Security Analyst & SCA & SAST

Remote, USA Full-time
Role & responsibilities The Senior Security Analyst (IC2) will be responsible for strengthening application security across the organisation by implementing secure development practices, performing vulnerability assessments, and driving DevSecOps initiatives. This role requires hands‑on expertise in Static Application Security Testing (SAST), Software Composition Analysis (SCA), and a strong understanding of Application Security (AppSec) and DevSecOps principles. Key Responsibilities • Application Security Testing: • Perform SAST and SCA scans for web, API, and mobile applications. • Analyze scan results, prioritise vulnerabilities, and collaborate with development teams for remediation. • DevSecOps Integration: • Embed security controls into CI/CD pipelines and automate security checks. • Drive adoption of secure coding practices and threat modelling across development teams. • Risk Management: • Conduct security reviews and validate secure architecture designs. • Maintain compliance with industry standards (OWASP, NIST, ISO 27001). • Tool Management: • Manage and optimise security tools such as HP Fortify, Checkmarx, Veracode, Burp Suite, and container security platforms. • Reduce false positives and improve scan efficiency. • Collaboration & Training: • Partner with architects, DevOps, and product teams to integrate security early in the SDLC. • Deliver training sessions on secure coding and tool usage. • Continuous Improvement: • Monitor emerging threats and recommend improvements to security processes. • Participate in POCs for new security tools and automation initiatives. Preferred candidate profile Experience & Qualification • 3-6 years of relevant experience • B.E/B. Tech or masters degree from a reputed institute with good academics history. MUST HAVE • Technical Expertise • Strong knowledge of SAST and SCA methodologies. • Hands‑on experience with tools like Fortify, Mend, Checkmarx, Veracode, SonarQube, GHAS. • Programming Knowledge • Proficiency in Java, .NET, Python, or JavaScript. • Certifications (Preferred) • CEH, CSSLP, GWAPT, or similar. • Experience • 3–6 years in application security. Skills required • SCA Management • Perform dependency scanning to identify vulnerable open‑source components. • Use tools like Mend & GHAS for SCA. • Ensure compliance with licensing and vulnerability management policies. • SAST Implementation • Configure and run SAST tools (e.g., Fortify, Checkmarx, Veracode, SonarQube). • Integrate SAST into CI/CD pipelines for automated code scanning. • Analyze scan results, prioritise vulnerabilities, and guide remediation. • Secure Development Lifecycle • Collaborate with developers to enforce secure coding standards. • Conduct code reviews and threat modelling sessions. • Governance & Compliance • Align with OWASP Top 10, NIST, and ISO 27001 standards. • Support audits and generate compliance reports. • Training & Awareness • Conduct developer training on secure coding and vulnerability remediation. Apply tot his job
Apply Now

Similar Jobs

Software Security Engineer (Associate, Mid-Level, or Senior)

Remote, USA Full-time

Staff Program Manager - Security Compliance Programs (San Jose, CA required)

Remote, USA Full-time

Senior Security Software Engineer - Cloud & Infra Security

Remote, USA Full-time

Project Manager – Implementations Security

Remote, USA Full-time

Sr. Program Manager, Missile Defense

Remote, USA Full-time

Technical Project Manager; PMP- Cisco Network​/Security

Remote, USA Full-time

Project Manager, Product Security

Remote, USA Full-time

System Software Engineer – Security Tools and Infrastructure

Remote, USA Full-time

Software Engineer, Security

Remote, USA Full-time

Principal Security Engineer job at Zillow in US National

Remote, USA Full-time

Legal Counsel (GtM Team)

Remote, USA Full-time

**Experienced Virtual Customer Support Representative – Delivering Exceptional Experiences for arenaflex Customers**

Remote, USA Full-time

**Experienced Data Entry Specialist – Remote Work Opportunity with Competitive Pay**

Remote, USA Full-time

[Remote] Business Development Representative

Remote, USA Full-time

**Experienced Data Entry Clerk – Remote Focus Group Participation Opportunity with blithequark**

Remote, USA Full-time

**Experienced Live Chat Representative – Deliver Exceptional Client Experience at arenaflex**

Remote, USA Full-time

**Experienced Customer Service Representative – High Paying Remote Opportunity at arenaflex**

Remote, USA Full-time

Virtual Content Creator Jobs Create and Manage Digital Content Remotely

Remote, USA Full-time

Remote Inventory Data Entry Assistant - UPS Careers

Remote, USA Full-time

Remote Life Insurance Broker in Key West, FL in Semler Insurance Agency

Remote, USA Full-time
Back to Home