Application Security Analyst
2 weeks ago
- Relocation Assistance Available**
- Required three (3) days in the Orlando Headquarters Office and remote two (2) days.***
Position Summary
As a member of the professional staff, contributes general knowledge and skill in a discipline area.
(e.g., Accounting, Finance, Human Resources, Information Resources, Operations Planning & Support, Sales
& Marketing) to support team and/or department objectives.
Generally, works under limited supervision, but within established guidelines, producing and analyzing more.
complex business information to assist in the decision-making process.
Specific Job Summary
The Application Security Analyst role is responsible for incorporating security measures into the complete DevOps lifecycle and ensuring that security is an integral aspect of all software development and deployment processes. This position focuses on conducting comprehensive security assessments like static and dynamic analyses, code reviews, and automated vulnerability scans across various applications and environments. It also involves enforcing secure coding standards by collaborating with development, operations, and security teams to integrate vulnerability remediation within CI/CD pipelines.
In addition to conducting hands-on offensive security testing, this role requires expertise in mapping attack scenarios to frameworks such as the MITRE ATT&CK framework to assess the organization's defense mechanisms. The individual will be responsible for identifying weaknesses in both existing and new systems and providing detailed recommendations for improving security measures across various technology environments. The ideal candidate is a highly skilled and collaborative security professional with a deep understanding of offensive security techniques and a passion for improving security processes through continuous testing and learning.
Expected Contributions
- Contributes to team, department, and/or business results by performing complex quantitative and qualitative analysis for business processes and/or projects. Often manages small projects, business processes or parts of larger ones.
- Responds to, solves, and makes decisions on more complex/non-routine business requests with limited to moderate risk.
- Performs more complex quantitative and qualitative analysis for business processes and/or projects. Often manages small projects, business processes or parts of larger ones.
- Responds to, solves, and makes decisions on more complex/non-routine business requests with limited to moderate risk.
- Assists more senior associates in achieving business results by:
- identifying opportunities to enhance the effectiveness of business processes.
- participating in setting department operating plans.
- achieving results against budget within scope of responsibility.
- Demonstrates an awareness of personal strengths and areas for improvement and acts independently to improve and increase skills and knowledge.
Specific Expected Contributions
- Conducts thorough penetration testing of infrastructure, web applications, APIs, and cloud environments to identify vulnerabilities and potential attack vectors.
- Collaborates with application development teams to implement security testing practices early in the software development lifecycle (SDLC), ensuring secure code and configurations.
- Reviews application development processes to ensure secure coding practices are followed, identifying vulnerabilities in the development, staging, and production environments.
- Leads red team exercises simulating advanced persistent threats (APTs) to assess the organization's security resilience in real-world attack scenarios.
- Collaborates closely with blue team members to provide feedback on detection and response efforts and support the development of effective defenses.
- Maps offensive security test results to the MITRE ATT&CK framework to ensure comprehensive understanding of adversary tactics, techniques, and procedures (TTPs).
- Executes vulnerability assessments and perform threat simulations to evaluate the effectiveness of security controls in place.
- Conducts vulnerability validation, including verifying the exploitability of identified vulnerabilities and conducting follow-up testing to confirm remediation.
- Leads and mentor junior security analysts, providing guidance on offensive security techniques and tools.
- Develops and refines testing methodologies, including custom attack scenarios to improve the organization's testing capabilities.
- Collaborates with IT, security engineering, and development teams to ensure vulnerabilities are prioritized and remediated effectively.
- Documents and communicates findings, providing clear, actionable recommendations to improve security across technology platforms.
- Stays up to date with emerging threats and vulnerability trends, continuously improving security testing practices and capabilities.
Candidate Profile
Successful candidates should possess knowledge, experience, and demonstrate leadership skills as follows:
Generally, a professional position with specific knowledge in a discipline (e.g., Accounting, Human Resources, Information Resources). College degree and/or relevant experience typically required.
Specific Candidate Profile
Education
- Bachelor's degree in computer science, Information Security, or a related field. Equivalent work experience may be considered in lieu of a degree.
Certifications Preferred
- Offensive Security Certified Professional (OSCP)
- Certified Ethical Hacker (CEH)
- GIAC Penetration Tester (GPEN)
- Offensive Security Web Expert (OSWE)
- Certified Secure Software Lifecycle Professional (CSSLP)
- GIAC Web Application Penetration Tester (GWAPT)
Experience
- At least 4 years of experience in offensive security roles, including penetration testing, red teaming, and application security testing.
- Hands-on experience with penetration testing tools (e.g., Burp Suite, Metasploit, Kali Linux, Cobalt Strike) and custom scripting for security testing.
- Proven expertise in identifying and exploiting vulnerabilities in applications, including web applications, mobile apps, APIs, and cloud platforms.
- Experience working with modern development practices, including DevSecOps, CI/CD pipelines, and integrating security testing into the software development lifecycle (SDLC).
- Deep knowledge of application security testing methods, including static analysis, dynamic analysis, and fuzzing.
- Familiarity with security practices such as Secure Development Lifecycle (SDL), Secure Code Reviews, and application security code scanning.
- Experience with cloud platforms (AWS, Azure, GCP) and container security (e.g., Docker, Kubernetes).
- Ability to map attack scenarios to the MITRE ATT&CK framework and provide insights for improving security defenses.
Skills/Attributes
- Advanced Penetration Testing Skills: Deep knowledge of testing web and mobile applications, APIs, and cloud services for vulnerabilities, with strong experience exploiting weaknesses to simulate real-world attacks.
