Job Description
Title: APPLICATION SECURITY VULNERABILITY ANALYST
Visas: USC/GC
Need LinkedIn, VISA DL
100% REMOTE
NO FAKE GREEN CARDS
14+Â Years of exp
Â
This is an Application Security / AppSec vulnerability role, not a traditional SOC Analyst, infrastructure vulnerability scanner, or generic Vulnerability Management position.
The core of the role is hands-on analysis and validation of findings coming from SAST, SCA, and AI-assisted application security tools. The person needs to be technically capable of looking at the underlying application code, investigating the finding, and determining whether it represents a legitimate security issue or a false positive before unnecessarily involving the development team
Â
This is a remote role; candidates must work EST business hours.
Responsibilities:
- Review and analyze vulnerabilities identified through SAST, SCA, AI-based, and related application security tools.
- Perform hands-on review of application source code to validate security findings and determine whether identified vulnerabilities represent legitimate risk.
- Triage findings before engaging development teams, with a focus on identifying false positives and minimizing non-actionable issues.
- Evaluate vulnerabilities beyond vendor-assigned severity scores by considering exploitability, exposure, attack paths, business impact, compensating controls, and application context.
- Validate vulnerability classifications, severity recommendations, and remediation priority.
- Utilize AI tools and effective prompting techniques to analyze security findings, increase confidence in finding credibility, and reduce false positives.
- Assess vulnerability trends and recurring development patterns that may require broader corrective action.
- Explain validated application security findings clearly to developers, architects, technology owners, and business stakeholders.
- Provide actionable remediation guidance and secure coding recommendations.
- Partner with developers and technology owners to drive validated vulnerabilities through remediation and closure within defined SLAs.
- Track remediation progress and escalate aging findings or remediation blockers as appropriate.
- Validate completed remediation activities and make closure recommendations.
- Support vulnerability triage and vulnerability management activities across multiple application security tools.
- Participate in vulnerability review sessions and remediation discussions.
- Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale.
- Contribute to application security procedures, reporting, and process improvements.
Required Skills:
- 3+ years of experience in Application Security, Application Vulnerability Management, or a closely related cybersecurity discipline.
- Hands-on experience reviewing and validating application security findings generated by SAST and SCA tools.
- Strong application security vulnerability analysis and triage experience, including the ability to distinguish legitimate vulnerabilities from false positives.
- Hands-on technical ability to review source code and validate security findings at the code/application level before escalating issues to development teams.
- Ability to evaluate vulnerabilities based on actual exploitability, exposure, attack paths, application context, compensating controls, and business risk rather than relying solely on CVSS scores.
- Strong understanding of application security concepts and practices, including:
- OWASP Top 10
- Common Weakness Enumeration (CWE)
- Secure Software Development Lifecycle (SSDLC)
- Exploit Prediction Scoring System (EPSS)
- CVE/CVSS concepts
- Ability to analyze application security findings involving one or more modern enterprise development languages, including Java, TypeScript, JavaScript, C#, Python, Go, Node.js, or similar languages.
- Hands-on experience using AI tools to support application security or vulnerability analysis, including the ability to create effective prompts to validate findings, improve analysis, and reduce false positives.
- Strong written and verbal communication skills with the ability to clearly communicate technical security findings.
- Strong organizational skills with the ability to manage multiple vulnerability analysis and remediation efforts simultaneously.
- Demonstrated ability to work independently and drive issues toward resolution.
Preferred Skills:
- Experience working directly with development teams to explain vulnerabilities, provide remediation guidance, and drive findings through closure.
- Experience with AppScan, Snyk, ZAP, or comparable application security tools.
- Experience with Claude Code or similar AI-assisted security/development tools.
- Secure code review experience.
- Application security testing experience.
- CI/CD security integration experience.
- Experience with SCA tools and software dependency risk analysis.
- Understanding of software architecture and common web application attack patterns.
- Working knowledge of cloud-native applications and APIs.
- Familiarity with enterprise vulnerability management processes, remediation SLAs, and tracking workflows.
- Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, or similar.
Education:
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field preferred, or equivalent relevant professional experience.
Â
Â
Kind Regards,
Â
Deep Patel
Sr. Technical Recruiter
ZealHire Inc.
Direct: ​ (609) 337-2510
14 Wall Street 20th Floor | New York, NY 10005

Â