Principal Application Security Analyst

Posted 4 Days Ago
Be an Early Applicant
2 Locations
In-Office or Remote
135K-165K Annually
Senior level
Insurance
The Role
Build and operate an enterprise application security program. Responsibilities include managing SAST, DAST, SCA, API, and secrets scanning; integrating security testing into CI/CD; triaging vulnerabilities; distinguishing exploitable findings from false positives; coordinating remediation; delivering secure-coding education; translating security standards into developer guidance; applying threat intelligence; and producing risk-based reporting for technical, managerial, and executive audiences.
Summary Generated by Built In
U.S. Citizenship is required for this position due to Department of Defense restrictions.

Our Principal Application Security Analyst builds and operates WPS’s enterprise Application Security program, reducing application risk by operationalizing secure-development standards, strengthening developer secure-coding practices, running application-security testing tools, and reporting results to technical, managerial, and executive audiences. They sit within our Cyber Threat Management team and work in close partnership with Cyber Trust & Architecture, that own enterprise security standards, to translate those standards into practical developer guidance and testing criteria. This Senior Analyst is an individual-contributor position requires technical depth and will provide organizational influence to work independently with developers, interpret application security findings, and communicate risk at multiple levels of the organization. Success in this role will strengthen the security of WPS applications throughout the SDLC. This Principal Analyst manages day-to-day application-security testing, triage, and developer engagement independently, while partnering with Cyber Trust & Architecture on standards interpretation and with the Manager, Cyber Threat Management on program priorities.

Salary Range - $135,000 ~ $165,000
The base pay offered for this position may vary within the posted range based on your job-related knowledge, skills, experience and may fall outside of this range.
Work Location
Our first consideration will be to have this employee be able to take advantage of Hybrid work and collaboration, living within the state of Wisconsin. Employees within 45 miles of WPS Headquarters (1717 W. Broadway in Madison, WI, 53713) will be expected to be able to work in office 3 days a week on a regular basis.

How do I know this opportunity is right for me?  If you:

  • Can operate, tune, and continuously improve enterprise application-security testing capabilities (SAST, DAST, SCA, API and secrets scanning), distinguishing exploitable weaknesses from false positives and integrating testing into the development and CI/CD lifecycle.
  • Want to partner with Cyber Trust & Architecture to translate enterprise application-security standards and secure-by-design requirements into practical developer guidance, testing criteria, and implementation practices across the software-development lifecycle.
  • Have built and delivered a developer-focused secure-coding education program, using real vulnerability trends and hands-on guidance to strengthen developers’ ability to meet enterprise security standards.
  • Enjoy developing and maintaining technical, managerial, and executive reporting that translates application-security findings, vulnerability trends, and standards adoption into actionable, risk-based information.
  • Thrive when coordinating the remediation of application vulnerabilities with developers and system owners, prioritizing based on actual exploitability and business risk, and validating fixes through retesting.
  • Want to apply current threat intelligence and attacker techniques to application-security testing and priorities, partnering with Cyber Trust & Architecture, Cyber Risk & Assurance, and development teams to strengthen security outcomes. 

Minimum Qualifications

  • U.S. Citizenship is required for this position due to Department of Defense restrictions.
  • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Systems, or a related field or equivalent combination of education and relevant work experience.
  • 5 or more years of progressive experience in application security, software security, DevSecOps, or a related technical security discipline.
  • Hands-on experience with application-security testing technologies (SAST and DAST), the ability to tune tools and independently validate findings, and experience translating cybersecurity standards and technical requirements into practical developer guidance and secure-coding training.
  • Proficient knowledge of common application vulnerabilities and attack techniques,  that could include: Authentication / Authorization, Injection, Session management, API security, Insecure dependencies, etc.
  • Knowledge of modern software-development methodologies, CI/CD pipelines, APIs, and cloud-based application environments, sufficient to integrate security testing into the development lifecycle.
  • Excellent analytical skills in distinguishing exploitable vulnerabilities from false positives and prioritizing remediation based on actual risk.
  • Strong communication, problem solving, and decision-making skills.

 Preferred Qualifications

  • Knowledge of OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and MITRE ATT&CK.
  • Professional certification such as CSSLP, GWAPT, GWEB, or OSWE.

Remote Work Requirements

  • Wired (ethernet cable) internet connection from your router to your computer.
  • High speed cable or fiber
  • Minimum of 10 Mbps downstream and at least 1 Mbps upstream internet connection (can be checked at https://speedtest.net).
  • Please review Remote Worker FAQs for additional information.

