Application Security Analyst
Stellantis · Auburn Hills, MI · 2 days ago
EngineeringFull-time
About the role
This role focuses on identifying, analyzing, and mitigating application security vulnerabilities throughout the SDLC. It supports a broader "Shift Left" cybersecurity strategy, ensuring security is integrated early in development and reinforced through DevSecOps practices.
Responsibilities
- Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing
- Analyze vulnerabilities and recommend secure coding fixes
- Demonstrate vulnerabilities to development teams
- Drive remediation efforts to closure
- Work within CI/CD pipelines using tools such as Jenkins, GitLab, GitHub Actions, TeamCity, Checkmarx, GitHub Advanced Security, and Burp Suite
- Integrate security controls into development workflows
- Lead Web Application Firewall (WAF) deployment for new and existing apps
- Implement application security policies, controls, and standards
- Partner with development, platform, and supplier teams
- Provide clear remediation guidance
- Train teams on secure coding and application security practices
- Develop training materials
- Conduct security assessments using standard tools
- Track and report risks, milestones, deliverables, and status updates
- Recommend strategies based on application risk posture
Basic Qualifications
- Bachelor's degree in Computer Science, Information Technology, or related field
- 3+ years of hands-on experience in application security, security testing, and DevSecOps
- Strong understanding of application architectures (web, mobile, APIs), software development methodologies (Agile, SDLC), and modern programming languages (Java, C#, Python)
- Experience performing and interpreting results from SAST, DAST, IAST, SCA, and mobile security testing tools
- Hands-on experience with secure code review in common languages (Java, C#, Python preferred)
- Prior background in application development, including compiled code, web applications/services, and mobile app development
- Knowledge of security frameworks and standards: NIST, ISO 27001, NIST SSDF or similar secure development frameworks
- Strong understanding of OWASP Top 10 vulnerabilities and mitigation techniques, and common attack vectors (web exploits, DDoS, bot attacks)
- Experience with WAF technologies: Akamai, Cloudflare, AWS WAF, Azure Front Door
- Familiarity with cloud platforms and modern environments: AWS, Azure, GCP, containers (Docker, Kubernetes)
- Working knowledge of programming/scripting: Java, JavaScript, SQL, HTML; scripting languages (Python, Bash preferred)
- Strong analytical, problem-solving, and communication skills
- Ability to explain technical risks to non-technical audiences
- Experience writing security reports and documentation
- Ability to work independently and cross-functionally
Preferred Qualifications
- Industry certifications: GIAC GWEB, ISC2 CSSLP, EC-Council CASE, or equivalent AppSec certifications
Benefits
- Comprehensive health and well-being coverage from day one, including medical, dental, vision, and prescription drug coverage, plus an Employee Assistance Program (EAP)
- Family building benefit supporting fertility and infertility treatments, adoption services, and gestational surrogacy
- Generous paid time off including 17+ paid holidays, shutdown from December 24th through New Year's Day, vacation, float and wellbeing days, sick time, and fully paid parental leave
- Competitive retirement savings plans with employer match on 401k, Roth, and Catch-Up plans, plus an employer contribution even if you don't contribute
- Income protection and insurance options including life insurance, group accident, critical illness, and more
- Company vehicle lease program with insurance, maintenance, and unlimited miles included for eligible employees and their immediate families, plus exclusive discounts on Stellantis products
- Tuition reimbursement, student loan refinancing programs, and 18 paid volunteer hours each year
Schedule
This role is based in Auburn Hills, MI and is required to be on-site in the HQ building 5 days per week.
This response is AI-generated, for reference only.