Description :
Cybersecurity Analyst (Application Security - AppSec)
About the Role :
The Cybersecurity Analyst with an Application Security (AppSec) focus will be embedded within our development teams to identify, triage, and remediate security vulnerabilities across our software development lifecycle.
You will champion security-first coding practices and ensure our applications meet stringent compliance standards.
Key Responsibilities :
- Perform static (SAST) and dynamic (DAST) application security testing on pre-production and production codebases.
- Conduct manual and automated penetration testing to discover and validate security flaws (e.g., OWASP Top 10).
- Work directly with development teams to provide actionable guidance and remediation solutions for identified vulnerabilities.
- Integrate security tools and processes into the CI / CD pipeline (DevSecOps), shifting security left in the development process.
- Manage and triage security alerts from bug bounty programs and internal reporting channels.
- Develop and deliver security awareness training to the engineering organization.
Technical Skills Required :
4+ years of experience in Application Security, Penetration Testing, or a related cybersecurity role.Strong understanding of secure coding principles and common web application vulnerabilities (e.g., SQL Injection, XSS, CSRF).Hands-on experience with security tools such as Burp Suite, OWASP ZAP, Nessus, or Fortify.Familiarity with at least one major programming language's security pitfalls (Java, Python, or Node.js).Knowledge of cloud security concepts (IAM, security groups, WAF) on AWS / Azure / GCP.Relevant certifications like OSCP, CISSP, or CEH are highly desirable(ref : hirist.tech)