp Suite Pro and Invicti to identify and remediate vulnerabilities, integrate security tools into CI/CD pipelines, and collaborate with teams to enhance application security practices. You'll need strong technical skills in secure development lifecycles and excellent communication abilities.

Binance logo

Application Security Engineer

Binance

Location
Brunei Darussalam
Posted

Application Security Engineer at Binance: Collaborate on mobile security, blockchain security, and AI tools

Gusto, Inc. logo

Principal Security Engineer - Application Security

Gusto, Inc.

Location
Canada
Posted
Salary Range
225k - 285k USD

Security Engineering role at Gusto, designing safe features with safety & privacy in mind, building security tools & services, 12+ yrs info sec exp reqd.

Wealthsimple logo

Staff Security Developer - Application Security and Posture Management

Wealthsimple

Location
Canada
Posted
Salary Range
80k - 120k CAD

Join Wealthsimple as an Application Security Engineer and help secure our applications with your expertise in tooling, architecture, and offensive security testing. Collaborate with teams to mitigate risks and enhance security practices while enjoying top-tier benefits and a supportive remote-first culture.

Figma logo

Security Compliance Analyst

Figma

Location
United States of America
Posted
Salary Range
122k - 215k USD

Coordinate and manage audit certification lifecycles for Figma's compliance initiatives. Maintain certifications like SOC 2 Type II and ISO 27001, drive roadmaps based on customer needs, improve operational activities, implement scalable controls, and configure automation tools for continuous monitoring.

Twilio logo

Security Customer Trust Analyst, Information Security

Twilio

Location
Ireland
Posted

Remote Security Customer Trust Analyst role at Twilio, supporting largest customers with security awareness and education, collaborating with internal stakeholders and contributing to process enhancements.

Twilio logo

Security Customer Trust Analyst, Information Security

Twilio

Location
United Kingdom
Posted

Security Customer Trust Analyst at Twilio: Support largest customers' security awareness & education, collaborate with internal teams, identify risks, and maintain questionnaire responses.

Alma logo

Senior Security Operations Analyst

Alma

Location
United States of America
Posted
Salary Range
145k - 175k USD

Join Alma as a Senior Security Operations Analyst to defend against cybersecurity threats by managing incidents, deploying detection tools, and collaborating with teams to enhance security measures. Enjoy remote work flexibility and comprehensive benefits.

Gitlab logo

Intermediate Backend Engineer, Application Security Testing: Composition Analysis

Gitlab

Location
United States of America
Posted
Salary Range
98k - 210k USD

Enhance security posture by developing features for GitLab's products like Dependency Scanning and Container Scanning. Collaborate with cross-functional teams to maintain high quality in a fast-paced environment. Enjoy remote work and comprehensive benefits including equity compensation and home office support.

G-P logo

Information Security Analyst - SecOps

G-P

Location
United States of America
Posted
Salary Range
110k - 135k USD

Secure G-P's infrastructure by investigating alerts, responding to incidents, and providing security expertise. Enjoy excellent benefits including health insurance, 401K matching, PTO, and sabbaticals after five years.

ExtraHop logo

Product Security Analyst III | SOC

ExtraHop

Location
United States of America
Posted

Product Security Analyst at ExtraHop: Collaborate with top-tier professionals, learn & innovate, and grow your skills in cyber, cloud & product security.

Binance logo

Web3 Security Data Analyst

Binance

Location
Brunei Darussalam
Posted

Security Data Analyst at Binance: Analyze on-chain data for anomalous transactions and develop detection mechanisms.

Twilio logo

Staff Analyst, Security Risk Management

Twilio

Location
Canada
Posted

Risk management analyst needed at Twilio, requiring 5+ years of experience in security-centric risk management and compliance frameworks.

Twilio logo

Staff Analyst, Security Risk Management

Twilio

Location
Canada
Posted

Risk Management Analyst at Twilio, leading daily management of One Twilio Risk Management program, developing risk registers, collaborating with teams, and analyzing risk data.

Udacity logo

Session Lead - Integrated Application Security Services Nanodegree Session lead

Udacity

Location
India
Posted

Provide world-class technical support to students in their Nanodegree journey by leading weekly virtual sessions, responding to questions, and ensuring progress. Utilize expertise in Python, SQL, Big Data, Hadoop, and other relevant areas while fostering a supportive learning environment.

