The Application Security Analyst is responsible for ensuring that the company application products - whether on-premises, web-based, or cloud - are designed, developed and maintained with security in mind. This role involves conducting security research, evaluating and recommending security tools, supporting compliance initiatives, and proactively identifying vulnerabilities across all products. The analyst works closely with the software development team to embed security into every stage of the development lifecycle.
Key Responsibilities:
- Research, evaluate, and recommend security tools and practices to strengthen software development teams' security posture.
- Conduct vulnerability assessments and security testing across different types of applications (desktop, web and cloud).
- Support the software development team in implementing secure coding practices and integrating security into the development lifecycle (SSDLC)
- Contribute to security compliance initiatives (e.g. ISO 27001, SOC 2, GDPR and other relevant standards).
- Collaborate with the security team to align application security efforts with overall company security policies and strategies.
- Work with developers, software testers, and DevOps to embed security into CI/CD pipeline and deployment processes.
- Monitor and report on emerging threats, technologies, and best practices relevant to application security.
- Provide security awareness and guidance to the development team.
- Provide product security-related responses to customer security inquiries and requests from internal teams.
Skills & Qualifications:
- Good understanding of application and web security fundamentals
- Familiarity with common vulnerabilities such as the OWASP Top 10
- Basic knowledge of vulnerability assessment and security testing tools
- Understanding of software development and the SDLC
- Familiarity with secure coding concepts and DevSecOps practices
- Basic understanding of CI/CD pipelines
- Ability to analyze security findings and distinguish meaningful risks from false positives
- Good research and problem-solving skills
- Strong written and verbal communication skills
- Ability to work effectively with developers, testers, DevOps, and other technical teams
- Willingness and ability to continuously learn about emerging vulnerabilities, attack techniques, and security technologies