Application Security Analyst

GuidePoint Security Logo

GuidePoint Security

πŸ“Remote - Worldwide

Summary

Join GuidePoint Security's elite Application Security team as an Application Security Analyst. You will contribute to the delivery of DevSecOps and strategic AppSec projects, performing assessments, architecture reviews, threat modeling, and designing secure pipelines. This role involves client communication, report delivery, and thought leadership within the Application Security space. You will work on challenging projects, solving complex problems, and leveraging your experience and creativity to protect client applications. GuidePoint offers a supportive and collaborative environment with opportunities for professional growth. The position is primarily remote, with some travel potentially required.

Requirements

  • Willingness to travel up to 20%
  • Direct hands-on experience in performing Application Security service offerings, including but not limited to DevSecOps implementations, tool automation, application threat modeling, application architecture reviews, and program assessments
  • Experience and working knowledge of Application Security controls, application architectures, database architectures, security requirements, and industry standards and frameworks
  • Operational DevSecOps experience
  • Hands-on experience with a broad range of DevOps tooling that is necessary to support scalable application security, such as containerization technologies, continuous integration tools, source code repositories, defect tracking systems, and QA testing tools
  • Strong communication skills that include the ability to clearly articulate thoughts and distill complex problems into digestible pieces of information during live conversations, formal deliverables, white papers, and case studies
  • Bachelor’s degree in a relevant discipline or equivalent experience
  • Awareness and understanding of the rapidly changing application security landscape, including open-source and commercial tools, assessment methodologies and approaches, and strategy frameworks, such as OWASP SAMM, and BSIMM
  • Familiarity with common Agile development methodologies, such as the Scaled Agile Framework
  • Familiarity with common DevSecOps related tooling including but not limited to continuous integration tooling (Jenkins, Bamboo), QA testing frameworks and tools (Cucumber, NUnit, JUnit ), automated application security testing tools (SAST, DAST, IAST, OSA), defect tracking systems (JIRA, Azure DevOps), and containerization technologies
  • Understanding of a broad range of application security issues, mitigation strategies, and common application security controls

Responsibilities

  • Assist with the performance of Application Security services, including but not limited to DevSecOps and Application Security Program Assessments, Application Architecture Reviews, Threat Modeling, designing industry-leading Application Security programs, Secure SDLC Implementation, Security Configuration Reviews, AppSec-related training
  • Contribute to comprehensive assessment deliverables that are proficiently tailored to both technical and managerial audiences and fully detail the technical execution, core deficiencies, business impact, and realistic remediation strategies
  • Contribute to marketing initiatives via activities such as publishing research, speaking at industry conferences, authoring blog articles and white-papers, hosting webinars, and developing security tools
  • Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry
  • Foster client relationships by providing support, information, and guidance
  • Maintain a strong desire to learn, adapt, and improve along with a rapidly-growing company
  • Perform other duties as assigned

Preferred Qualifications

  • InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience
  • Standard industry certifications
  • Experience in an enterprise-level consulting services or Application Security related role
  • Internal operational (non-consulting) experience

Benefits

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family) and GPS will contribute in one lump sum: ($500 per EE annually / $1000 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Remote Jobs