- Application Security Expertise: Extensive experience with application security practices, secure code reviews, and vulnerability scanning tools.
- Secure Development Knowledge: Strong understanding of application development methodologies (e.g., Agile, DevOps) and experience incorporating security into development processes and pipelines.
- Red Team Expertise: Ability to simulate sophisticated attack techniques and scenarios, providing insight into potential attack paths and evaluating the organization's defenses.
- Cloud Security Knowledge: Solid understanding of cloud security best practices, including securing cloud environments (AWS, Azure) and containerized applications (Docker, Kubernetes).
- Vulnerability Management & Exploitability: Expertise in validating vulnerabilities, assessing their risk, and verifying exploitability across a wide range of systems.
- Incident Response Collaboration: Ability to work with incident response teams to translate offensive testing results into actionable intelligence for defensive improvements.
- Strong Documentation and Reporting Skills: Ability to document testing methodologies, findings, and recommendations clearly and concisely, and communicate technical issues to both technical and non-technical stakeholders.
- Mentorship & Leadership: Ability to lead and mentor junior security team members, promoting a culture of continuous improvement in offensive security practices.
- Problem-Solving & Analytical Thinking: Strong problem-solving skills, with the ability to think like an attacker to uncover vulnerabilities and develop strategies for exploitation and risk mitigation.
Marriott Vacations Worldwide is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture.
-
Cyber Security Operations Analyst
1 week ago
Orlando, Florida, United States H2 Performance Consulting Full timeH2 Performance Consulting is an Equal Opportunity/Affirmative Action Employer and strives to build a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status or disability status. As a...
-
Security Analyst
21 hours ago
Orlando, Florida, United States ThreatLocker Full timeCOMPANY OVERVIEWThreatLocker is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker platform with Application Allowlisting, Ringfencing, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert...
-
Epic Security Analyst II
4 days ago
Orlando, Florida, United States Orlando Health Full timePosition SummaryDepartment: Information TechnologyStatus: Full-TimeShift: Monday - Friday, 8am-5pm, hybrid(2x a week onsite) in Orlando, FLOn Call Required*At Orlando Health, we are ordinary people with extraordinary individuality, working together to bring help, healing and hope to those we serve. By daily embodying our over 100-year legacy, we reinforce...
-
Application Security Engineer
6 days ago
Orlando, Florida, United States Compunnel Inc. Full timeSenior Software Engineer – Application Security -- MAZDC5693188Sales Executive -- Anindya MazumdarJob DescriptionWe are seeking a Senior Software Engineer with strong expertise in application security to join a forward-thinking technology team focused on enhancing secure software development practices. This role combines deep technical knowledge with the...
-
TRIRIGA Corporate Applications Analyst
2 weeks ago
Orlando, Florida, United States MSR Technology Group Full time $80,000 - $120,000 per yearJob Title:TRIRIGA Corporate Applications AnalystLocation:Burbank, CA or Orlando, FL (Onsite role)Mandatory skill:"IBM Tririga, Jboss, Apache, Java(J2EE) SFTP Integration & InteroperabilityExperience integrating TRIRIGA with other enterprise systems (e.g., ERP, HRMS) using APIs or middleware for seamless data exchange".Job Summary:We are looking for a skilled...
-
Orlando, Florida, United States Siemens Full timeJob ID486351Posted since24-Nov-2025OrganizationChief Executive's OfficeField of workInternal ServicesCompanySiemens CorporationExperience levelEarly ProfessionalJob typeFull-timeWork modeHybrid (Remote/Office)Employment typePermanentLocation(s)Orlando - Florida - United States of AmericaArtificial Intelligence and Physical Security Analyst – AI & Machine...
-
Security Guard
2 weeks ago
Orlando, Florida, United States Admiral Security Services Full time $35,000 - $65,000 per yearAdmiral Security Services was established in 1976 and has consistently grown for over four decades. Today, we service hundreds of locations nationally, provide security coverage to millions of square feet of public and private facilities, and are one of the top 10 largest security companies in the United States.Now is your opportunity to join our...
-
Armed Security Officer
5 hours ago
Orlando, Florida, United States Platinum Group Security Full timeJoin Platinum Group Security – Protecting What Matters Since 1996 Are you ready to take your career to the next level with a trusted leader in the security industry? Since 1996, Platinum Group Security has been dedicated to providing exceptional security solutions across America. We're on a mission to find the best security professionals to join our...
-
Unarmed Security Officer
2 weeks ago
Orlando, Florida, United States CMG Security Services Full time $32,000 per yearWe are currently hiring for a weekend Security Officer to work Saturday and Sunday from 6am to 6pm . This is a post requiring attentiveness, professionalism, and a strong sense of responsibility.Key Responsibilities:Perform regular walkthroughs and patrols inside / outside the facilityComplete daily reports and wellness checks accurately and on timeRespond...
-
Sr SOC Analyst
2 weeks ago
Orlando, Florida, United States ExecutivePlacements Full time $80,000 - $120,000 per yearJoin to apply for theSr SOC Analystrole atKavaliroJoin to apply for theSr SOC Analystrole atKavaliroGet AI-powered advice on this job and more exclusive features.Job DescriptionKavaliro is seeking an Sr SOC Analyst to support a client onsite in Orlando, FL.Roles And ResponsibilitiesAct as a senior escalation point for cybersecurity alerts, threats, and...