CybersecurityJobs.io
← Back to all jobs

Job Description

The AWS Application Security Analyst supports application security efforts within a large-scale financial services environment. In a hybrid role based in Birmingham, AL, the position partners with software development, cloud, DevOps, and cybersecurity teams to identify, evaluate, and remediate security risks throughout the SDLC.

Responsibilities

  • Perform manual and automated application and source-code security reviews to identify vulnerabilities and security risks.
  • Lead threat modeling activities and conduct application security risk assessments for both new and existing applications.
  • Collaborate with development teams to select remediation approaches for security findings.
  • Use SAST, DAST, and Software Composition Analysis (SCA) tools to support application security testing.
  • Integrate application security controls and automated security testing into CI/CD pipelines.
  • Assess application security risk exposure across AWS cloud environments and containerized deployments.
  • Apply secure coding knowledge across areas such as network protocols, encryption, authentication, and common application vulnerabilities.
  • Strengthen DevSecOps practices across the SDLC through partnership with development, DevOps, cloud, and cybersecurity teams.
  • Create security guidance, FAQs, standards, and reusable application security best practices for development teams.
  • Communicate vulnerabilities, security risks, and remediation recommendations clearly to technical stakeholders.

Requirements

  • 5+ years of application security experience and strong knowledge of secure software development practices.
  • Hands-on experience with SAST, DAST, and SCA tooling.
  • Experience conducting manual code reviews and application security assessments.
  • Strong background in threat modeling and security risk assessments.
  • Working knowledge of AWS security practices and securing applications deployed in AWS environments.
  • Experience with DevSecOps, including integrating security testing into CI/CD pipelines.
  • Experience with GitHub, Jenkins, or comparable CI/CD platforms.
  • Understanding of container security and associated application security risks.
  • Programming or code-review experience with Java, Python, JavaScript, C#, or similar languages.
  • Strong understanding of network protocols, encryption, and authentication and authorization concepts.
  • Strong understanding of secure coding practices and common application vulnerabilities.
  • Effective communication skills to explain security findings and remediation recommendations to developers and technical teams.

Education

Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field.

Technology Focus

  • AWS
  • SAST, DAST, Software Composition Analysis (SCA)
  • CI/CD pipelines and DevSecOps
  • GitHub, Jenkins
  • Java, Python, JavaScript, C#
  • Container security

Salary and Location

Location: Birmingham, AL 35201 (hybrid).
Salary: USD 100,000 per year.

Benefits

  • Medical
  • Dental
  • Vision
  • Spending accounts
  • Life insurance
  • Voluntary plans
  • Participation in a 401(k) plan

Preferred Qualifications

  • Experience in financial services, banking, or another highly regulated environment.
  • Relevant security or cloud certifications such as AWS Certified Security – Specialty, CISSP, CSSLP, or GIAC Application Security certifications.

Similar Jobs