Haystack
← Back to Jobs
Technology
SO

AWS Application Security Analyst

System OneLafayette, LA🇺🇸United StatesPosted Sep 19, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Lafayette, LA, United States
Posted
Yesterday
JavaScriptPythonJavaC#AWSJenkinsEncryption

Job Description

AWS Application Security Analyst
Job Type: Permanent Full-Time
Work Model: Hybrid
Locations: Birmingham, AL | Knoxville, TN | Columbia, SC | Lafayette, LA

Visa: (No Sponsorship)
Position Overview
We are seeking an experienced AWS Application Security Analyst to support application security initiatives within a large-scale financial services environment.
This role will partner closely with software development, cloud, DevOps, and cybersecurity teams to identify, assess, and remediate security risks throughout the Software Development Lifecycle (SDLC).
The ideal candidate will have strong hands-on experience with application security testing, SAST, DAST, SCA, threat modeling, secure code review, DevSecOps, CI/CD security integration, AWS security, and container security.
Responsibilities

  • Perform manual and automated application and source-code security reviews to identify vulnerabilities and security risks.
  • Conduct threat modeling and application security risk assessments for new and existing applications.
  • Work with development teams to determine appropriate remediation approaches for security findings.
  • Utilize SAST, DAST, and Software Composition Analysis (SCA) tools for application security testing.
  • Integrate application security controls and automated security testing into CI/CD pipelines.
  • Evaluate application security risks across AWS cloud and containerized environments.
  • Apply knowledge of secure coding practices, network protocols, encryption, authentication, and common application vulnerabilities.
  • Partner with development, DevOps, cloud, and cybersecurity teams to strengthen DevSecOps practices throughout the SDLC.
  • Develop security guidance, FAQs, standards, and reusable application security best practices for development teams.
  • Clearly communicate vulnerabilities, security risks, and remediation recommendations to technical stakeholders.
Required Qualifications
  • 5+ years of application security experience and strong knowledge of secure software development practices.
  • Hands-on experience with SAST, DAST, and SCA tools.
  • Experience performing manual code reviews and application security assessments.
  • Strong experience with threat modeling and security risk assessments.
  • Working knowledge of AWS security and securing applications deployed in AWS environments.
  • Experience with DevSecOps and integrating security testing into CI/CD pipelines.
  • Experience with GitHub, Jenkins, or similar CI/CD platforms.
  • Understanding of container security and associated application security risks.
  • Programming or code-review experience with Java, Python, JavaScript, C#, or similar languages.
  • Strong understanding of:
    • Network protocols
    • Encryption
    • Authentication and authorization
    • Secure coding practices
    • Common application vulnerabilities
  • Strong communication skills with the ability to explain security findings and remediation recommendations to developers and technical teams.
Preferred Qualifications
  • Experience within financial services, banking, or another highly regulated environment.
  • Relevant security or cloud certifications such as:
    • AWS Certified Security – Specialty
    • CISSP
    • CSSLP
    • GIAC Application Security certifications

Education
Bachelor's degree in **Computer Science, Information Systems, Cybersecurity, or a related
#M1
#DI-CB2
#L1 - KB1


Ref: #404-IT Pittsburgh

Similar jobs