Haystack
← Back to Jobs
Remote
Technology
SG

Application Security Vulnerability Analyst

Software Guidance & AssistanceNew York, NY🇺🇸United StatesPosted 8 Sept 2026

Why This Role Stands Out

This remote Application Security Vulnerability Analyst role offers a fantastic opportunity to refine your expertise by evaluating and prioritizing security risks for a leading insurance client, leveraging cutting-edge AI tools. If you excel at translating complex technical findings into actionable insights for diverse stakeholders and driving remediation efforts, you'll thrive in this dynamic environment. Apply today to make a significant impact on application security and advance your career!

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
New York, NY, United States
Posted
Yesterday
JavaScriptTypeScriptPythonJavaC#Node.jsSonarQubeOWASP

Job Description

Software Guidance & Assistance, Inc., (SGA), is searching for an Application Security Vulnerability Analyst for a contractor assignment with one of our premier Insurance Services clients. This is a remote role; candidates must work EST business hours.
Responsibilities:
  • Review vulnerabilities identified through AI-based SAST, SCA, and related application security tools.
  • Evaluate vulnerabilities beyond vendor-assigned severity scores by considering exploitability, exposure, attack paths, business impact, compensating controls, and application context.
  • Distinguish between theoretical findings and vulnerabilities that present realistic application and business risk.
  • Validate vulnerability classifications and severity recommendations.
  • Identify false positives, duplicate findings, and opportunities for risk-based prioritization.
  • Utilize AI and effective prompting techniques to increase confidence in findings and reduce false positives.
  • Assess vulnerability trends and recurring development patterns that may require broader corrective action.
  • Explain application security findings clearly to developers, architects, technology owners, and business stakeholders.
  • Provide actionable remediation guidance and secure coding recommendations.
  • Assist application teams in understanding root causes and recommended fixes.
  • Partner with developers and technology owners to establish remediation plans and drive findings to closure.
  • Track remediation progress and ensure vulnerabilities are addressed within defined SLAs.
  • Escalate aging findings and remediation blockers as appropriate.
  • Validate completed remediation activities and make closure recommendations.
  • Support vulnerability triage activities across multiple application security tools.
  • Participate in vulnerability review sessions and remediation discussions.
  • Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.
  • Contribute to application security procedures, reporting, and process improvements.
Required Skills:
  • 3+ years of experience in Application Security, Vulnerability Management, Security Risk Management, or a related cybersecurity discipline.
  • Strong understanding of application security and vulnerability management, including:
    • OWASP Top 10
    • Common Weakness Enumeration (CWE)
    • Secure Software Development Lifecycle (SSDLC)
    • Exploit Prediction Scoring System (EPSS)
    • CVE/CVSS concepts
  • Experience reviewing and validating findings generated by SAST, SCA, or related application security tools.
  • Ability to evaluate vulnerabilities based on actual exploitability, exposure, application context, and business risk rather than relying solely on CVSS scores.
  • Experience identifying false positives and validating vulnerability classifications and severity.
  • Experience working directly with development teams to remediate application vulnerabilities.
  • Ability to understand application security findings involving one or more modern enterprise development languages, including Java, TypeScript, JavaScript, C#, Python, Go, or Node.js.
  • Experience using AI-based security tools or AI-assisted security analysis.
  • Ability to provide developers with actionable remediation and secure coding guidance.
  • Strong written and verbal communication skills with the ability to translate technical findings into clear, business-relevant language.
  • Strong organizational skills and the ability to manage multiple remediation efforts simultaneously.
  • Demonstrated ability to work independently and drive issues through resolution.
Preferred Skills:
  • Experience with SAST tools such as SonarQube, Snyk Code, Checkmarx, Veracode, GitHub Advanced Security, or similar.
  • Experience with SCA tools and software dependency risk analysis.
  • Application security testing and secure code review experience.
  • CI/CD security integration experience.
  • Experience with Claude Code or similar AI-assisted security/development tools.
  • Understanding of software architecture and common web application attack patterns.
  • Working knowledge of cloud-native applications and APIs.
  • Familiarity with enterprise vulnerability management and remediation tracking workflows.
  • Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, or similar.
Education:
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field preferred, or equivalent relevant professional experience.
By applying for a job with SGA, you agree to allow SGA to process your application for this and future opportunities in accordance with our Privacy Policy. Also, to ensure timely processing, you agree to be contacted by our AI recruiter via email, text, or phone. Message frequency varies and data rates may apply, but you can reply STOP to any SMS message to opt-out of texts and may contact SGA at to opt-out of AI communications. The choice not to engage with AI will not adversely impact your consideration for placement. AI is not used to make any hiring determinations.

SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .

SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.

Similar jobs