Job Title: Information Security Analysts
Location: Paterson, NJ
Employer: 4Consulting, Inc
Position Type: Full Time
Worksite: Remote
Position Summary
4Consulting, Inc is seeking a qualified Information Security Analysts to support technology consulting, application development, systems analysis, testing, data management, cybersecurity, infrastructure, or project delivery services for client projects. The selected candidate will perform duties consistent with the client’s project requirements and company delivery standards.
Essential Duties and Responsibilities
The candidate will be responsible for:
- Integrate and manage application security controls throughout the SDLC and CI/CD pipelines, including configuring security scanning capabilities and establishing repeatable security testing processes.
- Conduct and analyze application security assessments, review scan results, identify vulnerabilities and coding weaknesses, and provide actionable remediation guidance to development teams.
- Support secure software development and supply-chain security by performing secure code reviews, evaluating third-party and open-source components, and assessing risks associated with software dependencies.
- Collaborate with application, development, and security teams to identify security gaps, coordinate remediation activities, improve security workflows, and promote secure software development practices.
Minimum Qualifications
The position requires:
|
Education
|
Bachelor’s degree in Computer Science, Information Technology, Engineering, Business, or related field, or equivalent combination of education and experience.
|
|
Experience
|
6–9 years of experience in application security, cybersecurity, DevSecOps, secure software development, vulnerability assessment, or related security engineering.
|
|
Technical Skills
|
Application Security, DevSecOps, SAST, SCA, Vulnerability Assessment, Secure Code Review, CI/CD Security, Software Supply Chain Security, Security Testing, Source Code Management, Security Automation
|
|
Business / Domain Skills
|
- Experience supporting enterprise Application Security programs across the software development lifecycle and CI/CD environments.
- Experience working with GitHub, GitLab, Azure DevOps (ADO), and Jenkins within application development and DevSecOps environments.
- Experience onboarding applications and managing SAST and SCA scanning using Checkmarx or similar application security platforms.
- Experience assessing third-party and open-source libraries, software dependencies, and software supply-chain risks and providing remediation guidance.
|
|
Communication
|
Ability to communicate with technical and business stakeholders.
|
|
Documentation
|
Ability to prepare project documentation, status updates, and deliverables.
|
|
Work Authorization
|
Must be legally authorized to work in the United States. Sponsorship may be considered where permitted by company policy and project requirements.
|
Certification Required
None
Travel Required
None
Supervisory Role
No
Preferred Qualifications
- Experience implementing application security controls within enterprise development environments.
- Strong analytical, troubleshooting, and root-cause analysis skills.
- Strong understanding of secure software development practices and security requirements throughout the SDLC.
Equal Employment Opportunity Statement
4Consulting, Inc is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, citizenship status, immigration status where protected by law, or any other legally protected status. All candidates will be evaluated based on job-related qualifications, experience, skills, availability, and ability to perform the essential duties of the position.