Senior Application Security Analyst
Job Description
Protect data and applications by embedding application security controls across the SDLC in Microsoft Azure and hybrid or multi-cloud environments. This Senior Application Security Analyst role supports secure software development and compliance for WAHBE, with an emphasis on threat modeling, vulnerability management, secure coding guidance, and continuous validation through CI/CD.
What you’ll do
- Serve as a senior subject matter expert for application security across Microsoft Azure and cloud-native architectures, including hybrid and multi-cloud environments.
- Coordinate application security assessments, including code reviews aligned to WAHBE security policies, NIST, OWASP, and regulatory compliance (including CMS and IRS), with a focus on API and microservices security.
- Support implementation and continuous improvement of the Secure Software Development Lifecycle (SSDLC) by integrating security controls and best practices into development and deployment processes.
- Partner with Delivery, architects, and DevOps engineers to embed security throughout the SDLC, including participation in threat modeling, security requirement reviews, and architecture discussions.
- Review application and solution architectures to identify security weaknesses, attack surfaces, and insecure design patterns, and provide remediation recommendations.
- Conduct security design reviews for web applications, APIs, microservices, containers, and serverless technologies to support secure implementation practices.
- Develop, document, and enforce secure coding standards, secure design guidelines, and application security procedures to promote consistent and secure development.
- Enhance and lead the Application Security and Penetration Testing program, including security and penetration testing and integrating automated security testing into CI/CD.
- Perform vulnerability triage, validation, and risk analysis using security tools, threat intelligence, and manual analysis, including false-positive review and remediation prioritization.
- Track remediation activities and work with development teams to support timely resolution or appropriate risk acceptance documentation; recommend compensating controls when needed.
- Support monitoring and reporting by preparing vulnerability metrics, remediation status updates, trend analysis, and risk reports for leadership and stakeholders.
- Develop and deliver secure coding awareness sessions and application security training materials for development and engineering teams.
- Review Requests for Change (RFCs), product enhancements, and system modifications from a security perspective to ensure impacts and requirements are addressed.
- Continuously monitor cloud and on-premises environments for security events and anomalies, investigate root causes and impacts, support containment and recovery, and contribute to incident reports including post-incident analysis and lessons learned.
- Collaborate with Compliance, Risk Management, Audit, Infrastructure Security, and DevOps teams to support audits, regulatory compliance, and secure cloud adoption initiatives; ensure alignment with WAHBE security policies (including CMS and IRS).
- Ensure security requirements are included in user stories and case development within Agile methodology (including misuse, abuse, and confuse cases).
- Assess the security posture of new enterprise solutions for procurement by identifying security risks and providing secure cloud adoption guidance.
- Provide technical consultation and assessments for cloud environments and containers, and help integrate application security into CI/CD as part of SSDLC, enforcing security in deployment workflows.
- Assist in maintaining and updating security policies, procedures, and standards, support roadmap and strategy with the Application Security Lead, provide regular briefings, and stay current on emerging threats and technologies.
What you bring
- Seven (7) years of information security experience in specialized roles such as security architecture and design, security control implementation, penetration testing, application security, vulnerability management, or incident response.
- Knowledge of secure SDLC, secure architecture design, application security concepts, and cloud architecture, including DevSecOps practices and shift-left security integration.
- Experience performing application security code reviews, roles and permissions matrix reviews, and practical application risk assessments using manual and automated secure code review methods.
- Hands-on experience with vulnerability assessment tools including Nessus, Rapid7, Nmap, and Burp Suite, including SAST, DAST, and SCA.
- Advanced understanding of application-layer attacks, API abuse, and software supply chain vulnerabilities.
- Ability to apply strong analytical and problem-solving skills in complex scenarios.
- Experience integrating security in infrastructure-as-code, CI/CD pipelines, and the software development lifecycle, including automated controls, continuous monitoring, security gates, and pipeline enforcement policies.
- Interpersonal and collaboration skills with internal teams and external partners and vendors.
Technologies and standards you’ll work with
Microsoft Azure, cloud-native architectures, NIST, OWASP, CMS, IRS, Nessus, Rapid7, Nmap, Burp Suite, SAST, DAST, SCA, CI/CD, SSDLC, DevSecOps, infrastructure-as-code, and Agile.
Helpful background (desired)
- Bachelor’s degree in engineering, security, or a technology-related field.
- Experience with application security methodologies such as OWASP.
- Experience in information security, data security, privacy, and data management, including secure handling of PII, application-level encryption, and key management.
- Experience defining secure architectural requirements, security controls, and configuration standards in alignment with regulatory requirements.
- Experience with threat modeling frameworks such as STRIDE and MITRE ATT&CK, including application-specific threat modeling, attack path analysis, and abuse case analysis.
- Experience developing and updating security standards, procedures, awareness, and training programs, including secure coding standards and developer training.
- Understanding of SIEM systems and Endpoint Detection & Response.
- Experience managing cyber incident response, including coordination with development teams for rapid patching and hotfix deployment.
Working conditions
- Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday, with times requiring irregular hours.
- Preferred duty station is Olympia, Washington headquarters with remote and in-person collaboration.
- A hybrid remote and on-site schedule may be considered, but flexibility is required for in-office availability.
- Travel is limited, with occasional trips and irregular hours for meetings or trainings.
- Role requires standard office equipment, including setup for remote work, and responsibility for maintaining a safe, ergonomic, and secure workspace.
Special requirements and salary
- A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained. Results must meet Exchanges eligibility standards.
- Salary: Full range $98,842 to $148,263 per year (midpoint $123,552). Hiring range $113,668 to $123,552 per year.
Similar Jobs
A