Senior Application Security Analyst

State of Washington

Olympia (WA)

On-site

USD 99,000 - 148,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Washington Health Benefit Exchange is seeking a Senior Application Security Analyst to protect data and applications by integrating security controls across SDLC in cloud and on-prem environments. This role collaborates with delivery teams, DevOps, and vendors to implement secure practices.

The position conducts risk assessments, performs code reviews, and helps advance SSDLC with automated controls and secure coding standards.

Qualifications

  • Seven (7) years of information security experience in specialized roles.
  • Experience with secure SDLC and cloud-architecture including DevSecOps.

Responsibilities

  • Identify and mitigate application security risks.
  • Support incident response activities and remediation guidance.
  • Promote secure coding practices and SSDLC adoption.

Skills

Security architecture
Threat modeling
Vulnerability management
Code reviews
Security in CI/CD

Education

Bachelor's degree in engineering or security

Tools

Nessus
Rapid7
Nmap
Burp Suite

Job description

The mission of Washington Health Benefit Exchange (Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical solutions, an easy-to-use customer experience, our values of integrity, respect, equity and transparency, and by providing undeniable value to the health care community.

The Exchange is a public-private partnership that operates Washington Healthplanfinder, the eligibility and enrollment portal used by one in four Washington residents to obtain health and dental coverage. Through this platform, and with support from a Customer Support Center and statewide network of in-person navigators and brokers, individuals and families can shop, compare and enroll in private, qualified health plans (as defined in the Affordable Care Act) or enroll in Washington Apple Health, the state Medicaid program.

The Exchange embraces the following equity statement adopted by our Board of Directors:

Equity is fundamental to the mission of the Washington Health Benefit Exchange. The process of advancing toward equity and becoming anti-racist is disruptive and demands vigilance to dismantle deeply entrenched systems of privilege and oppression. While systemic racism is a root cause of many societal inequities, we must also use an intersectional approach to address all forms of bias and oppression, which interact with and often exacerbate racial inequities. To be successful, we must recognize the socioeconomic drivers of health and focus on people and places where needs are greatest. As we listen to community, we must hold ourselves accountable to responding to recommendations to remedy inequitable policies, systems, or practices within the Exchange’s area of influence. Our goal is that all Washingtonians have full and equal access to opportunities, power and resources to achieve their full potential.

SUMMARY

The Senior Application Security Analyst plays a key role in protecting WAHBE’s data and applications by ensuring security controls are effectively integrated throughout the Software Development Lifecycle (SDLC) across both cloud and on-premises environments. Operating under the guidance of the Application Security Lead, this role serves as a senior technical contributor and collaborates closely with delivery teams, DevOps, architects, IT, and external partners to implement and sustain secure software development practices.

This position is responsible for executing application security assessments, threat modeling, and vulnerability management, while supporting risk assessments and ensuring alignment with WAHBE’s security policies and regulatory requirements. The Senior Application Security Analyst helps drive the adoption and continuous improvement of the Secure Software Development Lifecycle (SSDLC) by integrating automated security controls, conducting code reviews, and promoting secure coding standards.

Key responsibilities include identifying and mitigating application security risks, supporting incident response activities, and providing actionable guidance to delivery teams for remediation. The role also contributes to strengthening overall application security posture by addressing emerging threats, supporting compliance efforts, and ensuring security best practices are consistently applied across the organization.

