Application Security Analyst
Application Security
Asvs
Cloud Platforms
Cybersecurity Tools
Data Analysis
DevSecOps
Dynamic Application Security Testing
Information Security
Information Technology (IT)
InfoSec
Iso 27017
Java Language
Owasp
Owasp Top Ten
Programming Languages
Risk Governance
Risk Management
Security
Security Compliance
Security Standards
Security Testing
Software Security
Solution Architecture
Static Application Security Testing
Vulnerability Assessment
Job Description
DHL eCommerce is seeking an Analytical and advisory Application Security Analyst to help secure homegrown and third-party applications, including cloud and AI solutions. This remote role emphasizes transparent risk reporting to IT leadership and close collaboration with the DevSecOps team, with independent review of security test results to guide remediation efforts.
Overview
- Location: Remote
- Salary: USD 63,300 - 101,100 per year
- Minimum experience: 3 years
- Education: Bachelor's degree in information technology or related field
Responsibilities
- Evaluate security architecture for systems, applications, and infrastructure across the lifecycle in both traditional and cloud environments, and provide guidance.
- Document and enhance security and DevSecOps procedures and the supporting documentation requirements.
- Review security test outputs, including SAST, DAST, and penetration tests, with a focus on the OWASP Top 10, and translate findings into actionable steps.
- Record test results and residual risks in the GRC tool and present findings to the Director of IT Security and leadership.
- Integrate industry best practices with organizational specifics to craft security solutions.
- Assist developers in identifying, understanding, and implementing remediation measures.
- Support the development of application security concepts and conduct security reviews.
- Participate in security assessments of AI solutions, validating guardrails and compliance.
- Contribute to security audits and security testing activities.
- Support risk management and vulnerability management processes.
Requirements
- Knowledge of OWASP Top 10 and ASVS frameworks with best practice implementations.
- Experience in cloud security and AI security standards, including ISO 27017, CSA CCM, NIST AI RMF, ISO 42001, and related practices.
- Ability to interpret multiple programming languages, including Python, Java, ReAct, and JavaScript, among others.
- Strong organizational and analytical skills.
- Capability to analyze data, draw conclusions, interpret results, and make IT-related recommendations.
- Effective communication with all management levels.
- Ability to operate effectively in a global environment with cultural awareness.
- Proven ability to deliver high-quality work under tight deadlines.
- Excellent written, oral, and interpersonal communication skills.
- Solid Microsoft Office proficiency (Word, Excel, PowerPoint).
- Strong attention to detail and multi-tasking capability.
Technologies
- Python
- Java
- ReAct
- JavaScript
- OWASP Top 10
- ASVS
- ISO 27017
- CSA CCM
- NIST AI RMF
- ISO 42001
- SAST
- DAST
- Microsoft Office
Benefits
- Competitive Pay
- Bonus Programs
- Retirement Savings - 401k with company match
- Medical, Dental, Vision, Well-being programs
- FSA/HSA availability
- Tuition Reimbursement
- Paid Time Off including vacation and sick time
- Company Paid Holidays and Floating Holidays
- Paid Parental Leave
- Employee Discount Program
- Employee Assistance & Work Life Program
- Short Term and Long-Term Disability
- Life Insurance
Physical Demands
- Available for on-call support as required
- Travel to remote sites as required (up to 20%)
- Regular sitting at a workstation for 25β75% of the shift
- Frequent standing and walking