Principal Application Security Analyst
Application Security
Ci/cd Security
Cybersecurity Tools
Dynamic Application Security Testing
Information Security
InfoSec
Owasp
Risk Management
Secrets Scanning
Secure Software Development
Security
Security Standards
Security Testing
Software Security
Static Application Security Testing
Static Code Analysis
Job Description
The Principal Application Security Analyst will design and run WPS’s enterprise application security program with a focus on reducing application risk across the SDLC. This individual-contributor role sits within the Cyber Threat Management team and combines application security testing, triage, developer enablement, and risk-focused reporting.
Role Overview
This position builds and operates the enterprise Application Security program, using secure-development standards to improve application risk posture throughout the software development lifecycle. The analyst manages day-to-day application-security testing and triage, engages developers to support secure coding, and helps translate enterprise security requirements into practical testing criteria.
Key Responsibilities
- Build and operate WPS’s enterprise Application Security program to reduce application risk by operationalizing secure-development standards, strengthening developer secure-coding practices, running application-security testing tools, and reporting outcomes to technical, managerial, and executive audiences.
- Partner with Cyber Trust & Architecture to translate enterprise security standards into developer guidance and actionable testing criteria.
- Work independently with developers to interpret application security findings and communicate risk across multiple levels of the organization.
- Manage day-to-day application-security testing, triage, and developer engagement independently, while collaborating with Cyber Trust & Architecture on standards interpretation and with the Manager, Cyber Threat Management on program priorities.
- Operationalize secure-development standards by strengthening secure-coding practices, executing application-security testing using approved tooling, and providing reporting to technical, managerial, and executive stakeholders.
- Coordinate remediation of application vulnerabilities with developers and system owners, prioritize using actual exploitability and business risk, and validate fixes through retesting.
Required Qualifications
- U.S. Citizenship required due to Department of Defense restrictions.
- Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Systems, or a related field, or an equivalent combination of education and relevant work experience.
- 5 or more years of progressive experience in application security, software security, DevSecOps, or a related technical security discipline.
- Hands-on experience with application-security testing technologies such as SAST and DAST, including the ability to tune tools, independently validate findings, and translate cybersecurity standards and technical requirements into developer guidance and secure-coding training.
- Proficient knowledge of common application vulnerabilities and attack techniques, potentially including Authentication / Authorization, Injection, Session management, API security, insecure dependencies, and related topics.
- Knowledge of modern software development methodologies, CI/CD pipelines, APIs, and cloud-based application environments to integrate security testing into the development lifecycle.
- Strong analytical skills to distinguish exploitable vulnerabilities from false positives and prioritize remediation based on actual risk.
- Strong communication, problem solving, and decision-making skills.
- Wired (ethernet cable) internet connection from your router to your computer, with high speed cable or fiber and minimum internet performance of 10 Mbps downstream and 1 Mbps upstream (verifiable at https://speedtest.net).
- Please review Remote Worker FAQs: https://secure.wpsic.com/files/remote-work-faqs.pdf.
Preferred Qualifications
- Knowledge of OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and MITRE ATT&CK.
- Professional certification such as CSSLP, GWAPT, GWEB, or OSWE.
Technologies
- SAST, DAST, SCA
- API and secrets scanning
- CI/CD pipelines, APIs, cloud-based application environments
- OWASP Top 10, OWASP API Security Top 10, CWE, CVSS
- MITRE ATT&CK
- CSSLP, GWAPT, GWEB, OSWE
Work Location
- Hybrid work available; employees should live within the state of Wisconsin.
- Employees within 45 miles of WPS Headquarters (1717 W. Broadway in Madison, WI, 53713) are expected to work in office 3 days per week on a regular basis.
Compensation and Benefits
- Salary: USD 135,000 - 165,000 per yearly
- Remote and hybrid work options available
- Performance bonus and/or merit increase opportunities
- 401(k) with a 100% match for the first 3% of your salary and a 50% match for the next 2% of your salary (100% vested immediately)
- Competitive paid time off
- Health insurance, dental insurance, and telehealth services start DAY 1
- Professional and Leadership Development Programs
- Additional benefits available at: https://www.wpshealthsolutions.com/careers/
How You Know This Role Fits
- Operate, tune, and continuously improve enterprise application security testing capabilities (SAST, DAST, SCA, API and secrets scanning), distinguishing exploitable vulnerabilities from false positives and integrating testing into the development and CI/CD lifecycle.
- Translate enterprise application-security standards and secure-by-design requirements into practical developer guidance, testing criteria, and implementation practices across the software-development lifecycle with Cyber Trust & Architecture.
- Develop and deliver developer-focused secure-coding education using real vulnerability trends and hands-on guidance to help developers meet enterprise security standards.
- Create and maintain technical, managerial, and executive reporting that converts application-security findings, vulnerability trends, and standards adoption into actionable, risk-based information.
- Coordinate vulnerability remediation with developers and system owners by prioritizing based on exploitability and business risk, then validate fixes through retesting.
- Apply current threat intelligence and attacker techniques to application-security testing and priorities in partnership with Cyber Trust & Architecture, Cyber Risk & Assurance, and development teams.
Similar Jobs
A