AWS Application Security Analyst
Job Type: Permanent Full-Time
Work Model: Hybrid
Locations: Birmingham, AL | Knoxville, TN | Columbia, SC | Lafayette, LA
Position Overview
We are seeking an experienced AWS Application Security Analyst to support application security initiatives within a large-scale financial services environment.
This role will partner closely with software development, cloud, DevOps, and cybersecurity teams to identify, assess, and remediate security risks throughout the Software Development Lifecycle (SDLC).
The ideal candidate will have strong hands-on experience with application security testing, SAST, DAST, SCA, threat modeling, secure code review, DevSecOps, CI/CD security integration, AWS security, and container security.
Responsibilities
- Perform manual and automated application and source-code security reviews to identify vulnerabilities and security risks.
- Conduct threat modeling and application security risk assessments for new and existing applications.
- Work with development teams to determine appropriate remediation approaches for security findings.
- Utilize SAST, DAST, and Software Composition Analysis (SCA) tools for application security testing.
- Integrate application security controls and automated security testing into CI/CD pipelines.
- Evaluate application security risks across AWS cloud and containerized environments.
- Apply knowledge of secure coding practices, network protocols, encryption, authentication, and common application vulnerabilities.
- Partner with development, DevOps, cloud, and cybersecurity teams to strengthen DevSecOps practices throughout the SDLC.
- Develop security guidance, FAQs, standards, and reusable application security best practices for development teams.
- Clearly communicate vulnerabilities, security risks, and remediation recommendations to technical stakeholders.
Required Qualifications - 5+ years of application security experience and strong knowledge of secure software development practices.
- Hands-on experience with SAST, DAST, and SCA tools.
- Experience performing manual code reviews and application security assessments.
- Strong experience with threat modeling and security risk assessments.
- Working knowledge of AWS security and securing applications deployed in AWS environments.
- Experience with DevSecOps and integrating security testing into CI/CD pipelines.
- Experience with GitHub, Jenkins, or similar CI/CD platforms.
- Understanding of container security and associated application security risks.
- Programming or code-review experience with Java, Python, JavaScript, C#, or similar languages.
- Strong understanding of:
- Network protocols
- Encryption
- Authentication and authorization
- Secure coding practices
- Common application vulnerabilities
- Strong communication skills with the ability to explain security findings and remediation recommendations to developers and technical teams.
Preferred Qualifications - Experience within financial services, banking, or another highly regulated environment.
- Relevant security or cloud certifications such as:
- AWS Certified Security – Specialty
- CISSP
- CSSLP
- GIAC Application Security certifications
- Education
Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field.
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
#M-
#LI-
Ref: #404-IT Pittsburgh