1

Web Application Security Analyst Jobs (NOW HIRING)

Web Application Security

Chicago, IL · On-site

$60.50 - $81/hr

... analysis of security vulnerabilities and apply lessons learnt. • Review application design and ... web application firewall rules. • Threat modelling (STRIDE or equivalent methodology)

We are seeking a detail-oriented, curious, and collaborative Application Security Analyst to play a ... Configure and optimize Web Application Firewall (WAF) rules; monitor logs to detect and mitigate ...

Application Security Analyst

Auburn Hills, MI · On-site

$55.50 - $74.25/hr

This role focuses on identifying, analyzing, and mitigating application security vulnerabilities ... Lead Web Application Firewall (WAF) deployment for new and existing apps * Implement application ...

Application Security Analyst

Auburn Hills, MI

$55.50 - $74.25/hr

Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing * Analyze ... Lead Web Application Firewall (WAF) deployment for new and existing apps * Implement application ...

This position is within the Inbound Web Application Security Engineering Team. Responsibilities ... Strong analytical and troubleshooting skills with the ability to identify root causes and resolve ...

This position is within the Inbound Web Application Security Engineering Team. Responsibilities ... Strong analytical and troubleshooting skills with the ability to identify root causes and resolve ...

This position is within the Inbound Web Application Security Engineering Team. Responsibilities ... Strong analytical and troubleshooting skills with the ability to identify root causes and resolve ...

next page

Showing results 1-20

Web Application Security Analyst information

See salary details

$64K

$84.3K

$94K

How much do web application security analyst jobs pay per year?

As of Sep 8, 2026, the average yearly pay for web application security analyst in the United States is $84,342.00, according to ZipRecruiter salary data. Most workers in this role earn between $82,500.00 and $83,000.00 per year, depending on experience, location, and employer.

What does a web application security analyst do?

A Web Application Security Analyst is responsible for identifying, analyzing, and mitigating security risks in web applications. Their main duties include performing security assessments, penetration testing, code reviews, and monitoring for vulnerabilities. They work closely with development teams to ensure applications are built securely from the ground up and stay compliant with security standards. Additionally, they keep up to date with the latest security threats and recommend best practices for safeguarding sensitive data.

What are the key skills and qualifications needed to thrive as a web application security analyst?

To thrive as a Web Application Security Analyst, you need expertise in web security concepts, vulnerability assessment, and secure coding practices, often backed by a degree in computer science or cybersecurity and relevant certifications like CEH or OSCP. Familiarity with tools such as Burp Suite, OWASP ZAP, and security information and event management (SIEM) systems is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts identify threats and convey risks to technical and non-technical stakeholders. These skills ensure robust protection of web applications, reducing the risk of breaches and safeguarding sensitive data.

What are some common challenges faced by web application security analysts when working with development teams?

Web Application Security Analysts often face challenges in balancing security requirements with development speed and business goals. They must effectively communicate security risks and recommendations to developers who may not have a security background, which requires strong interpersonal skills and the ability to translate technical findings into actionable steps. Additionally, analysts may need to prioritize vulnerabilities based on risk and resource constraints, ensuring critical issues are addressed without hindering project timelines. Building strong, collaborative relationships with development teams is crucial to successfully integrating security into the software development lifecycle.

What is the difference between Web Application Security Analyst vs Penetration Tester?

AspectWeb Application Security AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, OSCP (preferred)CEH, OSCP, GPEN
Work EnvironmentSecurity teams within organizations, focusing on ongoing security assessmentsConsulting firms or internal teams conducting simulated attacks
Industry UsageCommon in tech, finance, healthcare sectorsUsed across various industries for security testing
Primary FocusMonitoring, analyzing, and improving web application securityIdentifying vulnerabilities through simulated attacks

Both roles involve cybersecurity skills and certifications like CEH or OSCP. However, Web Application Security Analysts focus on maintaining and improving security within organizations, while Penetration Testers simulate attacks to identify vulnerabilities. The roles often overlap but differ in scope and approach.

What cities are hiring for Web Application Security Analyst jobs?

Cities with the most Web Application Security Analyst job openings:

What states have the most Web Application Security Analyst jobs?

States with the most job openings for Web Application Security Analyst jobs include:

What are popular job titles related to Web Application Security Analyst jobs?

For Web Application Security Analyst jobs, the most frequently searched job titles are:

Infographic showing various Web Application Security Analyst job openings in the United States as of September 2026, with employment types broken down into 77% Full Time, 19% Part Time, and 4% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $84,342 per year, or $40.5 per hour.

Web Application Security

InterSources Inc

Chicago, IL • On-site

$60.50 - $81/hr

Full-time

Re-posted 29 days ago


Job description

Job Summary:
InterSources Inc is a Certified Diverse Supplier and an Award-Winning Global Software Consultancy founded in 2007. They are seeking a Web Application Security professional to conduct security testing, provide documentation on security policies, and assist developers with best practices.
Responsibilities:
• Perform static application security testing (SAST)/code audits - automated and manual.
• Perform dynamic application security testing (DAST) - automated and manual.
• Perform root cause analysis of security vulnerabilities and apply lessons learnt.
• Review application design and architecture from a security standpoint and provide recommendations.
• Provide detailed documentation on security policies and remediation assistance.
• Assist developers in remediation by sharing security concepts and security best practices.
• Review and harden web application firewall rules.
• Threat modelling (STRIDE or equivalent methodology).
Qualifications:
Required:
• Perform static application security testing (SAST)/code audits - automated and manual.
• Perform dynamic application security testing (DAST) - automated and manual.
• Perform root cause analysis of security vulnerabilities and apply lessons learnt.
• Review application design and architecture from a security standpoint and provide recommendations.
• Provide detailed documentation on security policies and remediation assistance.
• Assist developers in remediation by sharing security concepts and security best practices.
• Review and harden web application firewall rules.
• Threat modelling (STRIDE or equivalent methodology).
• Deep understanding of HTTP protocol spec.
• Deep understanding of security principles and security best practices.
• Basic understanding of cryptography.
• Basic understanding of TLS protocol spec.
• Basic understanding of industry best practices - PCI, OWASP, WASC, STRIDE.
• Education: Bachelors/Master's degree in the field of Computers, Engineering, or Mathematics a plus.
• Certification in OSCP/OSWE a plus.
• Contribution to open-source projects a plus.
• At least 2-3 years experience in information security preferred.
• Web application development background with a strong interest in information security and relevant certification (OSCP/OSWE) acceptable.
Company:
InterSources Inc. solves operational problems where protection, performance, compliance, AI, and workforce capability must work together. Founded in 2007, the company is headquartered in Fremont, USA, with a team of 501-1000 employees. The company is currently Late Stage.

InterSources logo

About InterSources

Sourced by ZipRecruiter

In 2007, Our journey began as pioneers in the realm of technology and security. Since then, InterSources Inc. has evolved into a trusted partner, leading the way in Cloud Security, Cybersecurity, PLG Consulting, Digital Transformation, and Professional Services. With a rich history of excellence and a forward-thinking approach, we continue to secure your digital future and drive innovation. Explore our legacy of success and discover the possibilities that lie ahead.

Industry

Recruiting and staffing services

Company size

51 - 200 Employees

Headquarters location

Fremont, CA, US

Social media