1

Test Security Analyst Jobs in Vermont (NOW HIRING)

Senior Security Engineer

Burlington, VT · Remote

$114K - $157K/yr

... pen tests * Develop and maintain a library of security standards, patterns, and guardrails ... Drive root cause analysis and communicate findings clearly to engineering leadership * Build and ...

Senior Security Engineer

Burlington, VT · On-site

$112K - $154K/yr

Triageand drive remediation of vulnerabilities surfaced through scanning, bugbounty, and pen tests ... Driveroot cause analysis and communicate findings clearly to engineeringleadership * Buildand ...

... build, test and ship our products, our IT team keeps our business running smoothly. Learn more ... logic analyzers. * Deep understanding of the vulnerability lifecycle, including scanning, CVE ...

... build, test and ship our products, our IT team keeps our business running smoothly. Learn more ... Hands-on experience in embedded firmware debugging using JTAG-based debuggers and logic analyzers.

... build, test and ship our products, our IT team keeps our business running smoothly. Learn more ... logic analyzers. * Deep understanding of the vulnerability lifecycle, including scanning, CVE ...

New

Workday Absence & HCM Senior Analyst

Burlington, VT · Remote

$90K - $115K/yr

Build, revise and test reports, including creating calculated fields, and ensuring data integrity ... Maintain security groups in support areas, and create new security groups as needed * Configure ...

Showing results 21-40

Test Security Analyst information

What are some common challenges faced by test security analysts when investigating potential exam breaches?

Test Security Analysts often face challenges such as detecting sophisticated cheating methods, distinguishing between honest mistakes and intentional misconduct, and keeping up with evolving technology used to compromise test integrity. They must analyze large amounts of data, coordinate with multiple teams—including IT, legal, and test administration—and ensure that investigations are thorough while maintaining confidentiality. Staying current with new security threats and industry best practices is essential for success in this role.

What is the difference between Test Security Analyst vs Quality Assurance Tester?

AspectTest Security AnalystQuality Assurance Tester
CertificationsSecurity+; ISTQB Security TestingISTQB Foundation; ISTQB Agile Tester
Work EnvironmentSecurity-focused testing in software developmentGeneral software testing across projects
Industry UsageIT security, software development, testing teamsSoftware development, product teams, QA departments

The Test Security Analyst primarily focuses on identifying security vulnerabilities and ensuring software security compliance, while the Quality Assurance Tester concentrates on verifying overall software quality and functionality. Both roles require similar certifications and often work within the same industry environments, but their core responsibilities differ in scope and focus.

What are the key skills and qualifications needed to thrive as a test security analyst, and why are they important?

To thrive as a Test Security Analyst, you need a solid understanding of test administration protocols, data analysis, and investigative techniques, often supported by a degree in information security, education, or a related field. Experience with test delivery platforms, monitoring software, and familiarity with incident management systems are typically required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for detecting and addressing security breaches. These skills and qualities are crucial to ensure the integrity of testing processes, prevent cheating, and uphold the credibility of assessment programs.

What does a test security analyst do?

A Test Security Analyst is responsible for protecting the integrity and confidentiality of exams and assessment processes. They monitor for cheating, investigate security breaches, and develop policies and procedures to prevent misconduct. Their work often includes analyzing testing data for irregularities, coordinating with test centers, and implementing security technologies. The goal is to ensure that assessment results are fair, valid, and trustworthy for all candidates.
What are popular job titles related to Test Security Analyst jobs in Vermont? For Test Security Analyst jobs in Vermont, the most frequently searched job titles are:
What job categories do people searching Test Security Analyst jobs in Vermont look for? The top searched job categories for Test Security Analyst jobs in Vermont are:
What cities in Vermont are hiring for Test Security Analyst jobs? Cities in Vermont with the most Test Security Analyst job openings:

Senior Security Engineer

Mach7 Technologies

Burlington, VT • Remote

$114K - $157K/yr

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Title: Senior Security Engineer

Team: Engineering

Location: Remote-Friendly

About the Role:

We\'re looking for a Senior Security Engineer to lead application security efforts across our product portfolio, spanning web applications, APIs, mobile, embedded software, and shipped product deliverables. You\'ll be embedded in the engineering organization, partnering with product and platform teams to bake security into every phase of the software development lifecycle, not bolt it on at the end.

 

A critical part of this role is developing and maintaining a deep understanding of our product attack surface, how components interact, what\'s exposed, and where real risk lives. That understanding is what transforms security tooling output into prioritized, meaningful action across threat modeling, vulnerability management, and supply chain risk.

 

This is a high-impact role for someone who is equally comfortable reading source code, threat modeling a new microservice, and coaching a developer through a secure code review.

 


What You\'ll Do

Application Security & Secure SDLC 

  • Own and evolve the AppSec program across the entire SDLC — from design reviews to post-deployment monitoring — for web, API, mobile, and shipped product deliverables 
  • Build and maintain a living model of the product attack surface — mapping trust boundaries, data flows, exposed interfaces, and high-value targets — and use it to drive prioritization across all security workstreams 
  • Conduct threat modeling and architecture security reviews for new features, services, and product releases across all delivery channels 
  • Perform manual and automated secure code reviews across multiple languages (e.g. Python, Go, TypeScript, C/C++) 
  • Integrate and tune SAST, DAST, and SCA tooling within CI/CD pipelines (GitHub Actions, Jenkins, or equivalent) 
  • Triage and drive remediation of vulnerabilities surfaced through scanning, bug bounty, and pen tests 
  • Develop and maintain a library of security standards, patterns, and guardrails applicable across product types 

