Hiring.Camp

Security Analyst/Sr. Security Analyst (Application Security)-ITDSGGR (Contractual)

Imf

·

4 days ago

Location
IMF Headquarters 2, United States
Type
Contract
Department
Security
Closing date
Today
Source
Workday

Description

Work for the IMF. Work for the World.

 

The Security Analyst  (Application Security) supports the integration of security throughout the Software Development Lifecycle (SDLC) by partnering with development, infrastructure, and application teams to embed secure development practices, implement security requirements, and strengthen the overall security posture of enterprise applications. The role is responsible for identifying, validating, prioritizing, tracking, and supporting the remediation of application security vulnerabilities, while driving risk-based vulnerability management activities and application security initiatives across on-premises and cloud environments. The successful candidate combines hands-on expertise in application security and vulnerability management with the ability to provide actionable guidance, support secure software development, and continuously improve security outcomes through governance, metrics, reporting, and security best practices.

Major Duties and Responsibilities

Vulnerability Management & Risk Management

  • Lead the identification, validation, prioritization, tracking, and remediation of application security vulnerabilities, ensuring risks are addressed in accordance with established timelines and organizational priorities.
  • Partner with application owners and engineering teams to manage vulnerability workflows, including intake, analysis, assignment, risk-based prioritization, exception handling, remediation tracking, and escalation of critical issues.
  • Provide risk-based remediation recommendations and guidance to application teams to support informed security decisions and risk reduction efforts.

Application Security & Secure SDLC

  • Support the integration of security throughout the Software Development Lifecycle (SDLC) by promoting secure coding practices, implementing security requirements, participating in threat modeling and design reviews, and helping implement security controls across on-premises and cloud environments.
  • Lead and support the adoption of application security testing capabilities, including SAST, DAST, and SCA solutions within CI/CD pipelines, while reviewing security findings, validating results, and providing remediation guidance.

Governance, Reporting & Security Enablement

  • Maintain visibility into application security posture through tracking, analysis, and reporting of vulnerability status, severity, aging, ownership, exceptions, remediation progress, and risk trends using enterprise platforms.
  • Stay current with emerging threats, vulnerabilities, and industry best practices while supporting security awareness, developer enablement, and continuous improvement of application security processes and standards.

Minimum Qualifications

  • Educational development, typically acquired by the completion of an advanced university degree, or equivalent, in Computer Science, Cybersecurity, or related field, supplemented by a minimum of four (4) years of relevant, professional work experience, is required. Alternatively, a university degree, or equivalent, and ten (10) years of relevant professional experience, is required.
  • Experience in Vulnerability Management, Application Security, Secure Development or related cybersecurity disciplines.
  • Strong knowledge of application security principles, secure software development practices, and industry frameworks such as OWASP Top 10, NIST SSDF, NIST CSF, and ISO 27001.
  • Experience with one or more programming or scripting languages (e.g., Java, Python, .NET, PowerShell) and the ability to analyze application security findings and support remediation efforts.
  • Understanding of secure architecture principles for web, cloud, and enterprise applications, including common attack vectors and mitigation techniques.
  • Hands-on experience with application security testing methodologies and tools, including SAST, DAST, SCA, vulnerability assessments, and penetration testing.
  • Strong understanding of vulnerability management processes, including vulnerability validation, risk-based prioritization, remediation tracking, exception management, compensating controls, and vulnerability lifecycle management.
  • Experience collaborating with development and engineering teams to integrate security requirements and controls throughout the Software Development Lifecycle (SDLC).
  • Ability to analyze security risks, communicate technical findings to diverse audiences, and provide actionable remediation guidance.
  • Strong communication, analytical, stakeholder management, and collaboration skills, with the ability to influence security outcomes across cross-functional teams.

Preferred Qualifications

  • Security certifications, such as OSCP, SSCP, CEH, Security+, GIAC, CISSP, or equivalent.
  • Experience using ServiceNow, including native AI capabilities, and vulnerability management, ticketing, or reporting platforms to support remediation tracking and risk reporting.
  • Knowledge, certifications, and experience in Microsoft Azure, Azure DevOps, and Power BI for cloud operations, reporting, and data visualization.
  • Experience with enterprise application security tools, such as Burp Suite, Sonatype Nexus Lifecycle, Checkmarx, Fortify, HCL AppScan, Veracode, or similar solutions.

This is a one-year contractual appointment. Contractual appointments at the IMF are renewable for up to four years of cumulative contractual service, pending incumbent's performance, budget availability, and continuous business need.

