AWS Application Security Analyst
Job Description
System One is hiring an AWS Application Security Analyst to support application security initiatives in a large-scale financial services environment. This hybrid role partners with software development, cloud, DevOps, and cybersecurity teams to identify, evaluate, and remediate security risks throughout the Software Development Lifecycle (SDLC).
In this position, you will apply hands-on application security testing and security engineering practices across AWS and containerized environments, helping teams strengthen DevSecOps workflows and improve secure software delivery.
Key Responsibilities
- Perform manual and automated application and source-code security reviews to uncover vulnerabilities and security risks.
- Lead threat modeling and application security risk assessments for both new and existing applications.
- Collaborate with development teams to select appropriate remediation approaches for security findings.
- Use SAST, DAST, and Software Composition Analysis (SCA) tools to support application security testing.
- Help integrate application security controls and automated security testing into CI/CD pipelines.
- Assess application security risks across AWS cloud and containerized environments.
- Apply secure coding knowledge covering network protocols, encryption, authentication, and common application vulnerabilities.
- Partner with development, DevOps, cloud, and cybersecurity teams to strengthen DevSecOps practices across the SDLC.
- Create security guidance such as FAQs, standards, and reusable application security best practices for development teams.
- Communicate vulnerabilities, security risks, and remediation recommendations clearly to technical stakeholders.
Required Qualifications
- 5+ years of application security experience and strong knowledge of secure software development practices.
- Hands-on experience with SAST, DAST, and SCA tools.
- Experience performing manual code reviews and application security assessments.
- Strong experience with threat modeling and security risk assessments.
- Working knowledge of AWS security and securing applications deployed in AWS environments.
- Experience with DevSecOps and integrating security testing into CI/CD pipelines.
- Experience with GitHub, Jenkins, or similar CI/CD platforms.
- Understanding of container security and related application security risks.
- Programming or code-review experience with Java, Python, JavaScript, C#, or similar languages.
- Strong understanding of network protocols, encryption, authentication and authorization, and secure coding practices.
- Strong understanding of common application vulnerabilities.
- Strong communication skills to explain security findings and remediation recommendations to developers and technical teams.
Technologies
- AWS
- SAST, DAST, Software Composition Analysis (SCA)
- CI/CD pipelines, DevSecOps
- GitHub, Jenkins
- Java, Python, JavaScript, C#
- Container security
- Network protocols, encryption, authentication and authorization
Preferred Qualifications
- Experience within financial services, banking, or other highly regulated environments.
- Relevant security or cloud certifications, such as AWS Certified Security – Specialty, CISSP, CSSLP, or GIAC Application Security certifications.
Role Details
- Location: Lafayette, LA (Hybrid)
- Other Locations: Birmingham, AL; Knoxville, TN; Columbia, SC; Lafayette, LA
- Salary: USD 116,000 per year
- Education: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field
- Job Type: Permanent Full-Time
- Work Model: Hybrid
- Visa: USC, GC, EAD (No Sponsorship)