Senior Application Security Analyst
8 hours ago
Join Our Mission: To Save the World from Unsafe Mobile Apps NowSecure is the mobile app security software company trusted by the world's most demanding organizations and most advanced security teams. As the standards-based mobile app risk management company, NowSecure protects the Mobile App Economy. The world's most demanding organizations, innovative mobile developers and advanced security, privacy, safety and compliance teams entrust NowSecure to safeguard millions of mobile app users across banking, insurance, high tech, IoT, retail, hospitality, energy and government sectors. Only NowSecure delivers continuous security and compliance with the depth, speed, accuracy, and efficiency to meet modern business demands. Dedicated to the open-source community and standards including OWASP,and NIAP, NowSecure is SOC 2 certified and recognized by IDC, Deloitte, Gartner and TAG
YOUR OPPORTUNITY
Looking to build your problem-solving and vulnerability hunting abilities? As an Application Security Analyst, you'll have the opportunity to use your skills in mobile and web security, application pen testing, and networking protocols to support our public and private sector customers. Working on a team of penetration testing, vulnerability assessment, and risk management experts, you'll perform web application pentests as well as reverse engineering and vulnerability analysis of both iOS and Android mobile applications, connected wearables, medical devices and cutting edge automotive technologies. Take part in partnerships with other industry leaders and make a meaningful contribution to the security research and testing community. You'll even be able to leverage your security research prowess and join us in our 5G and baseband security laboratory Are you ready to help us on our mission to save the world from unsafe mobile apps?
RESPONSIBILITIES
- Perform regular vulnerability assessments, risk assessments, or penetration tests for NowSecure's customers to include web and mobile applications, wearable devices, API, and IoT.
- Create technically sound and actionable reports for customers informing upon identified vulnerabilities and paths to mitigation.
- Convey technical topics to a variety of audiences including developers and security teams, both internal and external to NowSecure.
- Take the part of a trusted advisor and provide your opinion as a subject matter expert to help our customers navigate business decisions as it comes to risk.
- Develop automation or tooling where necessary to introduce efficiencies into the testing process.
- Demonstrate a resourceful and creative approach to solving technical and procedural problems and build creative solutions.
- Work with a variety of projects which includes short-term engagements and extended program work with long-term customers.
SKILLS AND EXPERIENCE NEEDED FOR SUCCESS
- Bachelor's Degree and three years of work experience, or in lieu of a Bachelor's Degree, 6-8 years of related cyber security work experience will be accepted
- 4+ years experience in penetration testing or vulnerability assessment of web, mobile, or IoT applications/devices
- Deep understanding of security fundamentals (OWASP MASVS, OWASP MSTG), common vulnerabilities, and application security best practices.
- Experience conducting network traffic captures / packet captures (PCAP) including familiarity with proxies such as OWASP ZAP, mitmproxy, Charles, Fiddler, Burp Suite, etc.
- High proficiency in web security analysis, including mapping of the application's attack surface, vulnerability discovery, exploitation, and attack vector chaining.
- Experience rooting or jailbreaking mobile devices.
- Demonstrated experience with programming and scripting languages such as Python, Ruby, PowerShell, Java, JavaScript, etc.
- Demonstrated familiarity with iOS or Android system internals.
- Strong familiarity with DAST and SAST technologies.
- Solid understanding of TCP/UDP ports and protocols and web requests including POST, GET, HTTP headers, user agents, request parameters, cookies, etc.
- Strong technical writing skills.
- Proficiency with operating systems- Linux, Windows, MacOS.
- Self-starter with the ability to work independently, interface with multiple teams, and willingness to overcome challenging problems while identifying opportunities for improvement.
- Ability to multi-task and context switch to work on multiple project requests in parallel.
- Strong desire to learn and be willing to invest the time necessary to address knowledge gaps.
- Ability to work on a team or independently and be able to prioritize tasks.
DESIRED SKILLS (Stand out from the crowd…)
- Previous professional services or consulting experience.
- Previous red teaming, research or analytics experience.
- Background in system and network security, authentication and security protocols, and applied cryptography is helpful
- Experience using Frida for any type of application security project
- Binary reverse engineering using Binary Ninja, IDA Pro, or Radare (r2).
- Experience with AWS or Google cloud environments preferred with an understanding of its major technologies.
BONUS POINTS (You have our attention…)
- Experience with LTE and GSM protocols.
- Past experience with NowSecure tools.
- Experience with bug bounty and vulnerability disclosure programs.
- Published CVEs.
