Application Security Analyst

FSAStore.com

United States

On-site

USD 75,000 - 95,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
401K with company match
Flexible PTO
Monthly wellness & internet reimburse"
Professional development

Job summary

FSAStore.com is seeking an Application Security Analyst to embed security into software development. This hands-on role will secure code, fix pipelines, manage security tools, and help with audits such as PCI, HIPAA, and HITRUST.

You'll work closely with engineering to build security into CI/CD pipelines, implement testing and runtime protections, and ensure AI/ML components are resilient against threats. This remote-first, US-focused team values practical security and rapid delivery.

Qualifications

  • Minimum of 2+ years of experience in Application Security or Product Security.
  • Hands-on experience with secure code scanning tools such as SCA and SAST.
  • Strong knowledge of OWASP Top 10 vulnerabilities.
  • Experience securing APIs and microservices.
  • Familiarity with CI/CD pipelines.
  • Basic understanding of AI/ML systems.

Responsibilities

  • Perform application security assessments using SCA, SAST, Secrets management, and interactive testing tools.
  • Identify, triage, and prioritize vulnerabilities.
  • Integrate security testing into CI/CD pipelines (DevSecOps).
  • Assess security risks in AI/ML-enabled applications, including model exposure and inference endpoints.
  • Secure AI APIs, plugins, and third-party integrations.
  • Tune security controls across technologies such as WAF, EDR, MDM, and cloud.
  • Conduct threat modeling and secure design reviews for applications and AI use cases.
  • Assess and harden identity and access flows ensuring least privilege.
  • Automate repetitive security tasks so the team can focus on higher-value work.
  • Partner with developers to remediate vulnerabilities and improve secure coding practices.
  • Monitor and respond to security incidents as part of an on-call rotation.

Skills

SCA
SAST
Secrets management
Interactive testing
OWASP Top 10
API security
CI/CD pipelines
DevSecOps
Cloud security
AI/ML security

Tools

SAST tools
SCA tools
Threat modeling tools

Job description

We are seeking an Application Security Analyst to build security into how we ship software, and to help our small but growing Information Security team with day-to-day work. This is a hands‑on role. You will secure code, fix pipelines, manage security tools and requests and also help us stay ready for audits like PCI, HIPAA, and HITRUST.

You will work closely with engineering teams to embed security into development pipelines, implement testing and runtime protections, and ensure that AI/ML components are resilient against emerging threats.

This is a great fit for someone who likes both building and securing things, and whodoesn'tmind wearing more than one hat on a small team.

Key responsibilities:
  • Perform application security assessments using SCA, SAST, Secrets management, and interactive testing tools
  • Identify, triage, and prioritize vulnerabilities
  • Integrate security testing into CI/CD pipelines (DevSecOps)
  • Assess security risks in AI/ML‑enabled applications, including model exposure and inference endpoints
  • Secure AI APIs, plugins, and third‑party integrations
  • Tune security controls across technologies such as WAF, EDR, MDM, and cloud
  • Conduct threat modeling and secure design reviews for applications and AI use cases
  • Assess and harden identity and access flows ensuring least privilege
  • Automate repetitive security tasks so the team can focus on higher‑value work
  • Partner with developers to remediate vulnerabilities and improve secure coding practices
  • Monitor and respond to security incidents as part of an on‑call rotation
What you'll need:
  • Minimum of2+ years of experience in Application Security or Product Security
  • Hands‑on experience with secure code scanning tools such as SCA and SAST
  • Strong knowledge of OWASP Top 10 vulnerabilities
  • Experience securing APIs and microservices
  • Familiarity with CI/CD pipelines
  • Basic understanding of AI/ML systems
  • Cloud security experience
  • Good communication skills — you’ll work with engineers, and sometimes explain things to non‑technical people
  • A security mindset: you think about how things can break, not just how to make them work
Preferred Qualifications:
  • Experience with ML frameworks is a plus
  • Familiarity with AI threat models
  • Experience with WAF or API security solutions
  • Strong coding skills in at least one language (Python, Bash, or similar)
  • Experience in ecommerce, healthcare or another highly regulated industry
Compensation, Benefits, & Additional Details:

Health‑E Commerce's compensation philosophy is grounded in market data and internal equity to ensure fairness and consistency across the team. Individuals new to the company should generally expect offers to fall between the entry point and midpoint of the salary range. Our goal is to provide an offer that supports growth potential within the role and allows for future salary progression.

  • Compensation: $75,000 - 95,000
  • Discretionary Annual Bonus Eligibility: Up to 10%
  • Medical, Dental, Vision, and 401K with a company match
  • Dependent Care, FSA & HSA accounts
  • Flexible PTO & office closure on all major holidays
  • Monthly wellness & internet reimbursements
  • Professional development including certification support & leadership coaching

We are a remote first organization and hire within the states listed below. Please confirm you meet the physical location requirements prior to proceeding. *Select...

Please confirm your location from the options below: Arkansas, California, Colorado, Connecticut, Florida, Georgia, Idaho, Illinois, Kansas, Maine, Maryland,Massachusetts, Michigan, Minnesota, Missouri, New Hampshire, Nevada, New Jersey, New York,North Carolina, Ohio, Oregon, Pennsylvania, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, and Wisconsin.

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.

As set forth in FSAStore.com’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

Health‑E Commerce uses Real Talent technology integrated with Greenhouse to support AI powered talent matching. This technology assists our hiring team in identifying candidates whose skills and experience align with current and future opportunities. All hiring decisions are made by our recruitment professionals.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI DevSecOps Senior Engineer
AI DevSecOps Senior Engineer

Elevance Health • Indianapolis (IN)

Hybrid
USD 140,000 - 180,000
AI DevSecOps Senior Engineer
AI DevSecOps Senior Engineer

The Elevance Health Companies, Inc. • Indianapolis (IN)

Hybrid
USD 140,000 - 180,000
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Honolulu (HI)

On-site
USD 144,000 - 289,000
401(k) plan with company matching
Affordable medical plan options
Tuition assistance
+1
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Richmond (VA)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with company matching
Employee stock purchase plan
Application & Web Security Specialist
Application & Web Security Specialist

Dillards • Little Rock (AR)

On-site
USD 85,000 - 120,000
Principal Application Security Engineer – AI & Agentic Systems
Principal Application Security Engineer – AI & Agentic Systems

CVS Health • Columbus (OH)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Columbia (SC)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Cheyenne (WY)

On-site
USD 144,000 - 289,000
401(k) plan with matching contributions
Employee stock purchase plan
No-cost wellness programs
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Frankfort (KY)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Santa Fe (NM)

On-site
USD 144,000 - 289,000
Affordable medical plans
401(k) plan with company match
Employee stock purchase plan
+2