1

Web Application Security Analyst Jobs (NOW HIRING)

Embed security throughout the Software Development Lifecycle (SDLC). * Perform web application vulnerability assessments, penetration support, and threat modeling activities. * Identify, prioritize ...

Web Application Firewall Engineer

Charlotte, NC · On-site

$46.75 - $62.50/hr

Web Application Firewall Engineer * Location: Charlotte, NC -- Hybrid preferred; local candidates ... Analyze packet captures, CLI output, application logs, and network traffic to troubleshoot security ...

Application Security Engineer

Torrance, CA

$61.25 - $82/hr

... Static Analysis Security Testing (SAST) o Dynamic Application Security Testing (DAST) o Mobile ... Strong knowledge of secure development practices Deep knowledge of common web application ...

We are seeking an application security engineer in a 100% remote role. Experienced candidates will ... analysis time Job Type & Location This is a Contract to Hire position based out of Tampa, FL. Pay ...

Showing results 41-60

Web Application Security Analyst information

See salary details

$64K

$84.3K

$94K

How much do web application security analyst jobs pay per year?

As of Sep 8, 2026, the average yearly pay for web application security analyst in the United States is $84,342.00, according to ZipRecruiter salary data. Most workers in this role earn between $82,500.00 and $83,000.00 per year, depending on experience, location, and employer.

What does a web application security analyst do?

A Web Application Security Analyst is responsible for identifying, analyzing, and mitigating security risks in web applications. Their main duties include performing security assessments, penetration testing, code reviews, and monitoring for vulnerabilities. They work closely with development teams to ensure applications are built securely from the ground up and stay compliant with security standards. Additionally, they keep up to date with the latest security threats and recommend best practices for safeguarding sensitive data.

What are the key skills and qualifications needed to thrive as a web application security analyst?

To thrive as a Web Application Security Analyst, you need expertise in web security concepts, vulnerability assessment, and secure coding practices, often backed by a degree in computer science or cybersecurity and relevant certifications like CEH or OSCP. Familiarity with tools such as Burp Suite, OWASP ZAP, and security information and event management (SIEM) systems is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts identify threats and convey risks to technical and non-technical stakeholders. These skills ensure robust protection of web applications, reducing the risk of breaches and safeguarding sensitive data.

What are some common challenges faced by web application security analysts when working with development teams?

Web Application Security Analysts often face challenges in balancing security requirements with development speed and business goals. They must effectively communicate security risks and recommendations to developers who may not have a security background, which requires strong interpersonal skills and the ability to translate technical findings into actionable steps. Additionally, analysts may need to prioritize vulnerabilities based on risk and resource constraints, ensuring critical issues are addressed without hindering project timelines. Building strong, collaborative relationships with development teams is crucial to successfully integrating security into the software development lifecycle.

What is the difference between Web Application Security Analyst vs Penetration Tester?

AspectWeb Application Security AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, OSCP (preferred)CEH, OSCP, GPEN
Work EnvironmentSecurity teams within organizations, focusing on ongoing security assessmentsConsulting firms or internal teams conducting simulated attacks
Industry UsageCommon in tech, finance, healthcare sectorsUsed across various industries for security testing
Primary FocusMonitoring, analyzing, and improving web application securityIdentifying vulnerabilities through simulated attacks

Both roles involve cybersecurity skills and certifications like CEH or OSCP. However, Web Application Security Analysts focus on maintaining and improving security within organizations, while Penetration Testers simulate attacks to identify vulnerabilities. The roles often overlap but differ in scope and approach.

What cities are hiring for Web Application Security Analyst jobs?

Cities with the most Web Application Security Analyst job openings:

What states have the most Web Application Security Analyst jobs?

States with the most job openings for Web Application Security Analyst jobs include:

What are popular job titles related to Web Application Security Analyst jobs?

For Web Application Security Analyst jobs, the most frequently searched job titles are:

Infographic showing various Web Application Security Analyst job openings in the United States as of September 2026, with employment types broken down into 77% Full Time, 19% Part Time, and 4% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $84,342 per year, or $40.5 per hour.

Web Application and DDoS Security Admin Imperva CWAF SME

Cedar Rapids, IA • On-site

Compunnel
IT Services • 501 - 1,000 employees

Contractor

Posted 7 days ago


Job description

Job Summary
The Web Application & DDoS Security Administrator will administer, maintain, and optimize web application security and DDoS protection solutions supporting public-facing applications, APIs, and web platforms. The role requires deep hands-on expertise with Imperva Cloud WAF (CWAF), WAF policy management, DDoS mitigation, and web application and API security, while balancing security, performance, and business requirements in a fast-paced environment.
Key Responsibilities
• Administer and maintain Imperva Cloud WAF (CWAF) and DDoS protection platforms.
• Manage advanced security controls, including Bot Management, API Security, Client-Side Protection, and Account Takeover (ATO) Prevention.
• Implement, monitor, and tune WAF policies, rules, and security signatures.
• Execute security-related changes, service requests, and incident response activities.
• Partner with application, infrastructure, and security teams to design and implement web security controls.
• Evaluate applications, APIs, networks, and hosting environments and recommend security improvements.
• Troubleshoot complex application security, network security, and web performance issues.
• Support ongoing security reviews, vulnerability remediation, and compliance initiatives.
Required Qualifications
• Hands-on experience with Imperva Cloud WAF (CWAF) and DDoS mitigation technologies.
• Strong knowledge of web application security and API security.
• Strong understanding of HTTP/S, DNS, TCP/IP, and networking concepts.
• Knowledge of web hosting and application architectures.
• Experience analyzing and tuning WAF rules and security policies.
• Strong troubleshooting and problem-solving skills across application and network security domains.
• Ability to communicate effectively with both technical and non-technical stakeholders.
Preferred Qualifications
• Experience with AWS, Azure, or Google Cloud.
• Knowledge of DevSecOps and modern web application architectures.
• Experience balancing security, performance, and business requirements in a fast-paced environment.
Certifications
• CISSP, Security+, CEH, GIAC, or equivalent security certification.

Compunnel logo

About Compunnel

Sourced by ZipRecruiter

Compunnel is a well-known company located in Plainsboro, NJ, US, recognized in the industry of IT Services and Solutions. Established in 1989, Compunnel offers a suite of services that help businesses integrate technology efficiently into their operations, a recognizable name in the IT solutions sphere for over three decades. The company’s service portfolio includes Digital Transformation, Business Intelligence, Cloud Services, Cybersecurity, and Application Modern Services, among others. Guided by its mission "to innovate with industry-leading digital solutions and disruptive tech strategies for unimagining business growth," the company underlines its commitment to offering out-of-the-box solutions to its clients. Remarkable achievements of the company include serving more than 30 Fortune 500 companies and providing job opportunities for over 50,000 individuals.

Industry

It services

Company size

501 - 1,000 Employees

Headquarters location

Plainsboro, NJ, US

Year founded

1994

Social media