GuidePoint Security logo

Application Security Analyst

GuidePoint Security

Job Summary

At GuidePoint Security, the Application Security Analyst will assist in delivering DevSecOps and strategic AppSec projects. This role involves performing assessments, architecture reviews, threat modeling, designing security pipelines, and contributing to client engagements. Key responsibilities include providing technical leadership, delivering comprehensive reports, and fostering client relationships. The position requires a strong understanding of application security tools, methodologies, and frameworks, along with experience in DevOps tooling and Agile practices. Additionally, the role offers opportunities for thought leadership through speaking at conferences, authoring content, and participating in marketing initiatives. Continuous learning and skill development are encouraged to stay ahead in the information security industry.

Skills

Agile MethodologiesBambooJenkinsJiraDevSecOpsAzure DevOpsThreat ModelingSASTDASTApplication Architecture ReviewsSecurity Configuration ReviewsOWASP SAMMBSIMMCucumberNUnitJUnitIASTOSAcontainerization technologies

GuidePoint Security offers an inclusive set of Application Security services, including tactical assessments and strategic advisory. As an Application Security Analyst within Strategic Application Security Services, your primary responsibilities will be assisting with the delivery of DevSecOps and strategic AppSec projects. These offerings include performing DevSecOps/Agile and AppSec Program Assessments, performing Architecture Reviews and Threat Modeling, designing DevSecOps pipelines, assisting organizations with large-scale DevSecOps transformations, performing secure configuration reviews, and providing technical leadership within our Application Security practice.

 

The Application Security Analyst joins GuidePoint’s elite team of Application Security experts to deliver the aforementioned services, which involves performing engagements, communicating with clients, delivering comprehensive reports, and providing thought leadership within the Application Security space. You will spend your time focusing on challenging projects and solving complex problems. Our clients will rely on your experience, adaptability, and creativity to protect their business applications and mature their Application Security capabilities. GuidePoint Security’s Application Security team's offerings consistently evolve with the security industry and risks that modern environments face.

 

Role Requirements

  • Willingness to travel up to 20%

  • Assist with the performance of Application Security services, including but not limited to DevSecOps and Application Security Program Assessments,  Application Architecture Reviews, Threat Modeling, designing industry-leading Application Security programs, Secure SDLC Implementation, Security Configuration Reviews, AppSec-related training

  • Contribute to comprehensive assessment deliverables that are proficiently tailored to both technical and managerial audiences and fully detail the technical execution, core deficiencies, business impact, and realistic remediation strategies

  • Awareness and understanding of the rapidly changing application security landscape, including open-source and commercial tools, assessment methodologies and approaches, and strategy frameworks, such as OWASP SAMM, and BSIMM

  • Familiarity with common Agile development methodologies, such as the Scaled Agile Framework

  • Familiarity with common DevSecOps related tooling including but not limited to continuous integration tooling (Jenkins, Bamboo), QA testing frameworks and tools (Cucumber, NUnit, JUnit ), automated application security testing tools (SAST, DAST, IAST, OSA), defect tracking systems (JIRA, Azure DevOps), and containerization technologies

  • Understanding of a broad range of application security issues, mitigation strategies, and common application security controls

  • Contribute to marketing initiatives via activities such as publishing research, speaking at industry conferences, authoring blog articles and white-papers, hosting webinars, and developing security tools

  • Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry

  • Foster client relationships by providing support, information, and guidance

  • Maintain a strong desire to learn, adapt, and improve along with a rapidly-growing company

  • Perform other duties as assigned

Education, Credentials, and Experience

  • Direct hands-on experience in performing Application Security service offerings, including but not limited to DevSecOps implementations, tool automation, application threat modeling, application architecture reviews, and program assessments

  • Experience and working knowledge of Application Security controls, application architectures, database architectures, security requirements, and industry standards and frameworks

  • Operational DevSecOps experience

  • Hands-on experience with a broad range of DevOps tooling that is necessary to support scalable application security, such as containerization technologies, continuous integration tools, source code repositories, defect tracking systems, and QA testing tools

  • Strong communication skills that include the ability to clearly articulate thoughts and distill complex problems into digestible pieces of information during live conversations, formal deliverables, white papers, and case studies

  • InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience is strongly preferred

  • Standard industry certifications are preferred

  • Experience in an enterprise-level consulting services or Application Security related role is strongly preferred

  • Internal operational (non-consulting) experience is strongly preferred

  • Bachelor’s degree in a relevant discipline or equivalent experience