Jobs · Engineering · Michigan

Application Security Analyst

Stellantis · Auburn Hills, MI · 2 days ago
EngineeringFull-time

About the role

This role focuses on identifying, analyzing, and mitigating application security vulnerabilities throughout the SDLC. It supports a broader "Shift Left" cybersecurity strategy, ensuring security is integrated early in development and reinforced through DevSecOps practices.

Responsibilities

  • Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing
  • Analyze vulnerabilities and recommend secure coding fixes
  • Demonstrate vulnerabilities to development teams
  • Drive remediation efforts to closure
  • Work within CI/CD pipelines using tools such as Jenkins, GitLab, GitHub Actions, TeamCity, Checkmarx, GitHub Advanced Security, and Burp Suite
  • Integrate security controls into development workflows
  • Lead Web Application Firewall (WAF) deployment for new and existing apps
  • Implement application security policies, controls, and standards
  • Partner with development, platform, and supplier teams
  • Provide clear remediation guidance
  • Train teams on secure coding and application security practices
  • Develop training materials
  • Conduct security assessments using standard tools
  • Track and report risks, milestones, deliverables, and status updates
  • Recommend strategies based on application risk posture

Basic Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or related field
  • 3+ years of hands-on experience in application security, security testing, and DevSecOps
  • Strong understanding of application architectures (web, mobile, APIs), software development methodologies (Agile, SDLC), and modern programming languages (Java, C#, Python)
  • Experience performing and interpreting results from SAST, DAST, IAST, SCA, and mobile security testing tools
  • Hands-on experience with secure code review in common languages (Java, C#, Python preferred)
  • Prior background in application development, including compiled code, web applications/services, and mobile app development
  • Knowledge of security frameworks and standards: NIST, ISO 27001, NIST SSDF or similar secure development frameworks
  • Strong understanding of OWASP Top 10 vulnerabilities and mitigation techniques, and common attack vectors (web exploits, DDoS, bot attacks)
  • Experience with WAF technologies: Akamai, Cloudflare, AWS WAF, Azure Front Door
  • Familiarity with cloud platforms and modern environments: AWS, Azure, GCP, containers (Docker, Kubernetes)
  • Working knowledge of programming/scripting: Java, JavaScript, SQL, HTML; scripting languages (Python, Bash preferred)
  • Strong analytical, problem-solving, and communication skills
  • Ability to explain technical risks to non-technical audiences
  • Experience writing security reports and documentation
  • Ability to work independently and cross-functionally

Preferred Qualifications

  • Industry certifications: GIAC GWEB, ISC2 CSSLP, EC-Council CASE, or equivalent AppSec certifications

Benefits

  • Comprehensive health and well-being coverage from day one, including medical, dental, vision, and prescription drug coverage, plus an Employee Assistance Program (EAP)
  • Family building benefit supporting fertility and infertility treatments, adoption services, and gestational surrogacy
  • Generous paid time off including 17+ paid holidays, shutdown from December 24th through New Year's Day, vacation, float and wellbeing days, sick time, and fully paid parental leave
  • Competitive retirement savings plans with employer match on 401k, Roth, and Catch-Up plans, plus an employer contribution even if you don't contribute
  • Income protection and insurance options including life insurance, group accident, critical illness, and more
  • Company vehicle lease program with insurance, maintenance, and unlimited miles included for eligible employees and their immediate families, plus exclusive discounts on Stellantis products
  • Tuition reimbursement, student loan refinancing programs, and 18 paid volunteer hours each year

Schedule

This role is based in Auburn Hills, MI and is required to be on-site in the HQ building 5 days per week.

This response is AI-generated, for reference only.

Similar jobs