Application Security Analyst Lead

Brooklyn, NY, US • Posted 10 hours ago • Updated 10 hours ago
Contract Independent
Contract W2
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

✨ Finding the perfect fit...

Job Details

Skills

  • .NET
  • API
  • Access Control
  • Agile
  • Apache HTTP Server
  • Auditing

Summary

UNIVERSAL Technologies is seeking an Application Security Analyst Lead for an onsite role in Brooklyn, NY or within the 5 boroughs to oversee application security risk evaluation and accreditation for systems involved in large-scale data center migration initiatives. This role focuses on governance, risk acceptance, vulnerability management, and ensuring applications meet enterprise and regulatory security standards prior to production deployment.

WHO WE ARE

UNIVERSAL Technologies, LLC is a Women-Owned (M/WBE) IT solutions and consulting company with over 15 years of experience delivering enterprise-grade technology solutions. We partner with public sector and commercial clients to provide high-quality IT services across Development, Business Analysis, Project Management, Cyber Security, Network Engineering, and Systems Architecture. Our mission is to become an extension of our clients teams, delivering impactful and scalable solutions.

WHAT WE OFFER

  • Competitive compensation
  • Health, Dental, and Vision Insurance
  • Group Life Insurance
  • 401(K)
  • HSA/FSA options
  • Pre-Tax Transportation Program
  • Generous PTO and holiday package

MANDATORY SKILLS / EXPERIENCE

  • Minimum of 8 years of experience in Application Security aligned with standards such as OWASP and NIST
  • Minimum of 8 years of experience in Secure Software Development Life Cycle (SSDLC)
  • Minimum of 8 years of experience in Threat Modeling and Risk Assessments
  • Minimum of 5 years of experience performing application vulnerability scanning (SAST, DAST)
  • Minimum of 8 years of experience integrating security into CI/CD and DevSecOps environments (Azure, Jenkins)
  • Minimum of 8 years of experience in API security and access control frameworks (OAuth, SAML, SSO)
  • Minimum of 8 years of experience in cloud security architectures
  • Minimum of 8 years of experience working with security frameworks and compliance standards (NIST, ISO 27001, PCI-DSS, SOC 2, HIPAA, GDPR, FedRAMP, HITRUST)
  • Minimum of 8 years of experience in vulnerability management, penetration testing, and security operations
  • Minimum of 8 years of experience in incident response and security governance processes
  • Minimum of 8 years of experience in Agile environments, project coordination, and stakeholder communication
  • Hands-on experience with platforms including Windows Server, Linux, IIS, Apache, VMware, and Citrix
  • Experience with development technologies including .NET, C#, JavaScript, Python, PowerShell, and web technologies
  • Hands-on experience with security tools (required): Veracode, IBM AppScan, SD Elements, Burp Suite
  • Experience with additional tools (preferred): Checkmarx, Fortify, Prowler, SonarQube, Snyk, Wireshark, OWASP ZAP, Rapid7, STRIDE

SCOPE OF SERVICES

  • Lead application security accreditation efforts for systems involved in data center migration initiatives
  • Evaluate and analyze application vulnerability scan results to identify risks and security gaps
  • Document vulnerabilities and define mitigation strategies and SLA timelines based on severity and business impact
  • Assess whether identified vulnerabilities fall within agency risk tolerance levels
  • Communicate findings and risk posture to business owners, IT leadership, and security stakeholders
  • Develop and enforce risk mitigation strategies and compensating controls
  • Validate remediation efforts with development teams and support security certification for production readiness
  • Manage and enforce Risk Acceptance processes, including formal approval workflows with Business Owners, IT leadership, and CISO
  • Ensure alignment with enterprise security policies, regulatory requirements, and compliance standards
  • Support audit readiness and continuous improvement of application security governance practices

UNIVERSAL Technologies is an equal opportunity employer.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10205691a
  • Position Id: 8939181
  • Posted 10 hours ago

Company Info

About UNIVERSAL Technologies

“Our Mission is to become an extension of our client’s IT organization”

— JOAO RAQUEL, CEO

UNIVERSAL Technologies, LLC, focuses on supporting client engagements by seamlessly integrating our staff with the client’s existing Information Technology environment. Headquartered in New York City with additional offices in Albany, New York, we provide decades of experience to deliver measurable results within State and local government agencies and other large organizations.


What We Do

UNIVERSAL Technologies provides projects, personnel and solutions with a focus on ensuring that our clients’ infrastructure and computing environments are well designed, well managed, stable, and secure. We offer a wide range of services and products, from individual engagements to enterprise-wide solutions.

UNIVERSAL’s consulting practice and resources cross the technology boundaries of product specializations and its application requirements. Practice areas include but are not limited to:

·      IT SUPPORT FOR HETEROGENEOUS ENTERPRISE

·      SOFTWARE DEVELOPMENT

·      PROJECT MANAGEMENT

·      PROGRAM MANAGEMENT

·      BUSINESS ANALYSIS

·      SYSTEM ADMINISTRATION

·      SYSTEMS ARCHITECTURE

Our Systems Integration management experience and core competencies span the life cycle of enterprise implementation from requirements analysis through design, deployment, and operation in a wide range of disciplines:

•DATA CENTER ARCHITECTURE

•VIRTUAL CLOUD ARCHITECTURE AND DEPLOYMENT

•VIRTUALIZATION ARCHITECTURE, DESIGN AND DEPLOYMENT

•ENTERPRISE SYSTEMS AND NETWORK INTEGRATION

•ENTERPRISE DISASTER RECOVERY PLANNING, DESIGN AND DEPLOYMENT

•STORAGE MANAGEMENT

•ENTERPRISE SECURITY ARCHITECTURE, DESIGN AND DEPLOYMENT

•ENTERPRISE OPERATIONS MANAGEMENT


Our Clients

UNIVERSAL Technologies has a history of providing IT services to some of the leading New York State and New York City government agencies.

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Brooklyn, New York

Today

Easy Apply

Contract

Depends on Experience

Hybrid in Brooklyn, New York

Today

Easy Apply

Contract

Depends on Experience

New York, New York

Today

Easy Apply

Contract

Up to $65

Hybrid in Brooklyn, New York

3d ago

Easy Apply

Contract, Third Party

70+

Search all similar jobs