Senior Application Security Analyst

State of Washington$113K — $148K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of information security experience, emphasizing application security and vulnerability management
  • In-depth knowledge of secure SDLC and cloud architecture, particularly with DevSecOps practices
  • Experience with application security assessments, code reviews, and risk assessments
  • Familiarity with vulnerability assessment tools (Nessus, Rapid7, Nmap, Burp Suite)
  • Strong analytical skills to tackle emerging cybersecurity threats and develop defenses

Responsibilities

  • Lead application security assessments and coordinate code reviews for compliance with industry standards
  • Support and enhance the Secure Software Development Lifecycle by integrating security controls into processes
  • Collaborate with DevOps and delivery teams to embed security throughout the software development lifecycle
  • Provide detailed remediation recommendations after identifying security weaknesses in applications
  • Conduct vulnerability validation and risk analysis to prioritize remediation efforts

Benefits

  • Flexible hybrid remote work arrangement
  • Opportunity for professional development and continuous improvement initiatives
  • Collaboration with cross-functional teams and external partners
  • Involvement in cutting-edge security practices and emerging technologies
  • Strong emphasis on employee wellness and work-life balance
Full Job Description
Salary : $113,668.00 - $148,263.00 Annually
Location : Thurston County - Olympia, WA
Job Type: Full Time - Permanent
Job Number: 1470
Department: Health Benefits Exchange
Opening Date: 06/10/2026

SUMMARY
The Senior Application Security Analyst plays a key role in protecting WAHBE's data and applications by ensuring security controls are effectively integrated throughout the Software Development Lifecycle (SDLC) across both cloud and on-premises environments. Operating under the guidance of the Application Security Lead, this role serves as a senior technical contributor and collaborates closely with delivery teams, DevOps, architects, IT, and external partners to implement and sustain secure software development practices.

This position is responsible for executing application security assessments, threat modeling, and vulnerability management, while supporting risk assessments and ensuring alignment with WAHBE's security policies and regulatory requirements. The Senior Application Security Analyst helps drive the adoption and continuous improvement of the Secure Software Development Lifecycle (SSDLC) by integrating automated security controls, conducting code reviews, and promoting secure coding standards.

