Application Security Analyst/Senior
Location
United States
Posted
4 days ago
Salary
$79.5K - $134K / year
Job Description
Role Description
In this role you will provide leadership in protecting the confidentiality, integrity, and availability of web and/or mobile applications by establishing and enforcing system access controls. You will define system security requirements, recommend improvements to system security frameworks, ensure authorized access to systems through monitoring, performing testing, or scanning for security vulnerabilities, and raising security awareness.
- Identify security related issues and define security requirements during all phases of the application development lifecycle.
- Review program/development documents to ensure adherence to secure coding standards, guidelines and security requirements.
- Coordinate with developers to ensure secure and resilient design, prototyping, development, testing, support, and documentation of moderately complex application software.
- Monitor for atypical usage of information system accounts and other abnormalities to identify possible breaches.
- Assist with FISMA initiatives, e.g., updating security plans, to support ISSO responsibilities.
- Coordinate the identification of security-related issues and definition of security requirements during all phases of the software development lifecycle (SDLC).
- Perform penetration testing activities to ensure web vulnerabilities are not present within Treasury Services applications.
- Conduct analysis and interpreting of cybersecurity trends and emerging risks, quantifies potential impact, and develops conclusions and recommended application security responses.
- Perform other duties as assigned or requested.
- Adhere to the Bank's attendance policies through regular and prompt attendance.
Qualifications
- Application Security Analyst: Bachelor’s degree with 3+ years of related work experience or Associate's degree with 5+ years of related work experience - Strong preference of at least one security certification (CISSP, CSSLP, CCSP, CEH, AWS Security, etc.)
- Application Security Analyst Senior: Bachelor’s degree with 5+ years of related work experience or Associate's degree with 7+ years of related work experience - Strong preference of at least one security certification (CISSP, CSSLP, CCSP, CEH, AWS Security, etc.)
Requirements
- Ability to analyze highly complex business requirements.
- Thorough understanding of industry-based security controls relating to applications, services, and systems.
- Knowledge of cloud-based platforms and technologies and how to ensure these environments are secure.
- Thorough understanding of security controls relating to access control, authentication, and auditing.
- Demonstrated knowledge and understanding of information security industry trends and emerging technologies, especially relating to application security vulnerabilities.
- Proficient at testing web applications for security vulnerabilities, such as those listed in the OWASP Top 10 and familiar with the tools used for testing.
- Demonstrated ability to learn new systems and technologies.
- Excellent time management skills, and the ability to prioritize and multi-task.
Benefits
- Support overall health and financial security.
- Learn more about our benefits here: Cleveland Fed Benefits
Job Requirements
- Application Security Analyst: Bachelor’s degree with 3+ years of related work experience or Associate's degree with 5+ years of related work experience - Strong preference of at least one security certification (CISSP, CSSLP, CCSP, CEH, AWS Security, etc.)
- Application Security Analyst Senior: Bachelor’s degree with 5+ years of related work experience or Associate's degree with 7+ years of related work experience - Strong preference of at least one security certification (CISSP, CSSLP, CCSP, CEH, AWS Security, etc.)
- Ability to analyze highly complex business requirements.
- Thorough understanding of industry-based security controls relating to applications, services, and systems.
- Knowledge of cloud-based platforms and technologies and how to ensure these environments are secure.
- Thorough understanding of security controls relating to access control, authentication, and auditing.
- Demonstrated knowledge and understanding of information security industry trends and emerging technologies, especially relating to application security vulnerabilities.
- Proficient at testing web applications for security vulnerabilities, such as those listed in the OWASP Top 10 and familiar with the tools used for testing.
- Demonstrated ability to learn new systems and technologies.
- Excellent time management skills, and the ability to prioritize and multi-task.
Benefits
- Support overall health and financial security.
- Learn more about our benefits here: Cleveland Fed Benefits
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Cybersecurity Analyst monitoring and responding to security incidents at Porter
Senior Information Security Analyst
Cincinnati Children'sOur mission: to be the leader in improving child health.
Senior Information Security Analyst safeguarding systems at Cincinnati Children's Hospital
Cybersecurity Subject Matter Expert
JobgetherWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
This role is a senior technical position focused on safeguarding critical IT systems and networks through advanced cybersecurity expertise. You will lead complex assessments, vulnerability testing, and cybersecurity evaluations, providing actionable guidance and technical directi...
This role provides advanced Governance, Risk, and Compliance (GRC) support for federal information systems, managing the full lifecycle of Risk Management Framework (RMF) activities and external service authorization processes. Responsibilities include developing security authorization documentation, reviewing FedRAMP packages, conducting risk assessments per NIST 800-30, and supporting continuous monitoring efforts.