1

Web Application Security Analyst Jobs (NOW HIRING)

Security Engineer (Web Application) Location: Arlington, VA Security Clearance: Secret Duties and ... Strong organizational, analytical, and technical writing skills to be able to document findings in ...

Application Security Engineer

$60.25 - $80.25/hr

Monitor and analyze security events, alerts, and logs generated by the web application firewall systems. Investigate and respond to potential security incidents, working closely with the Security ...

The Application Security Analyst is responsible for ensuring the security of homegrown and 3rd party applications. The role emphasizes analytical and advisory responsibilities rather than hands-on ...

The Application Security Analyst is responsible for ensuring the security of homegrown and 3rd party applications. The role emphasizes analytical and advisory responsibilities rather than hands-on ...

Identify, analyze, and remediate web application vulnerabilities, insecure dependencies, misconfigurations, and security weaknesses. * Support vulnerability management activities throughout the ...

Ten company-paid holidays per year About the Role The Application Security Analyst helps embed ... Web Expert), CEH (Certified Ethical Hacker) * 4+ years of experience in application security ...

Join us as an Application Security Analyst for Barclays, where you will support the delivery and continuous enhancement of Application Security and DevSecOps capabilities, bringing practical ...

Web server/web application-based experience * Application Security * WAF experience * HTTP * HP ... The security analyst will leverage Splunk to analyze logs and other security events including ...

Showing results 21-40

Web Application Security Analyst information

See salary details

$64K

$84.3K

$94K

How much do web application security analyst jobs pay per year?

As of Sep 8, 2026, the average yearly pay for web application security analyst in the United States is $84,342.00, according to ZipRecruiter salary data. Most workers in this role earn between $82,500.00 and $83,000.00 per year, depending on experience, location, and employer.

What does a web application security analyst do?

A Web Application Security Analyst is responsible for identifying, analyzing, and mitigating security risks in web applications. Their main duties include performing security assessments, penetration testing, code reviews, and monitoring for vulnerabilities. They work closely with development teams to ensure applications are built securely from the ground up and stay compliant with security standards. Additionally, they keep up to date with the latest security threats and recommend best practices for safeguarding sensitive data.

What are the key skills and qualifications needed to thrive as a web application security analyst?

To thrive as a Web Application Security Analyst, you need expertise in web security concepts, vulnerability assessment, and secure coding practices, often backed by a degree in computer science or cybersecurity and relevant certifications like CEH or OSCP. Familiarity with tools such as Burp Suite, OWASP ZAP, and security information and event management (SIEM) systems is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts identify threats and convey risks to technical and non-technical stakeholders. These skills ensure robust protection of web applications, reducing the risk of breaches and safeguarding sensitive data.

What are some common challenges faced by web application security analysts when working with development teams?

Web Application Security Analysts often face challenges in balancing security requirements with development speed and business goals. They must effectively communicate security risks and recommendations to developers who may not have a security background, which requires strong interpersonal skills and the ability to translate technical findings into actionable steps. Additionally, analysts may need to prioritize vulnerabilities based on risk and resource constraints, ensuring critical issues are addressed without hindering project timelines. Building strong, collaborative relationships with development teams is crucial to successfully integrating security into the software development lifecycle.

What is the difference between Web Application Security Analyst vs Penetration Tester?

AspectWeb Application Security AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, OSCP (preferred)CEH, OSCP, GPEN
Work EnvironmentSecurity teams within organizations, focusing on ongoing security assessmentsConsulting firms or internal teams conducting simulated attacks
Industry UsageCommon in tech, finance, healthcare sectorsUsed across various industries for security testing
Primary FocusMonitoring, analyzing, and improving web application securityIdentifying vulnerabilities through simulated attacks

Both roles involve cybersecurity skills and certifications like CEH or OSCP. However, Web Application Security Analysts focus on maintaining and improving security within organizations, while Penetration Testers simulate attacks to identify vulnerabilities. The roles often overlap but differ in scope and approach.

What cities are hiring for Web Application Security Analyst jobs?

Cities with the most Web Application Security Analyst job openings:

What states have the most Web Application Security Analyst jobs?