- Active security certifications, including: OSCP, CHFI, CEH, GPEN, GWAPT, eMAPT, GMOB, CPENT, GXPN
- Advanced relevant academic training, such as a Master's degree in Computer Science, Computer Forensics, Cyber Security, or related field.
WE VALUE DIVERSITY
We believe that the best ideas come from teams where diverse points of view uncover new solutions to hard problems. We welcome and value team members who bring diverse life experiences, educational backgrounds, cultures, and work experiences.
COMPENSATION & BENEFITS
- The salary band for this position ranges is competitive and commensurate with experience and performance. This position will be eligible for a competitive annual bonus and equity package.
- Comprehensive Medical/Dental/Vision coverage
- 401K Plan + Company Match
- Remote work flexibility
- Home Office Stipend
- Paid Parental Leave
- Flexible PTO
dckTF7CAim
-
Remote, Oregon, United States GuidePoint Security Full time $120,000 - $180,000 per yearGuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...
-
Senior Applications Analyst
3 days ago
Remote, Oregon, United States Delta Dental Ins. Full time $80,500 - $174,300 per yearJOB DESCRIPTION We are seeking a skilled and experienced Senior Applications Analyst with expertise in Epic Wisdom to join our dynamic team. This Epic Applications Analyst will play a critical role in the implementation and installation of Epic applications, including module upgrades, new components, and modifications. The position is responsible for...
-
Senior Application Security Engineer
5 days ago
Remote, Oregon, United States Abnormal Full time $200,000 - $250,000 per yearAbout the RoleAbnormal AI is looking for a Senior Application Security Engineer to help build the next generation of secure AI-powered cybersecurity applications at scale. This is a senior IC-level role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software...
-
Security Analyst
5 days ago
Remote, Oregon, United States Mutual of Omaha Full time $80,000 - $120,000 per yearLocation: RemoteWork Type: Full Time RegularJob No: 504242Categories: Information Technology, FeaturedApplication Closes: Closes Oct 17, 2025 Are you driven by a passion for governance and motivated to effect substantial change in a dynamic professional setting? We invite you to consider a career with us as an IS Security Analyst within the I/S Governance...
-
Application System Analyst
11 hours ago
Remote, Oregon, United States ERP Initiatives Group Inc. Full time $80,000 - $120,000 per yearOverviewWe are seeking a highly skilled Application System Analyst to join our dynamic IT team. The ideal candidate will play a pivotal role in designing, implementing, and maintaining enterprise applications and systems. The Application Analyst will collaborate across departments to optimize system performance, ensure security compliance, and support...
-
Senior Application Security Engineer
5 days ago
Remote, Oregon, United States Rapport IT Services Full time $80,000 - $160,000 per yearEssential Functions:Engineers need to have strong development skills in either any one of Java, GoLang, Python AWS services, and possibly mobile application development.Hands-on development experience is crucial as this role requires active development involvement.Conduct security assessments on applications, including static and dynamic code analysis, to...
-
Senior Compensation Analyst
4 days ago
Remote, Oregon, United States Prime Therapeutics Full time $81,000 - $138,000 per yearOur work matters. We help people get the medicine they need to feel better and live well. We do not lose sight of that. It fuels our passion and drives every decision we make.Job Posting TitleSenior Compensation Analyst (Remote)Job DescriptionThe Senior Compensation Analyst is responsible for supporting or leading the development, implementation,...
-
Senior Business Analyst
5 days ago
Remote, Oregon, United States Changeis, Inc. Full time $80,000 - $120,000 per yearSenior Business AnalystLocation: Remote We are actively recruiting for a Senior Business Analyst for a contract to modernize a large application. The successful candidate possesses and applies expertise on multiple complex work assignments, as well as plans and completes major technology assignments. Assignments may be broad in nature, requiring originality...
-
Senior Analyst
5 days ago
Remote, Oregon, United States Leading Edge Skills Full time $42,000 per yearLeading Edge Skills (LES) is a focused IT and Business training center, based in California, right in the heart of Silicon Valley, that prepares students in transitioning and launching a new career quickly. We feel pride in offering a unique learning experience through training programs that are aligned with the industry requirements and are affordable....
-
Application Security Engineer
6 hours ago
Remote, Oregon, United States Isc2 Full time $120,000 - $200,000 per yearOverviewYour Future. Secured. ISC2 is a force for good. As the world's leading nonprofit member organization for cybersecurity professionals, our core values — Integrity, Advocacy, Commitment, Inclusion, and Excellence — drive everything we do in support of our vision of a safe and secure cyber world. Our globally recognized, award-winning portfolio of...