Security Analyst III (DevSecOps & Application Security)
Full Time
Remote
USD $85.00 - 90.00 per hour

.png%3Fformat%3Dwebp&w=384&q=75)
PTR Global
Fitment
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- Enterprise Software
- Emerging Technologies
- Cloud Architecture
- Software Development
- Bill Of Materials
- Software Packaging
- Malware Analysis
- Extraction
- Security Analysis
- Workflow
- Machine Learning (ML)
- Data Flow
- Hosting
- Authentication
- Data Security
- DLP
- IT Security
- Orchestration
- Authorization
- eXist
- Security Controls
- Use Cases
- Risk Management
- Microsoft Certified Professional
- Servers
- Embedded Systems
- Inventory
- Data Processing
- Access Control
- Computer Science
- Information Systems
- Cyber Security
- Software Engineering
- Software Security
- DevSecOps
- SCA
- Management
- Continuous Integration
- Continuous Delivery
- Vulnerability Management
- Security QA
- Testing
- Generative Artificial Intelligence (AI)
- Systems Modeling
- Cloud Computing
- DevOps
- GitHub
- Microsoft
- Microsoft Azure
- Databricks
- Amazon Web Services
- Google Cloud
- Google Cloud Platform
- SaaS
- Open Source
- Supply Chain Management
- RMF
- Risk Management Framework
- API
- OWASP
- Artificial Intelligence
- Threat Modeling
- CISSP
- Cisco Certifications
- Cloud Security
- Communication
- Privacy
- Finance
- Credit Cards
- Banking
- Onboarding
- Payroll
- Training
- Reporting
- PS
- PostScript
Summary
Position: Security Analyst III (DevSecOps & Application Security)
Location: Remote
Duration: 6 months
Job ID: 180381
Position Summary
This is a cybersecurity individual responsible for reducing security risk across enterprise software development, applications, artificial intelligence systems, cloud environments, and emerging technologies.
This role combines DevSecOps and Application Security with specialized expertise in AI Security and AI governance enablement. The Application and AI Security Senior Engineer develops and matures scalable security capabilities across the software development lifecycle, including SAST, DAST, software composition analysis, Software and AI-BOM, package and dependency management, container scanning, vulnerability management, and AI red teaming.
The position also supports the secure adoption of traditional AI/ML, Generative AI, AI-enabled applications, AI agents, agentic systems, coding assistants, models, APIs, Retrieval-Augmented Generation, and AI development platforms.
The Application and AI Security Senior Engineer partners with development, DevOps, cloud, architecture, Data & AI, Product Security, and governance teams to embed automated security controls into technology lifecycles and translate emerging threats into practical, risk-based requirements.
Business Use Job Responsibilities
DevSecOps & Application Security
Develop, implement, and mature DevSecOps capabilities that integrate automated security testing and vulnerability detection into software development and CI/CD processes.
Support and optimize Static Application Security Testing and Dynamic Application Security Testing, including pipeline integration, finding validation, prioritization, and remediation workflows.
Advance Software Bill of Materials and AI Bill of Materials capabilities to improve visibility into applications, packages, libraries, models, AI components, and software and AI supply-chain dependencies.
Support Software Composition Analysis, package and dependency management, and open-source software governance, including identification of vulnerable, obsolete, malicious, or unapproved components.
Develop and mature container and container-image scanning to identify vulnerable packages, embedded secrets, configuration weaknesses, malware, and other risks before deployment.
Embed security controls into source-code repositories, CI/CD pipelines, artifact repositories, container registries, and software release processes.
Establish risk-based vulnerability management practices and partner with development teams to validate findings, prioritize material risk, and drive remediation.
Develop and mature AI security testing and red-teaming capabilities for AI-enabled applications, models, and agents.
Conduct or coordinate adversarial testing for prompt injection, jailbreaks, sensitive-data disclosure, system prompt extraction, insecure RAG, unauthorized tool invocation, excessive agency, and misuse of agent permissions.
Evaluate automated AI testing capabilities, including model scanning, prompt and agent testing, runtime validation, and continuous security assessment. Translate findings into remediation requirements and reusable preventive controls.
Assess the security implications of AI-assisted development and agentic coding tools, including access to source code, repositories, packages, credentials, development environments, and CI/CD processes.
Perform Product Security reviews of new or materially changed applications and technologies to identify significant cybersecurity risks and establish appropriate security requirements.
AI Security
Perform technical security assessments of AI-enabled applications, models, platforms, GenAI services, AI agents, agentic workflows, machine-learning systems, and AI-enabled SaaS products.
Evaluate threats including prompt and indirect prompt injections, data disclosure, excessive agency, insecure tool access, model and data poisoning, insecure output handling, untrusted RAG content, AI supply-chain compromise, excessive privilege, shadow AI, and unauthorized agent actions.
Review AI architectures and components, including models, APIs, identities, data flows, data sources, RAG implementations, tools, actions, integrations, hosting environments, and external model or service providers.
