1

Web Application Security Analyst Jobs in Ohio (NOW HIRING)

DevSecOps Engineer

Akron, OH · On-site

$85K - $167K/yr

Design and support perimeter security solutions including Web Application Firewalls (WAF), Azure ... Provide analytical and problem-solving expertise to evaluate opportunities, and decisions and ...

Design and support perimeter security solutions including Web Application Firewalls (WAF), Azure ... Provide analytical and problem-solving expertise to evaluate opportunities, and decisions and ...

DevSecOps Engineer

Dayton, OH · Remote

$85K - $167K/yr

Design and support perimeter security solutions including Web Application Firewalls (WAF), Azure ... Provide analytical and problem-solving expertise to evaluate opportunities, and decisions and ...

DevSecOps Engineer

Akron, OH · Remote

$85K - $167K/yr

Design and support perimeter security solutions including Web Application Firewalls (WAF), Azure ... Provide analytical and problem-solving expertise to evaluate opportunities, and decisions and ...

DevSecOps Engineer

Columbus, OH · Remote

$85K - $167K/yr

Design and support perimeter security solutions including Web Application Firewalls (WAF), Azure ... Provide analytical and problem-solving expertise to evaluate opportunities, and decisions and ...

Senior Application Security Engineer

Independence, OH · Hybrid

$111K - $153K/yr

Define and own the enterprise Application Security strategy, roadmap, reference architectures, and secure design patterns for web, mobile, API, microservices, serverless, and AI-enabled applications.

... security work experience with a broad range of exposure to systems analysis, applications ... application teams, and team managers to obtain testing evidence and execute lest scripts. Formally ...

Showing results 41-60

Web Application Security Analyst information

What does a web application security analyst do?

A Web Application Security Analyst is responsible for identifying, analyzing, and mitigating security risks in web applications. Their main duties include performing security assessments, penetration testing, code reviews, and monitoring for vulnerabilities. They work closely with development teams to ensure applications are built securely from the ground up and stay compliant with security standards. Additionally, they keep up to date with the latest security threats and recommend best practices for safeguarding sensitive data.

What are the key skills and qualifications needed to thrive as a web application security analyst?

To thrive as a Web Application Security Analyst, you need expertise in web security concepts, vulnerability assessment, and secure coding practices, often backed by a degree in computer science or cybersecurity and relevant certifications like CEH or OSCP. Familiarity with tools such as Burp Suite, OWASP ZAP, and security information and event management (SIEM) systems is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts identify threats and convey risks to technical and non-technical stakeholders. These skills ensure robust protection of web applications, reducing the risk of breaches and safeguarding sensitive data.

What are some common challenges faced by web application security analysts when working with development teams?

Web Application Security Analysts often face challenges in balancing security requirements with development speed and business goals. They must effectively communicate security risks and recommendations to developers who may not have a security background, which requires strong interpersonal skills and the ability to translate technical findings into actionable steps. Additionally, analysts may need to prioritize vulnerabilities based on risk and resource constraints, ensuring critical issues are addressed without hindering project timelines. Building strong, collaborative relationships with development teams is crucial to successfully integrating security into the software development lifecycle.

What is the difference between Web Application Security Analyst vs Penetration Tester?

AspectWeb Application Security AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, OSCP (preferred)CEH, OSCP, GPEN
Work EnvironmentSecurity teams within organizations, focusing on ongoing security assessmentsConsulting firms or internal teams conducting simulated attacks
Industry UsageCommon in tech, finance, healthcare sectorsUsed across various industries for security testing
Primary FocusMonitoring, analyzing, and improving web application securityIdentifying vulnerabilities through simulated attacks

Both roles involve cybersecurity skills and certifications like CEH or OSCP. However, Web Application Security Analysts focus on maintaining and improving security within organizations, while Penetration Testers simulate attacks to identify vulnerabilities. The roles often overlap but differ in scope and approach.

Infographic showing various Web Application Security Analyst job openings in Ohio as of August 2026, with employment types broken down into 63% Full Time, 12% Part Time, and 25% Contract. Highlights an 83% In-person, and 17% Remote job distribution.

