1

Web Application Security Analyst Jobs in Colorado

Manual Ethical Hacking is part of the Application Development Security Framework Program within ... Perform assigned analysis of internal and external threats on information systems and predict ...

Senior Manual Ethical Hacker

Denver, CO

$102K - $132K/yr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use ...

Senior Manual Ethical Hacker

Denver, CO ยท On-site

$102K - $132K/yr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use ...

Senior Manual Ethical Hacker

Denver, CO ยท On-site

$150 - $200/hr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use ...

Compliance Lead

Denver, CO

$161K/yr

... guidance to security analysts, testers, and development teams during application security ... In-depth knowledge on common web application security flaws and secure coding practices and the ...

Senior Security Analyst

Denver, CO ยท On-site

$100K - $130K/yr

Mobile Device Management (MDM) & Mobile Application Management (MAM) * Security Incident & Event Management (SIEM) * Traditional and sophisticated Malware Protection technologies * Secure web gateway ...

Senior Security Analyst

Denver, CO ยท Hybrid

$100K - $130K/yr

Mobile Device Management (MDM) & Mobile Application Management (MAM) * Security Incident & Event Management (SIEM) * Traditional and sophisticated Malware Protection technologies * Secure web gateway ...

Penetration Tester

Colorado Springs, CO ยท On-site

$130K - $145K/yr

Analyzing software, firmware, hardware, and/or RF components within the system. * Opining on the ... Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ...

Penetration Tester

Colorado Springs, CO ยท Hybrid

$130K - $145K/yr

Analyzing software, firmware, hardware, and/or RF components within the system. * Opining on the ... Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ...

Penetration Tester

Colorado Springs, CO ยท Hybrid

$130K - $145K/yr

Analyzing software, firmware, hardware, and/or RF components within the system. * Opining on the ... Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ...

... analysis, API security, web application firewalls (WAF), container security, vulnerability validation and remediation, application data protection, and alignment with applicable security standards ...

Showing results 41-60

Web Application Security Analyst information

See Colorado salary details

$67.3K

$88.7K

$98.8K

How much do web application security analyst jobs pay per year?

As of Sep 9, 2026, the average yearly pay for web application security analyst in Colorado is $88,687.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,800.00 and $87,300.00 per year, depending on experience, location, and employer.

What does a web application security analyst do?

A Web Application Security Analyst is responsible for identifying, analyzing, and mitigating security risks in web applications. Their main duties include performing security assessments, penetration testing, code reviews, and monitoring for vulnerabilities. They work closely with development teams to ensure applications are built securely from the ground up and stay compliant with security standards. Additionally, they keep up to date with the latest security threats and recommend best practices for safeguarding sensitive data.

What are the key skills and qualifications needed to thrive as a web application security analyst?

To thrive as a Web Application Security Analyst, you need expertise in web security concepts, vulnerability assessment, and secure coding practices, often backed by a degree in computer science or cybersecurity and relevant certifications like CEH or OSCP. Familiarity with tools such as Burp Suite, OWASP ZAP, and security information and event management (SIEM) systems is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts identify threats and convey risks to technical and non-technical stakeholders. These skills ensure robust protection of web applications, reducing the risk of breaches and safeguarding sensitive data.

What are some common challenges faced by web application security analysts when working with development teams?

Web Application Security Analysts often face challenges in balancing security requirements with development speed and business goals. They must effectively communicate security risks and recommendations to developers who may not have a security background, which requires strong interpersonal skills and the ability to translate technical findings into actionable steps. Additionally, analysts may need to prioritize vulnerabilities based on risk and resource constraints, ensuring critical issues are addressed without hindering project timelines. Building strong, collaborative relationships with development teams is crucial to successfully integrating security into the software development lifecycle.

What is the difference between Web Application Security Analyst vs Penetration Tester?

AspectWeb Application Security AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, OSCP (preferred)CEH, OSCP, GPEN
Work EnvironmentSecurity teams within organizations, focusing on ongoing security assessmentsConsulting firms or internal teams conducting simulated attacks
Industry UsageCommon in tech, finance, healthcare sectorsUsed across various industries for security testing
Primary FocusMonitoring, analyzing, and improving web application securityIdentifying vulnerabilities through simulated attacks

Both roles involve cybersecurity skills and certifications like CEH or OSCP. However, Web Application Security Analysts focus on maintaining and improving security within organizations, while Penetration Testers simulate attacks to identify vulnerabilities. The roles often overlap but differ in scope and approach.

What cities in Colorado are hiring for Web Application Security Analyst jobs?

