← all jobs

NIH - Application Scanning Analyst

Work from home Full-time role Hiring

cFocus Software seeks a Application Scanning Analyst to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance. Qualifications:Public Trust Clearance B.S. Computer Science, Information Technology, or a related field 5+ years of experience performing application security assessments or web application vulnerability scanning. Experience conducting authenticated and unauthenticated web application security testing. Experience supporting enterprise vulnerability management programs. Experience interpreting application security findings and developing remediation guidance. Experience supporting Federal cybersecurity or large enterprise environments. Preferred certifications include: GWAPT, GWEB, CSSLP, OSWA, or CEH Duties:Perform authenticated and unauthenticated web application vulnerability scans. Conduct application security assessments against internally developed and commercial applications. Perform Dynamic Application Security Testing (DAST) and support Static Application Security Testing (SAST) activities. Assess APIs, web services, and middleware for security vulnerabilities. Conduct application configuration reviews and identify security weaknesses. Perform recurring vulnerability scans in accordance with Government-defined schedules. Analyze application scan results to identify security vulnerabilities and misconfigurations. Validate scan findings to eliminate false positives. Prioritize vulnerabilities using risk-based methodologies, including CVSS scoring and exploitability. Correlate application vulnerabilities with infrastructure and network risks. Identify critical vulnerabilities requiring immediate remediation. Perform root cause analysis for recurring application security issues. Collaborate with software development teams to improve application security. Provide remediation recommendations aligned with secure coding practices. Assist developers with vulnerability mitigation strategies. Support integration of security scanning into DevSecOps and CI/CD pipelines. Recommend application security improvements throughout the software development lifecycle (SDLC). Promote secure-by-design principles across NIH application environments.

More open positions

NIH - Network Engineer

Work from home Full-time role

Customer Service Representative, Series 7 Registered

Work from home Full-time role

Senior Python Backend Engineer

Work from home Full-time role

Newsletters Director

Work from home Full-time role

Junior Microsoft 365 Developer (Power Platform / SharePoint)

Work from home Full-time role

Strong Communicators Needed for An Airbnb Luxe Home Consultant Project - Jackson Hole, US

Work from home Full-time role

Customer Support Specialist – Technical & Clinical SaaS Solutions at careerzynith

Work from home Full-time role

Sales Consultant

Work from home Full-time role

[Remote] Sales / Pre-Sales Engineer - Data Platform

Work from home Full-time role

Voice Recording Project

Work from home Full-time role

Epic OpTime Analyst (OR, Anesthesia, Sedation & Perfusion)

Work from home Full-time role

MuleSoft Integration Engineer

Work from home Full-time role

[Remote] Senior Account Director

Work from home Full-time role

Senior Full-Stack Engineer, AI Editing

Work from home Full-time role

Virtual Training; Remote Personal Trainer

Work from home Full-time role

Project Coordinator, Supply Chain Solutions

Work from home Full-time role

[Remote] Medicare Sales Field Agent - Allegheny County, PA

Work from home Full-time role

Pessoa Desenvolvedora Angular - Sênior

Work from home Full-time role

Remote Data Entry & Office Support Specialist – Customer Service, Scheduling, and Administrative Coordination

Work from home Full-time role

Senior Linux SRE - Remote

Work from home Full-time role

Airline Sourcing Specialist

Work from home Full-time role