Key responsibilities include identifying and mitigating application security risks, supporting incident response activities, and providing actionable guidance to delivery teams for remediation. The role also contributes to strengthening overall application security posture by addressing emerging threats, supporting compliance efforts, and ensuring security best practices are consistently applied across the organization.
Duties
• Serve as a senior subject matter expert for application security across Microsoft Azure and cloud-native architectures including hybrid and multi-cloud environments
• Perform and coordinate application security assessments, code reviews to align with WAHBE security policies, industry standards (NIST, OWASP), and regulatory compliance (e.g., Centers for Medicare & Medicaid Services (CMS), Internal Revenue Service (IRS)), including API and microservices security assessments
• Support the implementation and continuous improvement of the Secure Software Development Lifecycle by integrating security controls and best practices into development and deployment processes
• Collaborate with the Delivery team, architects, DevOps engineers to embed security into all phases of the SDLC, including participation in threat modeling, security requirement reviews, and architecture discussions
• Review application and solution architectures to identify security weaknesses, attack surfaces, and insecure design patterns, and provide remediation recommendations
• Perform security design reviews for web applications, APIs, microservices, containers, and serverless technologies to ensure secure implementation practices are followed
• Develop, document, and enforce secure coding standards, secure design guidelines, and application security procedures to ensure consistent and secure development practices
• Enhance and lead the Application Security and Penetration Testing program, including performing security and penetration testing and integrating automated security testing into CI/CD pipelines to ensure continuous and effective validation of application security
• Conduct vulnerability triage, validation, and risk analysis using security tools, threat intelligence, and manual analysis, including false-positive review and remediation prioritization
• Track remediation activities for identified application vulnerabilities and work with development teams to ensure timely resolution or appropriate risk acceptance documentation
• Provide technical guidance for remediation planning and recommend compensating controls when immediate remediation is not feasible
• Support monitoring and reporting activities by preparing vulnerability metrics, remediation status updates, trend analysis, and risk reports for leadership and stakeholders
• Develop and deliver secure coding awareness sessions, technical guidance, and application security training materials for development and engineering teams
• Review Requests for Change (RFCs), product enhancements, and system modifications from a security perspective to ensure security impacts and requirements are addressed
• Continuously monitor the cloud and on-premise environment for security events, anomalies, and potential threats, and conduct thorough investigations to identify root causes and impacts, containment and recovery from security breaches, and preparation of incident reports, including post-incident analysis and lessons-learned
• Partner with Compliance, Risk Management, Audit, Infrastructure Security, and DevOps teams to support audits, regulatory compliance efforts, and secure cloud adoption initiatives
• Ensure procedures, processes and technologies align with WAHBE security policies and regulatory compliance (e.g., CMS, IRS)
• Work closely with delivery teams to ensure security requirements are factored into user stories and case development (including misuse, abuse, and confuse cases within Agile methodology)
• Assess the security posture of new enterprise solutions to be procured by identifying security risk and providing secure cloud adoption guidance
• Provide technical security consultation and assessments for cloud environments and containers, with an emphasis on following best practices and conducting comprehensive technical analysis
• Collaborate with WAHBE DevOps Team to integrate application security into CI/CD pipeline as part of SSDLC and enforce security in deployment workflows
• Assist in maintaining and updating WAHBE Security policies, procedures, and standards ensuring ongoing SSDLC adoption
• Collaborate with internal stakeholders, vendors, and external partners to ensure security integration and ongoing compliance, maintaining synchronization with the Security objectives
• Assist Application Security Lead in reviewing existing security capabilities and assist in defining roadmap and strategy for security enhancements
• Provide regular briefings to Application Security Lead and Information Security Manager (ISM), escalating issues and blockers as necessary
• Provide technical guidance on secure development and vulnerability management activities
• Stay current on industry trends, emerging threats, and relevant technologies, and communicate key insights to the Application Security Lead
• Perform other duties as assigned within the scope of application security

Qualifications

Required:
• Seven (7) years of information security experience in specialized roles such as, but not limited to security architecture and design, security control implementation penetration testing, application security, vulnerability management, incident response
• Demonstrated knowledge of secure SDLC, secure architecture design, application security concepts, and cloud- architecture including DevSecOps practices and shift-left security integration
• Experience performing application security code reviews, roles and permissions matrix reviews, and practical application risk assessments, including manual and automated secure code reviews
• Experience working with common vulnerability assessment tools such as Nessus, Rapid7, Nmap, and Burp Suite, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools
• Advanced understanding of emerging cybersecurity threats, including application-layer attacks, API abuse, and software supply chain vulnerabilities
• Strong analytical and problem-solving skills with the ability to "think outside the box"
• Experience integrating security in infrastructure-as-code, CI/CD pipelines, and the software development lifecycle, including implementation of automated controls and continuous monitoring and security gates and pipeline enforcement policies
• Demonstrates strong interpersonal and collaboration skills, effectively partnering with internal management, staff, and cross-functional teams as well as external partners and vendors
Desired:
• Bachelor's degree in engineering, security or a technology related or closely allied field
• Experience working with application security methodologies such as OWASP
• Demonstrated experience in information security, data security, privacy, and data management, including secure handling of Personally Identifiable Information (PII), application-level encryption, and key management
• Experience defining secure architectural requirements, security controls, and configuration standards in compliance with regulatory requirements
• Experience working with threat modeling frameworks such as STRIDE and MITRE ATT&CK, including application-specific threat modeling, attack path analysis, and abuse case analysis
• Experience developing, reviewing, and updating security standards, procedures, awareness and training, including secure coding standards and developer training programs
• Demonstrates a solid understanding of the functions and operations of Security Information and Event Management (SIEM) systems, Endpoint Detection & Response
• Demonstrated experience in managing cyber incident response, including coordination with development teams for rapid patching and hotfix deployment
• Advanced understanding of emerging cybersecurity threats, including application-layer attacks, API abuse, and software supply chain vulnerabilities

Supplemental Information

APPLICATION INSTRUCTIONS
This position will be open until we find a suitable number of candidates to review. If interested, please submit an application (CLICK HERE) as soon as possible. The Exchange reserves the right to close the recruitment at any time.