Cities in Colorado with the most Web Application Security Analyst job openings:

Infographic showing various Web Application Security Analyst job openings in Colorado as of September 2026, with employment types broken down into 71% Full Time, 26% Part Time, and 3% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $88,687 per year, or $42.6 per hour.

Staff / Sr Staff Application Security Engineer

Boulder, CO โ€ข On-site

SciTec
Guided Missile and Space Vehicle Manufacturingย โ€ขย 51 - 200 employees

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 3 days ago


Key responsibilities

  • Perform application security analysis using automated and manual techniques, including static code analysis, software composition analysis, fuzzing, and manual reviews.

  • Identify, analyze, and help remediate application vulnerabilities.

  • Support software engineers in integrating security considerations into system and application designs.


Job description

SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For the past forty-five plus years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions.

Important Notice: SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered.

SciTec has an immediate opportunity for a talented engineer to support our programs delivering Next-Generation Missile Warning software. This is a unique opportunity to join a business delivering core capabilities for National defense. You will work within a fast-paced team delivering end-to-end software processing of Overhead Persistent InfraRed (OPIR) sensor data for Missile Warning, Missile Defense, Battlespace Awareness, and Technical Intelligence.

We are seeking an Application Security Engineer to help secure mission-critical software systems by identifying, analyzing, and mitigating application-level vulnerabilities. This role focuses on hands-on security analysis, tooling integration, and working directly with software engineers to embed security into the development lifecycle.

The ideal candidate combines strong technical security skills with the ability to collaborate effectively with developers in a DevSecOps environment.

Responsibilities
  • Perform application security analysis using both automated and manual techniques, including:
    • Static code analysis (SAST)
    • Software composition analysis (SCA)
    • Fuzzing
    • Manual code and design reviews
  • Identify, analyze, and help remediate application vulnerabilities
  • Support software engineers in integrating security considerations into system and application designs
  • Integrate and maintain application security tooling within CI/CD and DevSecOps pipelines
  • Design, implement, and improve continuous integration security analysis tooling
  • Tune and maintain security tools to reduce false positives and improve signal quality
  • Assist development teams in understanding findings and implementing effective fixes
  • Support threat modeling and secure design reviews
  • Stay current with emerging vulnerabilities, attack techniques, and mitigation strategies
  • Document findings, recommendations, and best practices
  • Perform other duties as assigned

Requirements

  • Bachelor’s degree plus 2+ years of professional experience in cybersecurity or software development, or equivalent experience
  • 2+ years of experience focused on application/software security
  • Experience analyzing source code for security flaws
  • Familiarity with secure software development practices
  • Strong analytical, problem-solving, and communication skills
  • Detail-oriented with strong written and verbal communication abilities
  • Ability to qualify for and maintain a DoD or DoE Secret security clearance
  • Ability to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire
  • Good verbal and written communication skills
  • Attention to detail

Candidates who have any of the following skills will be preferred:

  • Active DoD Secret clearance or higher
  • Experience identifying, exploiting, and remediating application vulnerabilities
    • Credit for published CVEs is a strong plus
  • Proficiency in one or more programming languages such as C++, Python, JavaScript, Rust
  • Experience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube)
  • Experience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray)
  • Experience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar)
  • Experience with debugging, runtime instrumentation, or reverse engineering, including tools such as:
    • strace
    • eBPF
    • Ghidra or IDA Pro
  • Familiarity with threat modeling methodologies and frameworks such as MITRE ATT&CK
  • Experience working in DevSecOps or Agile development environments

*Resumes, Cover Letters, and Applications which are generated by AI will not be considered for employment.

Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

Benefits

SciTec offers a highly competitive salary and benefits package, including:

  • 4% Safe Harbor 401(k) match
  • 100% company paid HSA Medical insurance, with a choice of 2 buy-up options
  • 80% company paid Dental insurance
  • 100% company paid Vision insurance
  • 100% company paid Life insurance
  • 100% company paid Long-term Disability insurance
  • 100% company paid Hospital Indemnity insurance
  • Voluntary Accident and Critical Illness insurance
  • Short-term Disability insurance
  • Annual Profit-Sharing Plan
  • Discretionary Performance Bonus
  • Paid Parental Leave
  • Generous Paid Time Off, including Holiday, Vacation, and Sick Pay
  • Flexible Work Hours

The pay range for this position is $98,000 - $146,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education/training, and key skills. This is not a guarantee of compensation.

SciTec is proud to be an Equal Opportunity employer. VET/Disabled.


SciTec logo

About SciTec

Sourced by ZipRecruiter

Industry

Guided missile and space vehicle manufacturing

Company size

51 - 200 Employees

Headquarters location

Princeton, NJ, US

Year founded

1979