Application Security Vulnerability Analyst

New York, NY, US • Posted 21 hours ago • Updated 9 hours ago
Contract W2
On-site
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Insurance
  • Corrective And Preventive Action
  • ROOT
  • Documentation
  • Reporting
  • Process Improvement
  • Risk Management
  • OWASP
  • Software Development
  • Java
  • TypeScript
  • JavaScript
  • C#
  • Python
  • Node.js
  • Security Analysis
  • Communication
  • Organizational Skills
  • Management
  • GitHub
  • SCA
  • Risk Analysis
  • Software Security
  • Testing
  • Code Review
  • Continuous Integration
  • Continuous Delivery
  • Software Architecture
  • Web Applications
  • Cloud Computing
  • Vulnerability Management
  • Workflow
  • Security+
  • Computer Science
  • Cyber Security
  • Information Technology
  • Privacy
  • Artificial Intelligence
  • Recruiting
  • MEAN Stack
  • Customer Service
  • Training And Development
  • SAP BASIS

Summary

Software Guidance & Assistance, Inc., (SGA), is searching for an Application Security Vulnerability Analyst for a contractor assignment with one of our premier Insurance Services clients. This is a remote role; candidates must work EST business hours.
Responsibilities:
  • Review vulnerabilities identified through AI-based SAST, SCA, and related application security tools.
  • Evaluate vulnerabilities beyond vendor-assigned severity scores by considering exploitability, exposure, attack paths, business impact, compensating controls, and application context.
  • Distinguish between theoretical findings and vulnerabilities that present realistic application and business risk.
  • Validate vulnerability classifications and severity recommendations.
  • Identify false positives, duplicate findings, and opportunities for risk-based prioritization.
  • Utilize AI and effective prompting techniques to increase confidence in findings and reduce false positives.
  • Assess vulnerability trends and recurring development patterns that may require broader corrective action.
  • Explain application security findings clearly to developers, architects, technology owners, and business stakeholders.
  • Provide actionable remediation guidance and secure coding recommendations.
  • Assist application teams in understanding root causes and recommended fixes.
  • Partner with developers and technology owners to establish remediation plans and drive findings to closure.
  • Track remediation progress and ensure vulnerabilities are addressed within defined SLAs.
  • Escalate aging findings and remediation blockers as appropriate.
  • Validate completed remediation activities and make closure recommendations.
  • Support vulnerability triage activities across multiple application security tools.
  • Participate in vulnerability review sessions and remediation discussions.
  • Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.
  • Contribute to application security procedures, reporting, and process improvements.
Required Skills:
  • 3+ years of experience in Application Security, Vulnerability Management, Security Risk Management, or a related cybersecurity discipline.
  • Strong understanding of application security and vulnerability management, including:
    • OWASP Top 10
    • Common Weakness Enumeration (CWE)
    • Secure Software Development Lifecycle (SSDLC)
    • Exploit Prediction Scoring System (EPSS)
    • CVE/CVSS concepts
  • Experience reviewing and validating findings generated by SAST, SCA, or related application security tools.
  • Ability to evaluate vulnerabilities based on actual exploitability, exposure, application context, and business risk rather than relying solely on CVSS scores.
  • Experience identifying false positives and validating vulnerability classifications and severity.
  • Experience working directly with development teams to remediate application vulnerabilities.
  • Ability to understand application security findings involving one or more modern enterprise development languages, including Java, TypeScript, JavaScript, C#, Python, Go, or Node.js.
  • Experience using AI-based security tools or AI-assisted security analysis.
  • Ability to provide developers with actionable remediation and secure coding guidance.
  • Strong written and verbal communication skills with the ability to translate technical findings into clear, business-relevant language.
  • Strong organizational skills and the ability to manage multiple remediation efforts simultaneously.
  • Demonstrated ability to work independently and drive issues through resolution.
Preferred Skills:
  • Experience with SAST tools such as SonarQube, Snyk Code, Checkmarx, Veracode, GitHub Advanced Security, or similar.
  • Experience with SCA tools and software dependency risk analysis.
  • Application security testing and secure code review experience.
  • CI/CD security integration experience.
  • Experience with Claude Code or similar AI-assisted security/development tools.
  • Understanding of software architecture and common web application attack patterns.
  • Working knowledge of cloud-native applications and APIs.
  • Familiarity with enterprise vulnerability management and remediation tracking workflows.
  • Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, or similar.
Education:
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field preferred, or equivalent relevant professional experience.
By applying for a job with SGA, you agree to allow SGA to process your application for this and future opportunities in accordance with our Privacy Policy. Also, to ensure timely processing, you agree to be contacted by our AI recruiter via email, text, or phone. Message frequency varies and data rates may apply, but you can reply STOP to any SMS message to opt-out of texts and may contact SGA at to opt-out of AI communications. The choice not to engage with AI will not adversely impact your consideration for placement. AI is not used to make any hiring determinations.

SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .

SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: sgainc
  • Position Id: 26-02273
  • Posted 21 hours ago

Company Info

About Software Guidance & Assistance

Founded in 1981, SGA is a technology and resource solutions provider with a national footprint and headquartered in the shadow of Wall Street. We’re a certified women-owned business. We provide contingent staffing, direct placement, and professional and managed services to transform businesses and evolve careers. We’re small enough to tailor our services to each client and big enough to deliver for some of the world’s largest employers. Our professionals are experts in areas such as IT, finance, accounting, risk, and clinical.

SGA provides contingent staffing, direct placement, and professional and managed services nationwide for Fortune 500 companies, mid-size businesses and select startups.

Our core skillsets include all areas of technology – business & data analysis, cyber & network security, database administration, development & architecture, infrastructure, program & project management, quality assurance & testing. We also deliver talent across professional business functions such as finance, accounting, risk, and clinical.

Our Professional & Managed Services team delivers IT projects through onshore, offshore and hybrid delivery models. We develop software products, modernize applications, add features, and integrate and maintain systems. Our scope covers, among others, complex application suites, data management and visualizations, machine learning and mobile applications.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Parsippany-Troy Hills, New Jersey

Today

Contract

USD 75.00 - 85.00 per hour

New York, New York

Today

Contract

USD 70.00 - 78.06 per hour

Rockville, Maryland

Today

Contract

USD 64.00 - 67.00 per hour

Cincinnati, Ohio

Today

Contract

USD 45.00 - 64.00 per hour

Search all similar jobs