Application Security Vulnerability Analyst

Perennial Resources International

New York (NY)

On-site

USD 110,000 - 160,000

Full time

8 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Guardian is seeking an experienced professional to lead vulnerability analysis and risk assessment within its application security program. You will review findings from SAST/SCA tools, evaluate risk beyond CVSS, and provide actionable remediation guidance to developers and architects.

You will partner with technology owners to establish remediation plans, track progress, and communicate risk to stakeholders. Strong communication and collaboration across multiple workstreams are essential.

Qualifications

  • 3+ years in application security or related cybersecurity discipline.
  • Strong understanding of OWASP Top 10 and CWEs.
  • Experience interpreting findings from application security tools.
  • Experience using AI-based security tools.
  • Ability to evaluate findings in context of exploitability, exposure, and business risk.
  • Experience working with development teams to remediate vulnerabilities.
  • Strong written and verbal communication skills.

Responsibilities

  • Review vulnerabilities identified through AI-based SAST, SCA, and related tools.
  • Evaluate vulnerabilities beyond vendor severity scores considering exposure, business impact, and compensating controls.
  • Validate vulnerability classifications and remediation recommendations; identify false positives.
  • Provide actionable remediation guidance and secure coding recommendations.
  • Assist application teams in understanding root causes and fixes; align remediation plans with stakeholders.
  • Track remediation progress and escalate blockers; ensure closure within SLAs.

Skills

Experience in App Security
Communication skills
Organizational skills
Independent work

Education

Security certifications (Security+, CSSLP, GWAPT, OSWE)

Tools

SAST tools
SCA tools
CI/CD security
Secure code reviews

Job description

Vulnerability Analysis & Risk Assessment
  • Review vulnerabilities identified through AI-based SAST, SCA, and related application security tools.
  • Evaluate vulnerabilities beyond vendor-assigned severity scores by considering:
  • Exposure
  • Business impact
  • Compensating controls
  • Application context
  • Distinguish between theoretical findings and vulnerabilities that present realistic risk to Guardian.
  • Validate vulnerability classifications and severity recommendations.
  • Identify false positives, duplicate findings, and opportunities for risk-based prioritization.
  • Ability to utilize AI to develop prompts to increase confidence in finding credibility and reduce false positives
  • Assess vulnerability trends and recurring development patterns requiring broader corrective action. These responsibilities align with Security Assurance practices for prioritizing realistic risks rather than relying solely on finding volume or scanner output
  • Explain findings clearly to developers, architects, technology owners, and business stakeholders.
  • Provide actionable remediation guidance and secure coding recommendations.
  • Assist application teams in understanding root causes and recommended fixes.
  • Partner with developers and technology owners to establish remediation plans.
  • Track remediation progress and follow up to ensure issues are resolved within Guardian-defined SLAs.
  • Escalate aging findings and remediation blockers as appropriate.
  • Support validation of completed remediation activities and closure recommendations. Remediation coordination and driving vulnerabilities through closure is a core expectation within Guardian's vulnerability management operating model.
Application Security Operations Support
  • Support vulnerability triage activities across multiple application security tools.
  • Participate in vulnerability review sessions and remediation discussions.
  • Contribute to documentation, procedures, and process improvements.
  • Identify opportunities to improve consistency, efficiency, and quality in vulnerability review processes.
  • Assist with application security reporting and stakeholder communications.
  • Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale. Security Assurance materials emphasize operational clarity, documentation, and repeatable processes that drive work to closure.
Required Qualifications
  • 3+ years of experience in Application Security, Vulnerability Management, Security Risk Management, or a related cybersecurity discipline.
  • Strong understanding of:
  • OWASP Top 10
  • Common software security weaknesses (CWEs)
  • Software vulnerability management practices
  • Experience interpreting and validating findings from application security tools.
  • Experience using AI Based Security Tools.
  • Ability to evaluate findings in the context of exploitability, exposure, and business risk rather than relying solely on CVSS scores.
  • Experience working directly with development teams to remediate vulnerabilities.
  • Strong written and verbal communication skills with the ability to translate technical findings into business-relevant language.
  • Strong organizational skills with the ability to manage multiple workstreams and remediation efforts simultaneously.
  • Demonstrated ability to work independently and drive outcomes with limited supervision. These qualifications align closely with Security Assurance expectations for reviewing technical findings, making risk-based decisions, and influencing remediation outcomes.
Required Technical Skills

Experience reviewing or working with applications developed in one or more of the following languages:

  • Java
  • TypeScript
  • C#
  • Python
  • Go
  • Node.js
  • Experience with one or more of the following is preferred:
  • SAST tools (SonarQube, Snyk Code, Checkmarx, Veracode, GitHub Advanced Security, etc.)
  • SCA tools and dependency risk analysis
  • CI/CD security integration
  • Secure coding reviews
Preferred Qualifications
  • Application security testing experience.
  • Secure code review experience.
  • Experience using Claude Code or related AI security testing tools.
  • Understanding of software architecture and common web application attack patterns.
  • Working knowledge of cloud-native applications and APIs.
  • Familiarity with vulnerability management processes and remediation tracking workflows.
  • Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, GWAPT, or similar.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Information Security Engineer
Senior Information Security Engineer

Jobtailor • Arizona

On-site
USD 120,000 - 190,000
AI-Driven Application Security & Risk Analyst
AI-Driven Application Security & Risk Analyst

Perennial Resources International • New York (NY)

On-site
USD 110,000 - 160,000
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

Infosys • Richardson (TX)

On-site
USD 110,000 - 170,000
Application Offensive Security Consultant
Application Offensive Security Consultant

StaffWorthy • Jersey City (NJ)

On-site
USD 90,000 - 120,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Application Security Specialist - AI Trainer
Application Security Specialist - AI Trainer

Mercor • Miami (FL)

On-site
USD 120,000 - 180,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Application Security Specialist - AI Trainer
Application Security Specialist - AI Trainer

Obsidian • Miami (FL)

On-site
USD 120,000 - 180,000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • Illinois

On-site
USD 120,000 - 180,000