Job Description Title: APPLICATION SECURITY VULNERABILITY ANALYST Visas: USC/GC Need LinkedIn, VISA DL 100% REMOTE NO FAKE GREEN CARDS 14+ Years of exp This is an Application Security / AppSec vulnerability role, not a traditional SOC Analyst, infrastructure vulnerability scanner, or generic Vulnerability Management position. The core of the role is hands-on analysis and validation of findings coming from SAST, SCA, and AI-assisted application security tools. The person needs to be technically capable of looking at the underlying application code, investigating the finding, and determining whether it represents a legitimate security issue or a false positive before unnecessarily involving the development team This is a remote role; candidates must work EST business hours. Responsibilities: Review and analyze vulnerabilities identified through SAST, SCA, AI-based, and related application security tools. Perform hands-on review of application source code to validate security findings and determine whether identified vulnerabilities represent legitimate risk. Triage findings before engaging development teams, with a focus on identifying false positives and minimizing non-actionable issues. Evaluate vulnerabilities beyond vendor-assigned severity scores by considering exploitability, exposure, attack paths, business impact, compensating controls, and application context. Validate vulnerability classifications, severity recommendations, and remediation priority. Utilize AI tools and effective prompting techniques to analyze security findings, increase confidence in finding credibility, and reduce false positives. Assess vulnerability trends and recurring development patterns that may require broader corrective action. Explain validated application security findings clearly to developers, architects, technology owners, and business stakeholders. Provide actionable remediation guidance and secure coding recommendations. Partner with developers and technology owners to drive validated vulnerabilities through remediation and closure within defined SLAs. Track remediation progress and escalate aging findings or remediation blockers as appropriate. Validate completed remediation activities and make closure recommendations. Support vulnerability triage and vulnerability management activities across multiple application security tools. Participate in vulnerability review sessions and remediation discussions. Maintain accurate documentation of risk decisions, remediation guidance, and disposition rationale. Contribute to application security procedures, reporting, and process improvements. Required Skills: 3+ years of experience in Application Security, Application Vulnerability Management, or a closely related cybersecurity discipline. Hands-on experience reviewing and validating application security findings generated by SAST and SCA tools . Strong application security vulnerability analysis and triage experience, including the ability to distinguish legitimate vulnerabilities from false positives. Hands-on technical ability to review source code and validate security findings at the code/application level before escalating issues to development teams. Ability to evaluate vulnerabilities based on actual exploitability, exposure, attack paths, application context, compensating controls, and business risk rather than relying solely on CVSS scores. Strong understanding of application security concepts and practices, including: OWASP Top 10 Common Weakness Enumeration (CWE) Secure Software Development Lifecycle (SSDLC) Exploit Prediction Scoring System (EPSS) CVE/CVSS concepts Ability to analyze application security findings involving one or more modern enterprise development languages, including Java, TypeScript, JavaScript, C#, Python, Go, Node.js, or similar languages. Hands-on experience using AI tools to support application security or vulnerability analysis , including the ability to create effective prompts to validate findings, improve analysis, and reduce false positives. Strong written and verbal communication skills with the ability to clearly communicate technical security findings. Strong organizational skills with the ability to manage multiple vulnerability analysis and remediation efforts simultaneously. Demonstrated ability to work independently and drive issues toward resolution. Preferred Skills: Experience working directly with development teams to explain vulnerabilities, provide remediation guidance, and drive findings through closure. Experience with AppScan, Snyk, ZAP , or comparable application security tools. Experience with Claude Code or similar AI-assisted security/development tools. Secure code review experience. Application security testing experience. CI/CD security integration experience. Experience with SCA tools and software dependency risk analysis. Understanding of software architecture and common web application attack patterns. Working knowledge of cloud-native applications and APIs. Familiarity with enterprise vulnerability management processes, remediation SLAs, and tracking workflows. Security certifications such as Security+, CSSLP, GWEB, GWAPT, CySA+, OSWE, or similar. Education: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field preferred, or equivalent relevant professional experience. Kind Regards, Deep Patel Sr. Technical Recruiter ZealHire Inc. Email: Deep@zealhire.com Direct: (609) 337-2510 14 Wall Street 20th Floor | New York, NY 10005 www.zealhire.com Related