Application Security Analyst in Abbeyville, Colorado at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Analyst based in the United States.
This is a hands-on application security role within a small and growing information security team.
You’ll help embed security throughout the software development lifecycle, from code scanning and threat modeling to CI/CD and runtime protections.
The role combines application security, cloud security, identity, API protection, and emerging AI/ML security challenges.
You’ll work closely with engineering teams to identify vulnerabilities, prioritize risks, and drive practical remediation.
You’ll also contribute to security automation, incident response, and audit readiness in regulated environments.
Because the team is lean, you’ll have broad ownership and the opportunity to take on diverse security challenges.
This role is ideal for a security-minded professional who enjoys building, problem-solving, collaborating, and continuously improving how software is secured.
- Perform application security assessments using SCA, SAST, secrets management, and interactive application testing tools.
- Identify, triage, prioritize, and communicate application vulnerabilities based on risk and business impact.
- Integrate security testing and controls into CI/CD pipelines, helping strengthen DevSecOps practices across development teams.
- Assess security risks in AI/ML-enabled applications, including model exposure, inference endpoints, and emerging AI-specific attack vectors.
- Secure APIs, plugins, microservices, and third-party integrations against common and emerging threats.
- Configure and continuously improve security controls across technologies such as WAF, EDR, MDM, and cloud platforms.
- Conduct threat modeling and secure design reviews for applications, APIs, cloud solutions, and AI-enabled use cases.
- Review and strengthen identity and access management flows, applying least-privilege principles and appropriate security controls.
- Partner directly with developers to remediate vulnerabilities, improve secure coding practices, and integrate security into everyday development workflows.
- Automate repetitive security activities using scripting and other tools to increase efficiency and allow the security team to focus on higher-value work.
- Monitor security events and participate in an on-call rotation for incident response and security investigations.
- Contribute to security and compliance readiness for frameworks and requirements relevant to regulated environments, including PCI, HIPAA, and HITRUST.
- 2+ years of professional experience in Application Security, Product Security, or a closely related security discipline.
- Hands-on experience with application security and code-scanning technologies, particularly SCA and SAST tools.
- Strong understanding of the OWASP Top 10 and common application security vulnerabilities.
- Experience securing APIs, microservices, and third-party integrations.
- Familiarity with CI/CD pipelines and the principles of DevSecOps.
- Basic understanding of AI/ML systems and the security risks associated with AI-enabled applications.
- Experience with cloud security and modern cloud-based application environments.
- Scripting ability in Python, Bash, or a comparable language, with the ability to automate repetitive security tasks.
- Strong analytical and problem-solving skills, with a security mindset focused on identifying how systems could fail or be exploited.
- Clear communication skills and the ability to explain security concepts and recommendations to both technical and non-technical stakeholders.
- Ability to collaborate effectively with engineers, developers, and other business teams while building trust and encouraging secure development practices.
- Experience with ML frameworks, AI threat models, WAF or API security solutions is a plus.
- Experience in e-commerce, healthcare, or another highly regulated industry is advantageous.
- Ability to work remotely while maintaining Eastern Time (ET) working hours.
- $75,000–$95,000 USD base salary.
- Eligibility for a discretionary annual bonus of up to 10%.
- 100% remote work within the United States.
- Medical, dental, and vision insurance.
- 401(k) plan with company match.
- Dependent Care, FSA, and HSA accounts.
- Paid parental and bonding leave.
- Flexible paid time off and office closure on major holidays.
- Monthly wellness and internet reimbursements.
- Professional development opportunities, including certification support and leadership coaching.
- Mental health and wellbeing resources.
- Opportunity to work across application security, cloud security, DevSecOps, API security, and emerging AI/ML security.
- Broad responsibilities and hands-on ownership within a small, growing information security team.
- Collaborative environment with opportunities to partner closely with engineering and other technical teams.