States with the most job openings for Web Application Security Analyst jobs include:

What are popular job titles related to Web Application Security Analyst jobs?

For Web Application Security Analyst jobs, the most frequently searched job titles are:

Infographic showing various Web Application Security Analyst job openings in the United States as of September 2026, with employment types broken down into 77% Full Time, 19% Part Time, and 4% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $84,342 per year, or $40.5 per hour.

Application & Web Security Specialist

Little Rock, AR • On-site

Full-time

Re-posted 7 days ago


Dillard's rating

5.8

Company rating: 5.8 out of 10

Based on 293 frontline employees who took The Breakroom Quiz

12th of 21 rated department stores


Job description

APPLICATION AND WEB SECURITY SPECIALIST

THE OPPORTUNITY

The Application and Web Security Specialist will serve as a security consultant to Web and Application Developers. You will work with developers on identifying security risks within their applications and validating remediation. This role offers the opportunity to build solid relationships throughout the enterprise, with developers and vendors, while learning about the various technologies employed within our organization. There are other opportunities to serve included with this role that relate to other Security disciplines such as Threat Security, Vulnerability Management, and Event Correlation. 

THE TEAM

The Information Security Team is responsible for the confidentiality of customer and employee information, ensuring the data stored and shared maintains integrity, all while making sure that all of this does not impact the availability of the entire Dillard's enterprise.

This team is expected to be high-performing. To meet this expectation, the team members are communicative and collaborative, always sharing knowledge and research. Members of this team should be able to understand what is expected of them and adjust on the fly, as priorities may change depending on the company's needs. If you are someone who sets a standard of excellence for yourself and you enjoy working alongside others who set the same standard and who genuinely want each of their peers to succeed, you may be the perfect addition to this team. 

WHAT YOU WILL DO

  • Inspect and assess current solutions for Web and Application Security risks
  • Architect and implement security controls within the Software Development Lifecycle (SDLC)
  • Hold recurring cadences with development and security leadership to discuss findings and future paths for the company regarding application security posture
  • Participate in vulnerability verification and assist development teams in remediation based on reports from scanners, along with manual application security testing
  • Conduct application security testing  on code and web environments after every significant modification
  • Ensure security controls comply with applicable laws, regulations, and policies to minimize risk and audit findings
  • Train others in IT on application security concepts and educate developers on risk-based coding, including the OWASP best practices
  • Participate in on-call rotation across the Information Security Team
  • Ensure applications maintain a  Software Bill of Materials (SBOM) for each application
  • Secure and monitor web applications using the web application firewall
  • Secure and monitor all in-house APIs for exploitation
  • Implement security solution(s) for securing AI systems across the environment
  • Collaborate with AI/ML teams to ensure AI security
  • Secure and monitor all in-house AI applications for risk and exploitation

THE SKILLSET

  • Knowledge of web architectures (Apache, WebSphere, CDN, OCP/Docker, Next.JS, React) and ability to read, review, and analyze OOP languages when used in production-ready web applications
  • Understanding of security threats and solutions for applications
  • Experience analyzing risk following regulations, including PCI, HIPAA, Sarbanes-Oxley, and state privacy laws
  • Experience creating processes, procedures, and solutions that reduce technical risk and increase operational efficiency
  • Experience using DAST and SAST tools
  • Experience navigating and monitoring web application traffic through the web application firewall
  • Experience using AI tools for creating and implementing agentic solutions
  • Experience with LLMs, generative AI systems, or LLM-based applications
  • Experience implementing guardrail solutions
  • Hands-on experience with assessing risk and security testing AI systems for OWASP Top 10 for LLMs
  • Ability to work independently and with teams while meeting multiple deadlines
  • Strong interpersonal and communication skills with proven decision-making skills
  • Desire to troubleshoot and lead investigations
  • History of and commitment to ethical behavior and full ethical disclosure

Location & Hours:  This is a full-time, on-site position located at our Little Rock, Arkansas headquarters. A high level of attendance is required as an essential function of this position.

No immigration sponsorship (ex. H-1B, TN, STEM OPT) is available for this position


What Dillard's employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom