IT Application Security Analyst
Job Description
Scandinavian Tobacco Group is looking for an IT Application Security Analyst to embed security-by-design across the enterprise SDLC. This onsite role in Bethlehem, PA partners closely with development, DevOps, QA, and IT Operations to improve application security maturity through standards, tooling, automation, and practical guidance. If you want a position where you can turn secure development expectations into day-to-day workflows, this role is built for that.
As an Application Security Analyst, you will help shape secure development standards aligned to key frameworks and regulations, integrate SAST, DAST, and SCA tooling into CI/CD, and ensure vulnerabilities are actionable and routed into remediation. You will also support threat modeling, secure design and code review practices, and incident response investigations when security issues arise.
Responsibilities
- Assess and continuously improve SDLC processes, tools, and release workflows from a security perspective.
- Conduct gap analyses against secure development frameworks including NIST SSDF and OWASP ASVS.
- Define, maintain, and evolve secure development standards and procedures aligned with PCI DSS and CCPA/GDPR.
- Partner with engineering teams to recommend and implement practical security improvements across the SDLC.
- Embed security controls across planning, design, coding, testing, deployment, and maintenance.
- Deliver threat modeling, secure design guidance, and application architecture reviews.
- Establish and support secure design and code review practices, coaching developers on security best practices.
- Balance security requirements with developer experience and business requirements to reduce friction while increasing security maturity.
- Implement, operate, and optimize application security tooling including SAST, DAST, and SCA solutions.
- Integrate security tooling (e.g., Snyk, Checkmarx) into CI/CD pipelines for automated vulnerability detection.
- Define and enforce security gates or holds at key points within development and release workflows.
- Ensure vulnerability findings are actionable, prioritized, and integrated into remediation processes.
- Support static, dynamic, and penetration testing activities in partnership with internal and external resources.
- Integrate vulnerability management, continuous monitoring, and remediation tracking into the SDLC.
- Provide application security support during security incidents, assisting teams with investigation and remediation.
- Support secure platform and environment modernization efforts, including container security, OS hardening, and secrets management (e.g., Vault, Azure Key Vault).
- Contribute to application and platform architecture improvements focused on security, stability, and resilience.
Requirements
- 3+ years of experience in Application Security or Software Engineering with a focus on secure development practices.
- Hands-on experience implementing secure SDLC frameworks such as NIST SSDF and OWASP ASVS.
- Practical experience integrating SAST/DAST tools into CI/CD pipelines and workflows.
- Working knowledge of PCI DSS and privacy regulations (CCPA/GDPR) as they impact software development.
- Strong communication skills with the ability to influence and collaborate with engineering teams.
Technologies
NIST SSDF, OWASP ASVS, PCI DSS, CCPA/GDPR, SAST, DAST, SCA, Snyk, Checkmarx, Vault, Azure Key Vault, CI/CD, container security, OS hardening
Benefits
- Comprehensive Health Care, Vision & Dental Plan
- Flexible Spending Account
- Disability Plans
- Basic & Supplemental Life Insurance
- Additional Supplemental Benefits
- Paid Vacation, Paid Time Off (PTO) days, Holidays
- 401(k) Retirement Saving Plan including a generous Company match
Preferred Qualifications
- Experience with container security, image hardening, and secrets management technologies.
- Familiarity with the OWASP Top 10, API security, and modern application security practices.
- Experience coordinating or supporting penetration testing or DAST programs.
- Relevant certifications such as CSSLP, CISSP, GWAPT, GCSA, or similar.
Direct Search Notice: This Direct Search is conducted exclusively by Scandinavian Tobacco Group. Applications from agencies are not accepted, and compensation will not be provided for unsolicited CVs.
Visa Sponsorship: This position does not offer Visa sponsorship. Candidates must have valid work authorization in the United States, and only qualified candidates will be contacted.
Compensation: USD 125,000 - 135,000 per year.