Third-Party & Supply Chain Security 

  • Own the Software Bill of Materials (SBOM) program — define generation, storage, and consumption processes across all product lines 
  • Establish and maintain policies for evaluating, onboarding, and continuously monitoring third-party dependencies and open-source components 
  • Triage and prioritize CVEs and license risks surfaced through SCA tooling, driving timely remediation with engineering teams 
  • Define processes for responding to upstream supply chain incidents (e.g. compromised packages, malicious dependencies) 
  • Collaborate with procurement and legal to assess security risk of third-party vendors and integrations 
  • Contribute to industry frameworks and internal standards around software supply chain security (SLSA, NIST SSDF, or equivalent) 
  • Act as a trusted security advisor embedded within product engineering squads 
  • Lead security training, lunch-and-learns, and developer education initiatives 
  • Collaborate with the Platform team on secrets management, identity, and access controls 
  • Work with the GRC function to translate compliance requirements (SOC 2, ISO 27001) into engineering controls 

Incident & Vulnerability Management 

  • Participate in the security on-call rotation and lead security incident response investigations 
  • Drive root cause analysis and communicate findings clearly to engineering leadership 
  • Build and maintain metrics and dashboards to track the health of the AppSec program 
  • Participate as a member of the Cybersecurity council, representing development in the organization. Report weekly on new threat intelligence as it relates to product security, and any actions that are being taken to remediate new findings.  
What We\'re Looking For
Required

·         5+ years of experience in security engineering, with a strong AppSec focus 

·         Hands-on experience with threat modeling frameworks (STRIDE, PASTA, or similar) 

·         Proficiency with common AppSec tooling: Semgrep, Snyk, Burp Suite, OWASP ZAP, or equivalents 

·         Deep understanding of web application vulnerabilities (OWASP Top 10, API security, auth/authz flaws) 

·         Ability to read and reason about code in at least two languages; prior development experience a plus 

·         Experience with software supply chain security — SBOM generation and analysis (CycloneDX, SPDX), SCA tooling, and dependency risk management 

·         Strong written and verbal communication skills — you can explain risk to both engineers and executives 

      Preferred 

·         Experience with cloud-native environments (AWS, GCP, or Azure) and container/Kubernetes security 

·         Familiarity with software supply chain frameworks such as SLSA, NIST SSDF, or OpenSSF Scorecards 

·         Contributions to open-source security tooling or security research 

·         Relevant certifications: OSCP, CSSLP, GWEB, or similar 

 

We recognize that candidates bring diverse experiences and backgrounds. If you don’t meet every requirement, we still encourage you to apply! Many strong candidates don’t check every box. We value potential, growth, and impact as much as experience.

 

Who You Are

·         Experienced security professional with a strong background in application security and secure software development.

·         Skilled at threat modeling, secure code reviews, and identifying real-world risks across complex systems.

·         Knowledgeable in web, API, mobile, and software supply chain security best practices.

·         Comfortable working with developers to embed security throughout the SDLC.

·         Proficient with security testing and vulnerability management tools, including SAST, DAST, and SCA solutions.

·         Strong communicator who can translate technical risks into actionable recommendations.

·         Collaborative, proactive, and driven to improve both product security and engineering security culture.

·         Passionate about continuous learning, emerging threats, and helping teams build secure products at scale.


About Mach7:

Mach7 Technologies helps healthcare organizations bring all their medical images together in one place so they can be easily accessed, shared, and used to support patient care. Our enterprise imaging solutions, including a vendor-neutral archive (VNA), enterprise PACS, the eUnity enterprise diagnostic viewer, and teleradiology workflows, consolidate imaging from across the enterprise into a single, accessible source of truth. Built on open standards, including DICOM and a configurable HL7 engine, and free from proprietary data lock-in, our technology lets providers store, view, and share images on their own terms. The result is a simpler, more connected imaging environment that puts data ownership back where it belongs: with the people delivering care. Your data, your infrastructure, your choice.

 


AI Expectations

·         Integrate AI into daily work — leverage AI tools to enhance efficiency, elevate quality, and support smarter, faster decision-making.

·         Apply critical human judgment to AI output — review, validate, and take full accountability for AI-assisted work, ensuring accuracy and reliability.

·         Continuously improve through AI — proactively identify opportunities to optimize processes, rethink workflows, and challenge existing approaches rather than maintaining the status quo.

·         Use AI responsibly and ethically — safeguard sensitive information, adhere to company guidelines, and actively identify risks such as bias, inaccuracies, or misuse.

CLIMBS Culture Code

At Mach7, our culture is rooted in CLIMBS, a mindset that guides how we show up, collaborate, and grow each day. More than just a set of values, CLIMBS represents the standard we hold ourselves to and the way we approach our work, our teams, and our impact.

C — Customer First
Every decision starts with the customer’s perspective. Success = customer outcomes and satisfaction.

L — Learn & Grow
Curiosity keeps us climbing. We embrace continuous learning, share knowledge freely, and invest in each other’s development.

I — Innovate for Impact
We value meaningful, outcome-driven innovation over activity. We challenge the status quo and align behind real customer benefit.

M — Minimize Complexity & Move
As complex as needed but no more. Agility beats bureaucracy. We move fast and stay focused on what matters.

B — Build Good Sh*t
(Yes, intentionally memorable.) Extreme ownership, craftsmanship, and pride in high-quality work.

S — Everyone Sells
Not just Sales—Engineering, Product, Support, Finance, IT. We align behind commercial success to enable company success