Department:

ITDPVPM Information Technology Department Project and Vendor Management Project Portfolio Management Section

Hiring For:

A11, A12

The IMF is guided by the principle that the employment, classification, promotion, and assignment of staff shall be made without discrimination against any person. We welcome requests for reasonable accommodations for disabilities during the selection process. Information on how to request accommodations will be provided during the application process.

Skills

PythonJavaAzureCI/CDPower BIServiceNowCybersecurityPenetration TestingDevOpsRisk ManagementISO 27001CISSP

Similar Jobs

30

IT Security - Sr. Analyst

Default CKE Brand · Franklin, TN

1 month ago

Cyber Security Analyst Sr

Gdit · USA CA Beale AFB - Beale AFB (CAC003), United States of America

1 month ago

Cyber Security Analyst Sr

GDIT · USA CA Beale AFB - Beale AFB (CAC003), United States of America

1 month ago

Information Security Sr Analyst

Peak6Group · Belfast, United Kingdom · Hybrid

1 month ago

Cyber Security Analyst Sr

Gdit · USA CA Beale AFB - Beale AFB (CAC003), United States of America

1 month ago

Cyber Security Analyst Sr

GDIT · USA CA Beale AFB - Beale AFB (CAC003), United States of America

1 month ago

Workday Security Sr. Analyst

RSM · USA-MN-Minneapolis-801 Nicollet Mall, United States of America

2 months ago

Sr. Security Analyst - I.T.

Baker Group · Ankeny, IA

4 days ago

Security Analyst/Sr. Security Analyst (Application Security)-ITDSGGR (Contractual)

IMF works to foster global · IMF Headquarters 2, United States

4 days ago

Sr Analyst, Security

RTX · US-AZ-TUCSON-842 ~ 1151 E Hermans Rd ~ BLDG 842, United States of America · Onsite

5 days ago

Sr. Security Analyst

LevelBlue LLC · Poland

1 week ago

Sr. Security Analyst I (II)

PJM employees work collaboratively to · Audubon, United States of America · Hybrid

2 weeks ago

Sr. Security Analyst - MDR

Trendmicro · Irving, Texas, United States of America · Hybrid, Onsite

3 weeks ago

Sr. Analyst, Security - Goleta, CA

RTX · US-CA-GOLETA-H01 ~ 6380 Hollister Ave ~ BLDG H01, United States of America · Onsite

3 weeks ago

Sr. Security Analyst - Security Operations Center (SOC)

Lennar · Irving TX (Greenway), United States of America +1

1 month ago

Sr. Analyst, Security (Security Operations and Intelligence Center - CHII)

Cardinalhealth · IND07, India

1 month ago

Sr. Security Analyst

Warnerbros · Hyderabad - Phoenix Equinox Tower 2, India · Hybrid

1 month ago

Sr Security Analyst

Evermos · Kota Bandung,, Jawa Barat

1 month ago

Sr Security Analyst - Cloud Security

Lennox · Chennai, IN · Hybrid

1 month ago

Sr Analyst, Security (CSSO) - Tucson, AZ

RTX · US-AZ-TUCSON-842 ~ 1151 E Hermans Rd ~ BLDG 842, United States of America · Onsite

1 month ago

Sr. Security Analyst, Industrial Security (P2)

RTX · US-VA-CHESAPEAKE-305 ~ 1100 International Plz ~ BLDG 305, United States of America · Onsite

2 months ago

Principal Industrial Security Analyst/Sr Princ Industrial Security Analyst

Northrop Grumman · CASU21, United States of America

2 months ago

Principal Industrial Security Analyst/Sr Princ Industrial Security Analyst

Northrop Grumman · Sunnyvale, CA,US, US

2 months ago

Principal Industrial Security Analyst/Sr Princ Industrial Security Analyst

Northrop Grumman · UTSL01, United States of America · Onsite

2 months ago

Principal Industrial Security Analyst/Sr Princ Industrial Security Analyst

Northrop Grumman · Salt Lake City, UT,US, US · Onsite

2 months ago

Sr Security Analyst

Meijer · 705 - Corporate Campus/Virtual MI, United States of America

2 months ago

Sr Security Analyst - Cloud Security

Lennox · Chennai, IN · Hybrid

3 months ago

Sr. Analyst, Security (Onsite)

RTX · US-CA-SAN JOSE-826 ~ 200 Holger Way ~ BLDG 826, Ast, United States of America · Onsite

3 months ago

Information Security Analyst Sr Adv/Information Systems Security Officer (TS/SCI with Poly Required)

GCI

4 months ago

Sr. Security Analyst, EMEA

Lucidsoftware · Amsterdam, NL +1 · Remote, Hybrid

4 months ago