Security Analyst

ASM Research, An Accenture Federal Services Company

Boston (MA)

On-site

USD 85,000 - 95,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ASM Research, An Accenture Federal Services Company, seeks a Security Analyst to weave application security into the software development lifecycle for enterprise and mission-critical systems. You will work with software engineering, architecture, DevOps, operations, and stakeholders to translate security requirements into practical design, development, testing, deployment, and remediation.

The role emphasizes security reviews, threat modeling, vulnerability management, and secure-development

Qualifications

  • Bachelor’s degree in CS, engineering, or equivalent experience.
  • Typically 5–10 years in application security or related cybersecurity.
  • Experience applying secure SDLC practices including threat modeling and architecture reviews.
  • Experience assessing vulnerabilities in web apps, APIs, cloud workloads, and infrastructure.
  • Ability to interpret and communicate findings from security testing and vulnerability scans.
  • Strong vulnerability triage, risk scoring, and remediation tracking.
  • U.S. citizenship with ability to obtain a Public Trust background.

Responsibilities

  • Integrate application security requirements across planning, development, testing, deployment, and maintenance of SDLC.
  • Conduct security architecture reviews, threat modeling, secure design reviews, and vulnerability assessments.
  • Analyze findings from SAST, DAST, SCA, dependencies, secrets, container scans, and pen tests.
  • Partner with DevOps, architecture, and operations to mitigate risks with actionable steps.
  • Perform secure code reviews and assess for auth weaknesses and misconfigurations.
  • Track vulnerabilities and remediation actions through closure and retesting.
  • Develop security procedures, standards, and risk communications for informed decisions.
  • Evaluate security tools for CI/CD integration and coverage.

Skills

Threat modeling
Secure SDLC
Architecture review
Security testing
Vulnerability assessment
Communication findings
CI/CD security
Cloud security

Education

Bachelor's degree in CS/engineering or equivalent
5–10 years in application security or related field

Tools

SAST
DAST
SCA
Dependency scanning
Secrets scanning
Container scanning
Penetration testing

Job description

The Security Analyst integrates application security practices throughout the software development life cycle for enterprise and mission-critical systems. The role partners with software engineering, architecture, DevOps, operations, and client stakeholders to translate security requirements into practical design, development, testing, deployment, and remediation activities.

The Security Analyst conducts security architecture and design reviews, vulnerability assessments, and technical risk analyses; interprets findings; and guides application owners through prioritized mitigation and validation. The role also develops and enforces secure-development procedures, evaluates security tools and automation, and strengthens the organization’s application security posture in a highly regulated federal IT environment.

Key Responsibilities
  • Integrate application security requirements, secure design practices, and security acceptance criteria across planning, development, testing, deployment, and maintenance phases of the software development life cycle.

  • Conduct and support security architecture reviews, threat modeling, secure design reviews, and vulnerability assessments for web applications, APIs, cloud-hosted workloads, services, and supporting infrastructure.

  • Analyze findings from static application security testing, dynamic application security testing, software composition analysis, dependency scanning, secrets scanning, container scanning, and penetration testing to determine risk and remediation priority.

  • Partner with development, DevOps, architecture, and operations teams to identify security risks, explain vulnerabilities, and provide practical, actionable mitigation recommendations.

  • Perform or support secure code reviews and assess applications for authentication and authorization weaknesses, insecure configurations, secrets exposure, common software weaknesses, and other security control gaps.

  • Track vulnerabilities and corrective actions through remediation, validate evidence of closure, and perform retesting as needed to confirm risk reduction.

  • Develop and maintain security procedures, technical standards, assessment reports, and risk communications that support informed authorization, remediation, and stakeholder decisions.

  • Evaluate application-security products and developer-facing tools for coverage, integration feasibility, operational impact, reporting quality, and compatibility with source-control and CI/CD workflows.

Required Qualifications
  • Bachelor’s degree in Computer Science, Engineering, or another technical discipline, or equivalent relevant experience.

  • Typically 5–10 years of progressively responsible experience in application security, secure software engineering, vulnerability management, or a closely related cybersecurity discipline.

  • Demonstrated experience applying secure SDLC practices, including security requirements definition, threat modeling, architecture review, secure design patterns, and security acceptance criteria.

  • Experience assessing web applications, APIs, services, cloud-hosted workloads, and supporting infrastructure for vulnerabilities, insecure configurations, identity and access control weaknesses, and software security risks.

  • Ability to interpret, prioritize, and communicate findings from application-security testing, vulnerability scanning, dependency analysis, secrets scanning, container scanning, and penetration testing.

  • Strong working knowledge of vulnerability triage, risk scoring, exploitability analysis, compensating controls, remediation tracking, and validation of corrective actions.

  • U.S. citizenship is required, with the ability to obtain and maintain a Public Trust background investigation.

Preferred Qualifications
  • Professional security certification such as CSSLP, Security+, CISSP, a GIAC application-security credential, or a cloud-security certification.

  • Experience embedding automated security controls, policy gates, and scan-result workflows into CI/CD pipelines and infrastructure-as-code delivery processes.

  • Experience supporting application security activities within a highly regulated federal, defense, or government environment.

  • Experience conducting secure architecture reviews, applying threat-modeling methods, and remediating OWASP-aligned application-security risks.

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties" or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

$85,000 – $95,000

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

ASM Research, An Accenture Federal Services Company • Des Moines (IA)

On-site
USD 85,000 - 95,000
Security Analyst
Security Analyst

ASM Research, An Accenture Federal Services Company • Montgomery (AL)

On-site
USD 85,000 - 95,000
Security Analyst
Security Analyst

ASM Research, An Accenture Federal Services Company • Providence (RI)

On-site
USD 85,000 - 95,000
Security Analyst
Security Analyst

ASM Research, An Accenture Federal Services Company • Sacramento (CA)

On-site
USD 85,000 - 95,000
Security Analyst
Security Analyst

ASM Research, An Accenture Federal Services Company • Bismarck (ND)

On-site
USD 85,000 - 95,000
Security Analyst
Security Analyst

ASM Research, An Accenture Federal Services Company • Raleigh (NC)

On-site
USD 85,000 - 95,000
Security Analyst
Security Analyst

ASM Research, An Accenture Federal Services Company • Charleston (WV)

On-site
USD 85,000 - 95,000
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr

ASM Research, An Accenture Federal Services Company • Providence (RI)

On-site
USD 80,000 - 111,000
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr

ASM Research, An Accenture Federal Services Company • Pierre (SD)

On-site
USD 80,000 - 111,000
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr

ASM Research, An Accenture Federal Services Company • Boston (MA)

On-site
USD 80,000 - 111,000