SALARY INFORMATION
Full Salary Range: $98,842.00 to $148,263.00 annually, with midpoint at $123,552.00.

Hiring Range: $113,668.00 and $123,552.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer.

The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum.

BENEFITS
Take a peek at our

WORKING CONDITIONS
Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in-person collaboration. While a hybrid remote and on-site schedule may be considered, the position will require flexibility to allow for in-office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location.

The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

SPECIAL REQUIREMENTS
A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The result of this background screen must meet the Exchanges eligibility standards.

OTHER INFORMATION
The above statements are intended to describe the general nature and levels of work being performed. They are not intended to be construed as an exhaustive list of responsibilities, duties and skills of personnel so classified.

This is not an employment agreement or contract. Management has the exclusive right to alter this job description at any time without notice.

About State of Washington

State of Washington Careers

Joining the State of Washington's diverse team offers more than just a job; it opens opportunities to build and grow a career in an array of fields. State of Washington is renowned for its commitment to excellence and innovation in public service.

Explore Job Opportunities

State of Washington offers a variety of job opportunities that cater to a range of skills and interests. From environmental science to public health, the state provides roles that contribute significantly to the community and the environment. Each position at the State of Washington supports a culture of leadership and professional growth.

Experience Professional Growth

Career advancement is a cornerstone of employment with the State of Washington. With programs designed to foster leadership skills and professional development, employees are encouraged to ascend through the ranks. The State of Washington is committed to providing career pathways that help individuals achieve their professional goals.

Engage in Diversity Training and Innovation

The State of Washington places a high priority on creating an inclusive work environment. Diversity training is integral, ensuring all team members understand and appreciate the value of differences. Innovation is at the heart of the State of Washington, where new ideas and perspectives lead to effective solutions and services.

Benefits and Culture

Employees at the State of Washington enjoy a comprehensive benefits package that supports both their professional and personal lives. Health benefits, retirement plans, and wellness programs are just the beginning. The culture here is built on mutual respect, collaboration, and a commitment to excellence.

Internship Programs

For those starting their career journey, internship opportunities provide a gateway to full-time employment and a chance to develop valuable industry skills. Internships at the State of Washington are designed to give hands-on experience and insights into the workings of state government.

Join the Team

State of Washington is continuously hiring new talent. Interested candidates are encouraged to review open positions that match their skills and career interests. The hiring process is thorough, ensuring that both the candidate and the position are a perfect match.

Prepare for Your Interview

To help candidates succeed, State of Washington offers resources on how to effectively prepare for interviews. Tips on crafting a compelling resume and mastering interview techniques are available to ensure applicants present their best selves.

Networking and Career Events

Regular networking events and career fairs provide opportunities to connect with leaders in various fields and explore potential job openings. These events are ideal for sharing professional experiences, meeting potential mentors, and learning more about the State of Washington's mission and values.

Stay Connected

Keep up to date with the latest news, job alerts, and career tips from the State of Washington by subscribing to the careers newsletter. Discover the exciting and rewarding opportunities that await at the State of Washington.

SEARCH STATE OF WASHINGTON JOBS

READ CAREERS BLOG

JOB ALERT EMAILS

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the rewarding career opportunities at the State of Washington today.
Learn more about State of Washington

Similar Jobs

More Jobs at State of Washington

More Information Technology Jobs

Find similar Senior Application Security Analyst jobs: