Senior Cloud Application Security Analyst

PowerPlan, Inc.

Atlanta (GA)

Hybrid

USD 110,000 - 160,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) or equivalent

Job summary

PowerPlan seeks a Senior Security Analyst / AppSec Specialist to strengthen our application security posture in a hands-on, high-impact role within Information Security & Compliance. You will partner with DevOps, product, and compliance teams to advance vulnerability management maturity across our cloud-hosted SaaS environment.

Responsibilities include implementing a centralized vulnerability management platform, coordinating annual penetration testing, and driving NIST CSF 2.0 maturity with

Qualifications

  • Hands-on AppSec experience in a SaaS environment.
  • Experience with vulnerability management life cycle and tooling.
  • Strong knowledge of security controls and threat modeling.
  • Experience coordinating penetration tests and managing findings.
  • Excellent cross-functional communication and documentation.
  • Familiarity with SOC 2, ISO 27001 and NIST CSF 2.0.

Responsibilities

  • Implement a centralized application vulnerability management platform within 120 days.
  • Lead annual application and cloud penetration testing program.
  • Establish standardized security architecture review processes.
  • Drive measurable maturity improvements aligned to NIST CSF 2.0.
  • Strengthen cross-functional security collaboration across Dev, CloudOps, IT & compliance.

Skills

AppSec expertise
SAST/DAST/SCA
Pen-testing coordination
Vulnerability management
CrowdStrike
Qualys
Rapid7
Cloud security (AWS/Azure)
Threat modeling
Architecture reviews
SOC 2 / ISO 27001 / NIST CSF 2.0
Security communication

Education

Bachelor’s degree or higher in CS/InfoSec or related field

Tools

DefectDojo

Job description

PowerPlan is looking for every opportunity to help our customers and prospects gain more value from our suite of software solutions. We are seeking a Senior Security Analyst / AppSec Specialist to join our Information Security & Compliance team. This is a hands‑on, high‑impact role responsible for strengthening our application security posture, driving vulnerability management maturity, and supporting security operations across our cloud‑hosted SaaS environment. The successful candidate will serve as a technical security practitioner embedded within our engineering and operations ecosystem, partnering closely with DevOps, product, and compliance teams.

To be successful in this role, you should have extensive experience with CrowdStrike Falcon, including its Next‑Gen SIEM, Data Protection, CSPM, and Threat Intelligence capabilities, as well as experience coordinating penetration tests and running vulnerability assessments with Qualys. You should have hands‑on experience with Rapid7, CI/CD pipeline hardening, cloud security in AWS and/or Azure, and security architecture. Experience implementing process improvements and driving program maturity aligned with NIST CSF 2.0 is essential. You should also have excellent communication, problem‑solving, and analytical skills, as well as the ability to work independently and as part of a team.

Company

PowerPlan specializes in enterprise software solutions used by organizations with complex financial, regulatory, and operational needs. We deliver secure, cloud‑hosted SaaS products that help customers manage critical workflows with accuracy, transparency, and compliance.

The security team plays a central role in protecting customer trust, enabling rapid product innovation, and ensuring alignment with frameworks such as SOC 2, ISO 27001, and NIST CSF 2.0. We operate in a collaborative environment that values technical depth, continuous improvement, and responsible innovation.

KEY PERFORMANCE OBJECTIVES (First 12 Months)
OBJECTIVE 1 Implement a Centralized Application Vulnerability Management Platform (First 120 Days)
Outcome

Deploy a consolidated platform (e.g., DefectDojo) that aggregates SAST, DAST, SCA, penetration‑testing, and manual‑review findings within 120 days. Ensure all engineering teams have visibility into normalized, prioritized findings, with assignment and SLA workflows in place. Produce monthly reports showing coverage, SLA adherence, and remediation progress.

Impact

Provides a “single pane of glass” that enables consistent prioritization, eliminates fragmented tooling silos, and measurably reduces MTTR for application vulnerabilities. Improves audit readiness and strengthens engineering alignment by creating a unified source of truth for risk decisions.

How

Evaluate and implement the platform, integrate scanning tools and pen‑test reports, configure cross‑team workflows, onboard engineering groups, define remediation SLAs, and publish monthly dashboards to engineering and security leadership.

OBJECTIVE 2 Lead the Annual Application + Cloud Penetration Testing Program (Annual Cycle)
Outcome

Coordinate annual penetration testing for web applications, APIs, and cloud environments; ensure final reports are processed within 30 days. Track remediation and retesting and ensure all critical/high‑risk findings are addressed within SLA. Maintain audit‑ready documentation for compliance teams.

Impact

Ensures independent validation of application and cloud security posture, reduces exploitable weaknesses, and directly supports SOC 2 and ISO 27001 evidence requirements. Builds leadership confidence through measurable remediation accountability.

How

Manage vendor selection and scoping, coordinate technical access and test data, review findings, facilitate engineering remediation, validate fixes, capture evidence, and update Confluence with all required artifacts and timelines.

