Imf
Security Analyst/Sr. Security Analyst (Application Security)-ITDSGGR (Contractual)
USA, Washington DC · Senior
Sponsorship not specifiedDetected 13 hours ago
PythonJavaPowerShell.NETAzureCI/CDDevOpsData VisualizationCybersecurityStakeholder ManagementVendor ManagementCommunicationCollaborationBurp SuiteCISSP
About the role
- The Security Analyst (Application Security) supports the integration of security throughout the Software Development Lifecycle (SDLC) by partnering with development, infrastructure, and application teams to embed secure development practices, implement security requirements, and strengthen the overall security posture of enterprise applications. The role is
- responsible for identifying, validating, prioritizing, tracking, and supporting the remediation of application security vulnerabilities, while driving risk-based vulnerability management activities and application security initiatives across on-premises and cloud environments. The successful candidate combines hands-on expertise in application security and
Requirements
- Alternatively, a university degree, or equivalent, and ten (10) years of relevant professional experience, is required.
- Experience in Vulnerability Management, Application Security, Secure Development or related cybersecurity disciplines.
- Strong knowledge of application security principles, secure software development practices, and industry frameworks such as OWASP Top 10, NIST SSDF, NIST CSF, and ISO 27001.
- Experience with one or more programming or scripting languages (e.g., Java, Python,.NET, PowerShell) and the ability to analyze application security findings and support remediation efforts.
- Hands-on experience with application security testing methodologies and tools, including SAST, DAST, SCA, vulnerability assessments, and penetration testing.
- Experience collaborating with development and engineering teams to integrate security requirements and controls throughout the Software Development Lifecycle (SDLC).
- Ability to analyze security risks, communicate technical findings to diverse audiences, and provide actionable remediation guidance.
- Strong communication, analytical, stakeholder management, and collaboration skills, with the ability to influence security outcomes across cross-functional teams.
Nice to have
- Security certifications, such as OSCP, SSCP, CEH, Security+, GIAC, CISSP, or equivalent.
- Knowledge, certifications, and experience in Microsoft Azure, Azure DevOps, and Power BI for cloud operations, reporting, and data visualization.
- Experience with enterprise application security tools, such as Burp Suite, Sonatype Nexus Lifecycle, Checkmarx, Fortify, HCL AppScan, Veracode, or similar solutions.
- This is a one-year contractual appointment.
- Contractual appointments at the IMF are renewable for up to four years of cumulative contractual service, pending incumbent's performance, budget availability, and continuous business need.
- ITDPVPM Information Technology Department Project and Vendor Management Project Portfolio Management Section
- The IMF is guided by the principle that the employment, classification, promotion, and assignment of staff shall be made without discrimination against any person.
- We welcome requests for reasonable accommodations for disabilities during the selection process.
This listing is sourced directly from Imf's careers page and normalized into a canonical job model.