Application Security Risk & Automation Analyst
Application Security Risk & Automation Analyst
Location: Remote
Employment Type: Contract
Schedule: Full-Time | 8 hours per day
Industry: Financial Services / Cybersecurity
Labor Category: Technical
Position Overview
We are seeking an experienced Application Security Risk & Automation Analyst to support the automation and operationalization of Secure Software Development Lifecycle (Secure SDLC) processes and application security capabilities.
This role will focus on integrating security into modern development workflows, reducing developer friction, improving vulnerability remediation, and automating security findings management. The ideal candidate will bring strong application security knowledge, hands-on experience with GitLab security controls, and the ability to use APIs, scripting, automation, and AI-assisted workflows to improve security operations.
Key Responsibilities
-
Validate application security findings and support risk-based prioritization and false-positive reduction.
-
Configure and maintain GitLab security approval workflows, Secure Merge Request controls, approval policies, and security enforcement gates.
-
Support implementation of AI-assisted security triage, remediation recommendations, and automated findings management.
-
Build and maintain automation for security finding enrichment, correlation, routing, deduplication, and reporting.
-
Integrate application security platforms with GitLab, ServiceNow, Jira, and enterprise reporting solutions.
-
Partner with development and engineering teams to improve vulnerability remediation outcomes and adoption of security workflows.
-
Support onboarding, implementation, and operationalization of new application security tools and capabilities.
-
Help embed security controls throughout the Secure SDLC and DevSecOps lifecycle.
-
Support software supply chain security and dependency-management initiatives.
-
Identify opportunities to reduce manual security processes through APIs, scripting, and workflow automation.
Required Qualifications
-
Strong knowledge of Application Security concepts and the OWASP Top 10.
-
Hands-on experience with application security testing technologies, including:
-
SAST – Static Application Security Testing
-
DAST – Dynamic Application Security Testing
-
SCA – Software Composition Analysis
-
Container Security
-
Secrets Detection
-
-
Experience configuring GitLab security controls, approval workflows, merge request controls, and policy-based enforcement.
-
Experience integrating security platforms with GitLab, ServiceNow, Jira, and/or enterprise reporting platforms.
-
Experience using APIs, scripting, and automation to improve security operations and application security workflows.
-
Understanding of Secure SDLC, DevSecOps, software supply chain security, and dependency management.
-
Ability to analyze security findings, identify false positives, assess risk, and help prioritize remediation.
-
Strong communication and collaboration skills with the ability to work effectively with software development and engineering teams.
Preferred Qualifications
-
Experience implementing or supporting AI-assisted security workflows, including automated triage and remediation recommendations.
-
Experience automating vulnerability or security findings management at enterprise scale.
-
Experience onboarding and operationalizing new AppSec platforms and security capabilities.
-
Experience working in large, complex enterprise technology environments.
Key Technologies
Application Security: SAST, DAST, SCA, Container Security, Secrets Detection
DevSecOps: GitLab, GitLab Secure, CI/CD security controls
Workflow & Integration: ServiceNow, Jira, APIs
Automation: Scripting, workflow automation, AI-enabled security processes
Required Skills
Required Languages
🇬🇧 English