OBJECTIVE 3 Implement a Standardized Security Architecture Review Process (First 120 Days)
Outcome

Establish and operationalize a design‑review process for all major new product features and third‑party integrations within 120 days. Produce documented review artifacts, identified risks, and required remediation actions for development teams. Ensure findings are incorporated before release.

Impact

Reduces late‑cycle rework, prevents design‑level security gaps, and embeds security as a natural part of the product development lifecycle. Improves release confidence and accelerate secure deployment across the SaaS platform.

How

Create templates, facilitate threat‑model discussions (e.g., STRIDE), review integration risks, track remediation items, collaborate with engineering leads, and maintain documented review outcomes in shared repositories.

OBJECTIVE 4 Drive Measurable Maturity Improvements Aligned to NIST CSF 2.0 (First 12 Months)
Outcome

Deliver measurable improvements across NIST CSF functions through documented workflows, baseline control assessments, performance metrics, and quarterly KPI reporting. Create repeatable processes and audit‑ready artifacts across Identify, Protect, Detect, Respond, and Recover.

Impact

Strengthens the formal structure and reliability of the security program, reduces operational and compliance risk, and enhances readiness for SOC 2 and ISO 27001 by demonstrating consistent, evidence‑based maturity growth.

How

Assess current control gaps, standardize repeatable workflows, document runbooks and procedures, collaborate with engineering and compliance, automate where practical, and present quarterly maturity dashboards.

OBJECTIVE 5 Strengthen Cross‑Functional Collaboration Across Dev, CloudOps, IT & Compliance (First 6-9 Months)
Outcome

Implement recurring cross‑team security syncs, remediation checkpoints, and shared KPI dashboards. Drive measurable improvements in SLA adherence, cloud misconfiguration reduction, recurring‑vulnerability prevention, and overall operational alignment.

Impact

Builds unified, organization‑wide ownership of security responsibilities, accelerates remediation cycles, and reduces risk introduced by siloed decisions or inconsistent practices.

How

Establish communication cadences, run joint review sessions, align remediation expectations, publish shared dashboards, and deliver clear visibility to leadership on cross‑team security performance.

What You Bring
  • Hands on experience with application security scanning (SAST/DAST/SCA), pen‑testing coordination, and vulnerability management platforms.
  • Strong working knowledge of CrowdStrike, Qualys, and/or Rapid7.
  • Cloud security experience in AWS and/or Azure, including IAM, logging, and posture management.
  • Experience performing or facilitating threat modeling and architecture reviews.
  • Familiarity with SOC 2, ISO 27001, and NIST CSF 2.0.
  • Strong analytical, communication, and documentation skills.
  • Ability to partner effectively across engineering, DevOps, CloudOps, IT, and compliance teams.
  • Demonstrated ability to drive process maturity and measurable improvements.

PowerPlan is an EOE”

Applicant and Candidate Privacy Notice

Please note that this is a hybrid role that involves a combination of onsite work from our corporate office as well as work from home. While we strive to accommodate flexible working arrangements when sensible, there will be times when onsite work is required. This could include scheduled office days, team meetings, client meetings, or special events.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer, Application Security (Remote)
Product Security Engineer, Application Security (Remote)

CrowdStrike • United States

On-site
USD 120,000 - 180,000
Market-leading compensation
Wellness programs
PTO & holidays
+4
Senior Product Security Engineer, Application Security (Remote)
Senior Product Security Engineer, Application Security (Remote)

CrowdStrike • United States

On-site
USD 160,000 - 250,000
Security Operations Engineer
Security Operations Engineer

Compunnel, Inc. • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Senior Cloud AppSec Analyst - Vulnerability & Cloud Security
Senior Cloud AppSec Analyst - Vulnerability & Cloud Security

PowerPlan, Inc. • Atlanta (GA)

Hybrid
USD 110,000 - 160,000
Health insurance
401(k) or equivalent
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Security Program Lead
Senior Security Program Lead

GlobalSource IT • Columbia (SC)

On-site
USD 90,000 - 120,000
Competitive compensation
Professional growth opportunities
Collaborative team environment
+1
Senior Manager - Cloud Security Engineer (CrowdStrike) at Confidential United States
Senior Manager - Cloud Security Engineer (CrowdStrike) at Confidential United States

Fairweather, LLC • United States

On-site
USD 150,000 - 200,000
Healthcare Coverage
401(k) Matching
Generous PTO
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Competitive salary
Health benefits
Company cell phone plan
+2
Platform Professional Services Sr. Consultant- Cloud (Remote)
Platform Professional Services Sr. Consultant- Cloud (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 110,000 - 190,000
Equity awards
Wellness programs
Paid time off
+4
Senior Application Security Architect
Senior Application Security Architect

Payactiv • Milpitas (CA)

On-site
USD 130,000 - 160,000
Health, Dental, and Vision insurance
401(k) with company match
Unlimited Paid Time Off
+2