Required:
  • Seven (7) years of information security experience in specialized roles such as, but not limited to security architecture and design, security control implementation penetration testing, application security, vulnerability management, incident response
  • Demonstrated knowledge of secure SDLC, secure architecture design, application security concepts, and cloud- architecture including DevSecOps practices and shift-left security integration
  • Experience performing application security code reviews, roles and permissions matrix reviews, and practical application risk assessments, including manual and automated secure code reviews
  • Experience working with common vulnerability assessment tools such as Nessus, Rapid7, Nmap, and Burp Suite, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools
  • Advanced understanding of emerging cybersecurity threats, including application-layer attacks, API abuse, and software supply chain vulnerabilities
  • Strong analytical and problem-solving skills with the ability to “think outside the box”
  • Experience integrating security in infrastructure-as-code, CI/CD pipelines, and the software development lifecycle, including implementation of automated controls and continuous monitoring and security gates and pipeline enforcement policies
  • Demonstrates strong interpersonal and collaboration skills, effectively partnering with internal management, staff, and cross-functional teams as well as external partners and vendors
Desired:
  • Bachelor’s degree in engineering, security or a technology related or closely allied field
  • Experience working with application security methodologies such as OWASP
  • Demonstrated experience in information security, data security, privacy, and data management, including secure handling of Personally Identifiable Information (PII), application-level encryption, and key management
  • Experience defining secure architectural requirements, security controls, and configuration standards in compliance with regulatory requirements
  • Experience working with threat modeling frameworks such as STRIDE and MITRE ATT&CK, including application-specific threat modeling, attack path analysis, and abuse case analysis
  • Experience developing, reviewing, and updating security standards, procedures, awareness and training, including secure coding standards and developer training programs
  • Demonstrates a solid understanding of the functions and operations of Security Information and Event Management (SIEM) systems, Endpoint Detection & Response
  • Demonstrated experience in managing cyber incident response, including coordination with development teams for rapid patching and hotfix deployment
  • Advanced understanding of emerging cybersecurity threats, including application-layer attacks, API abuse, and software supply chain vulnerabilities
SALARY INFORMATION

Full Salary Range: $98,842.00 to $148,263.00 annually, with midpoint at $123,552.00.

Hiring Range: $113,668.00 and $123,552.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer.

The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum.

BENEFITS

Take a peek at our benefits package.

WORKING CONDITIONS

Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in-person collaboration. While a hybrid remote and on-site schedule may be considered, the position will require flexibility to allow for in-office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location.

The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

SPECIAL REQUIREMENTS

A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The result of this background screen must meet the Exchanges eligibility standards.

OTHER INFORMATION

The above statements are intended to describe the general nature and levels of work being performed. They are not intended to be construed as an exhaustive list of responsibilities, duties and skills of personnel so classified.

This is not an employment agreement or contract. Management has the exclusive right to alter this job description at any time without notice.

The Washington Health Benefit Exchange is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, marital status, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

We participate in E-Verify. You can view the Department of Justice's Right to Work poster here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Washington Department of Natural Resources • Washington

Hybrid
USD 113,000 - 124,000
Comprehensive benefits package
Flexible work schedule
Professional development opportunities
Senior Power BI Engineer
Senior Power BI Engineer

State of Washington • Olympia (WA)

Hybrid
USD 90,000 - 135,000
Chief Financial Officer at Washington Health Benefit Exchange Olympia, WA
Chief Financial Officer at Washington Health Benefit Exchange Olympia, WA

Shell Lubricants Hub Hamburg • Olympia (WA)

On-site
USD 175,000 - 230,000
Comprehensive benefits package
Senior Security Engineer – Secure SDLC
Senior Security Engineer – Secure SDLC

Highmark Health • Nashville (TN)

On-site
USD 103,000 - 165,000
Senior Security Engineer – Secure SDLC
Senior Security Engineer – Secure SDLC

Highmark Health • Jackson (MS)

On-site
USD 103,000 - 165,000
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Frankfort (KY)

On-site
USD 86,400 - 138,600
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Boise (ID)

On-site
USD 86,400 - 138,600
Health insurance
Training and professional development
Flexible work arrangements
Lead Cyber Security Analyst
Lead Cyber Security Analyst

University of Washington • Seattle (WA)

On-site
USD 135,000 - 160,008
Security Engineer
Security Engineer

emergemarket.com • Renton (WA), Northern (KY)

On-site
USD 97,000 - 158,000
Medical, Dental, and Vision
HSA / FSA
Life Insurance / AD&D
+3
Information Security Sr. Advisor, PAM
Information Security Sr. Advisor, PAM

Elevance Health • Indianapolis (IN)

Hybrid
USD 140,000 - 190,000