IT Security Analyst II (AppSec)
Core
Application Security Engineer strengthening WGU's security posture by reviewing access requests, guiding vulnerability remediation, and contributing to security policies and standards.
Role type
Application Security Engineer (AppSec)
Builds
Security-focused tools, services, documentation, and standards for WGU's applications and systems
Domain
Higher Education / Application Security
Required skills
Source code analysis, vulnerability scanning, threat modeling, architecture reviews, SAST/DAST/IAST/SCA tool configuration, CI/CD pipeline integration, secure coding practices, access control assessment, security policy development
Preferred skills
Cloud infrastructure security, Burp Suite/Snyk/Checkmarx familiarity
Technologies
Python, Java, JavaScript, Go, C/C++, Kali, Nessus, Burp, NMap, Metasploit, Wireshark, SAST, DAST, IAST, SCA, CI/CD
Responsibilities
Analyze source code to identify security flaws; oversee vulnerability scanning of applications and APIs; perform threat modeling; conduct architecture reviews and create security documentation; build and maintain application security tools; collaborate with engineering teams to fix vulnerabilities; educate developers on secure coding; assess user access for least-privilege; contribute to security policies and standards
Seniority
Mid-level, hands-on IC