DevSecOps Engineer

Akron, OH • On-site

$85K - $167K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 7 days ago


Job description

Are you seeking purpose, challenge, and talented colleagues? We develop leaders and empower our associates to use their skills and talents to positively impact the world through service - to our coworkers, clients, and communities. We subscribe to the mission of "empowering our people to impact communities by bringing clients' visions to life," so if this speaks to you, let's connect!
At CESO, a DevSecOps Engineer is responsible for designing, building, securing, automating, and maintaining the company's cloud infrastructure and application hosting environments. This position serves as the bridge between infrastructure, software development, and cybersecurity, ensuring that applications and services are secure, scalable, reliable, and operationally efficient. The DevSecOps Engineer owns Azure infrastructure standards, CI/CD pipelines, infrastructure automation, security controls, observability, disaster recovery planning, and environment management across development, testing, and production environments. This position plays a critical role in establishing secure development practices, protecting enterprise systems, and enabling rapid delivery of business applications and AI solutions.
Primary Responsibilities
  • Develop and maintain infrastructure standards, governance policies, naming conventions, tagging strategies, and environment management practices.
  • Build, maintain, and optimize CI/CD pipelines and automated deployment processes that support application and infrastructure delivery, including environment provisioning, approval gates, rollback strategies, and release management procedures.
  • Own Azure networking architecture, including virtual networks, private endpoints, VPN connectivity, DNS, network segmentation, and secure remote access.
  • Manage Azure RBAC, managed identities, service principals, privileged access, and least-privilege security models.
  • Partner with software engineering teams to implement secure coding practices, application security controls, and security-focused development workflows.
  • Configure and manage SAST, DAST, dependency scanning, code quality controls, and vulnerability management processes.
  • Design and support perimeter security solutions including Web Application Firewalls (WAF), Azure Front Door, Application Gateway, and related technologies.
  • Implement monitoring, logging, observability, alerting, and telemetry solutions using Azure Monitor, Application Insights, Log Analytics, and related platforms.
  • Design and maintain high availability, backup, geo-replication, disaster recovery, and business continuity solutions.
  • Maintain architecture documentation, operational runbooks, deployment procedures, and technical reference materials.
  • Provide analytical and problem-solving expertise to evaluate opportunities, and decisions and communication them to relevant parties within the organization.
  • Collaborate effectively with technical and non-technical stakeholders to gather requirements, align priorities, and deliver solutions.
  • Perform other duties as assigned.

Position Requirements
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience is required.
  • Minimum of 3 years of experience in Azure administration, cloud engineering, DevOps, infrastructure engineering, cybersecurity, or related disciplines is required.
  • Experience designing and supporting Azure environments, cloud infrastructure, and enterprise application hosting platforms is required.
  • Azure Administrator, Azure Security Engineer, Azure DevOps Engineer, Cybersecurity, or related industry certifications are preferred.
  • Experience with Azure Front Door, Application Gateway, Web Application Firewall (WAF), Azure Bastion, Azure VPN Gateway, and ExpressRoute is required.
  • Experience implementing SAST, DAST, vulnerability management, dependency scanning, and application security programs is required.
  • Experience supporting and securing modern application architectures, including React, Node.js, .NET, Power Platform, Azure App Services, Azure Functions, APIs, and related cloud technologies is required.
  • Experience managing multi-environment deployment strategies and automated environment provisioning is required.
  • Experience building and maintaining CI/CD pipelines using GitHub Actions, Azure DevOps, or similar platforms is required.
  • Strong understanding of Azure networking concepts, including virtual networks, private endpoints, VPNs, firewalls, routing, and security groups is required.
  • Strong understanding of cloud security, identity management, RBAC, secrets management, and security best practices is required.
  • Working knowledge of software engineering practices, source control management, and application lifecycle management is required.
  • Experience implementing Azure Sentinel, SIEM solutions, security monitoring, and incident response processes is preferred.
  • Experience supporting AI, Azure OpenAI, Copilot, or cloud-based AI application environments is preferred.
  • Experience with Infrastructure-as-Code technologies such as Bicep, Terraform, ARM Templates, Pulumi, or similar tools is preferred.

Benefits and Perks
  • Flexible and Hybrid Work Schedule
  • Paid Time Off - Credited to You 100% Upfront
  • 401K with a Company Match
  • Rewards and Recognition Program
  • Training and Development to Foster Professional Growth
  • Paid Holidays
  • Medical / Dental / Vision Coverage
  • Welcome Box
  • Casual Dress Code
  • Reimbursement for Professional Licenses
  • Paid Time Off for Community Team Service Events
  • Voluntary or Supplemental Short-Term / Long-Term Disability
  • Employee Assistance Program
  • Company Paid Bonding and Recovery
  • Employee Events such as Lunches and Outings to Foster a Positive Work Environment

$85,897 - $167,023 a year
CESO Compensation Transparency:
The pay band shown reflects the minimum and maximum base salary for this position at CESO. Actual pay is determined by several factors, including location, experience, education, skills, and internal equity. Our pay structures are benchmarked against industry and market data to stay competitive. Each offer is based on a full review of a candidate's background, qualifications, and fit for the role.
Below are the typical new hire pay ranges for this position based on location:
• Akron, OH: $85,897 - $108,803
• Columbus, OH: $90,669 - $114,848
• Dayton, OH: $90,669 - $114,848
CESO is a principle-centered organization that aligns with strong service values, integrity, and authenticity. We develop and inspire through training and coaching on the job. At CESO, we believe that work should be more rewarding than just a paycheck. In addition to a comprehensive benefit and compensation program, we create memories and friendships through our employee and service events.
CESO, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, genetics, disability, age, veteran status, or any other characteristic protected by law. This organization participates in E-Verify and is a drug-free workplace. Criminal background checks and drug/alcohol checks are required.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.