Evaluate controls for authentication and authorization, model and API access, data protection, AI guardrails, input/output security, DLP, RAG security, logging and observability, human oversight, and runtime protection.
Develop and maintain AI security controls, technical standards, guardrails, assessment methodologies, architecture patterns, and implementation guidance.
AI Agent & Emerging Technology Security
Assess AI agents and agentic systems for risks associated with autonomy, identity, delegated authority, data access, memory, orchestration, tools, integrations, and actions.
Evaluate agent identities, service principals, authorization models, APIs, connectors, plugins, MCP-based integrations, least privilege, and human-in-the-loop controls.
Determine whether agent permissions and actions operate within appropriate authority boundaries and whether consequential actions have sufficient human oversight, logging, and auditability.
Evaluate emerging AI models, agent frameworks, coding assistants, open-source and open-weight technologies, protocols, and security products.
Analyze unfamiliar technologies to determine how AI is used, which models and providers are involved, what data is processed, what permissions and external connections exist, and which security controls are required.
AI Governance, Inventory & Security Posture
Provide technical cybersecurity expertise supporting AI governance, AI use-case assessments, technology intake, risk management, and security review processes.
Support discovery and inventory of AI applications, models, agents, services, APIs, integrations, development tools, MCP servers, and supporting components, including approved, embedded, unmanaged, and shadow AI.
Advance AI SBOM and component inventory practices to provide traceability across models, software libraries, services, APIs, data sources, tools, and dependencies.
Support continuous AI security posture management through telemetry, monitoring, control validation, metrics, remediation tracking, and governance evidence.
Evaluate third-party AI and SaaS providers for model usage, data processing, retention, tenant isolation, identity integration, access controls, logging, external providers, and software or AI supply-chain dependencies.
Required Experience
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related discipline, or equivalent professional experience.
Five or more years of experience in cybersecurity, DevSecOps, Application Security, Product Security, software engineering security, cloud security, AI security, or a comparable technical security discipline.
Demonstrated experience with several Application Security and DevSecOps capabilities, including:
SAST and DAST
Software Composition Analysis (SCA)
SBOM generation and management
Package and dependency management
Container and image scanning
CI/CD and repository security
Open-source software security
Vulnerability management and remediation
Experience with AI security testing, AI red teaming, Generative AI security, or adversarial testing strongly preferred.
Working knowledge of LLM and GenAI architectures, RAG, agentic systems, model APIs, and associated security considerations, including prompt-injection risks, AI supply-chain security, guardrails, observability, and agent identities and permissions.
Experience with enterprise cloud, development, container, and AI ecosystems such as Microsoft Azure, Azure DevOps, GitHub Enterprise, GitHub Copilot, Microsoft AI services, Copilot Studio, Azure Databricks, MLflow, AWS, or Google Cloud.
Experience assessing third-party SaaS, AI services, models, open-source software, development tools, and technology supply-chain components.
Familiarity with NIST CSF, NIST AI RMF, NIST SSDF, OWASP application and API security, OWASP AI and LLM security guidance, secure development, and threat modeling.
Relevant certifications such as CISSP, CSSLP, CCSP, GIAC, or cloud security certifications are preferred but not required.
Strong technical curiosity and the ability to rapidly evaluate unfamiliar technologies, architectures, vulnerabilities, and emerging threats.
Strong communication skills and ability to interface with technical and non-technical resources to include senior leaders.
Ability to distinguish material risks from theoretical concerns and translate technical findings into practical remediation requirements, preventive controls, automation opportunities, and risk-based recommendations.
At PTR Global, we understand the importance of your privacy and security. We NEVER ASK job applicants to:
Pay any fee to be considered for, submitted to, or selected for any opportunity.
Purchase any product, service, or gift cards from us or for us as part of an application, interview, or selection process.
Provide sensitive financial information such as credit card numbers or banking information. Successfully placed or hired candidates would only be asked for banking details after accepting an offer from us during our official onboarding processes as part of payroll setup.
Pay Range: $85- $90/hr. W2
The specific compensation for this position will be determined by several factors, including the scope, complexity, and location of the role, as well as the cost of labor in the market; the skills, education, training, credentials, and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits, including medical, dental, vision, and 401K contributions, as well as PTO, sick leave, and other benefits mandated by applicable state or localities where you reside or work.
If you receive a suspicious message, email, or phone call claiming to be from PTR Global, do not respond or click on any links. Instead, contact us directly at +1 . To report any concerns, please email us at
#LI-PS4
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: ptrtx
- Position Id: 180381
- Posted 3 hours ago
Company Info
Pinnacle Group is a leading provider of information technology and workforce solutions. Pinnacle Group includes Pinnacle Technical Resources, Inc., its flagship information technology staffing and consulting services provider; Pinnacle MSP, a managed services provider; Pinnacle Payrolling, a payrolling and independent contractor compliance provider; Pinnacle Canada, which provides staffing, MSP and payrolling services in Canada.

Create job alert
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs.png?format=webp)