Benefits

  • Remote and hybrid work options available
  • Performance bonus and/or merit increase opportunities
  • 401(k) with a 100% match for the first 3% of your salary and a 50% match for the next 2% of your salary (100% vested immediately)
  • Competitive paid time off
  • Health insurance, dental insurance, and telehealth services start DAY 1
  • Professional and Leadership Development Programs
  •  Review additional benefits: (https://www.wpshealthsolutions.com/careers/)

Who We Are

WPS, a health solutions company, is a leading not-for-profit health insurer and federal government contractor headquartered in Madison, Wisconsin. WPS offers health insurance plans for individuals, families, seniors and group health plans for small to large businesses. We process claims and provide customer support for beneficiaries of the Medicare program and manage benefits for millions of active-duty and retired military personnel across the U.S. and abroad. WPS has been making healthcare easier for the people we serve for nearly 80 years. Proud to be military and veteran ready.

Culture Drives Our Success

WPS’ culture is where the great work and innovations of our people are seen, fueled and rewarded. We accomplish this by creating an open and empowering employee experience. We recognize the benefits of employee engagement as an investment in our workforce—both current and future—to effectively seek, leverage, and include differing and unique perspectives that fuel agility and innovation on high-performing teams. This results in people bringing their authentic selves to work every day in an organization that successfully adapts to business changes and new opportunities.

We are proud of the recognition we have received from local and national organization regarding our culture and workplace:  WPS Newsroom - Awards and Recognition.

Sign up for Job Alerts

FOLLOW US!

Instagram
LinkedIn
Facebook
WPS Health Blog  

This position may from time to time provide support to federal health care programs and other governmental or regulated industries. In accordance with law and/or contractual requirements, individuals in this role are or may be subject to all applicable federal regulations, agency contract requirements, and WPS internal policies, including but not limited to standards for data security, privacy, confidentiality, and program integrity. WPS and its personnel are subject to mandatory enhanced screening and background investigation prior to being granted access to information systems and/or sensitive data in order to safeguard regulated information and government resources that provide critical services.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Skills Required

  • U.S. citizenship due to Department of Defense restrictions
  • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Systems, or a related field, or equivalent education and relevant work experience
  • Five or more years of progressive experience in application security, software security, DevSecOps, or a related technical security discipline
  • Hands-on experience with SAST and DAST technologies, including tuning tools and independently validating findings
  • Experience translating cybersecurity standards and technical requirements into developer guidance and secure-coding training
  • Knowledge of common application vulnerabilities and attack techniques, including authentication, authorization, injection, session management, API security, and insecure dependencies
  • Knowledge of software development methodologies, CI/CD pipelines, APIs, and cloud-based application environments
  • Excellent analytical skills for distinguishing exploitable vulnerabilities from false positives and prioritizing remediation based on risk
  • Strong communication, problem-solving, and decision-making skills
  • Knowledge of OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and MITRE ATT&CK
  • Professional certification such as CSSLP, GWAPT, GWEB, or OSWE
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Monona, WI
2,082 Employees
Year Founded: 1946

What We Do

WPS Health Solutions is celebrating 75 years in business as a highly regarded government contractor and leader in the insurance industry. In 2021, the Wisconsin State Journal named WPS as a Top Workplace in the Madison area. WPS has several divisions committed to delivering high-quality service to our customers. - WPS Health Insurance and WPS Health Plan offer affordable health plans for individuals, small businesses, and large businesses, plus benefits administration. - WPS Government Health Administrators administers Part A and Part B Medicare benefits—services we have provided since the program’s inception—for millions of seniors in multiple states. - WPS Military and Veterans Health serves millions more beneficiaries who are active in the U.S. military, veterans, and their families. - EPIC Specialty Benefits has offered voluntary nonmedical benefits, such as term life, disability, dental, and vision, for more than 35 years. WPS also actively partners with nonprofit organizations to help make lasting changes in the communities we serve, with an emphasis on health issues, especially for military and veterans, women, and children.

Similar Jobs

MongoDB Logo MongoDB

Senior Software Engineer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
126K-248K Annually

Skillsoft Logo Skillsoft

Senior Director, Commercial Operations

Artificial Intelligence • Consumer Web • Edtech • HR Tech • Information Technology • Software • Conversational AI
Remote
United States
2900 Employees
215K-235K Annually

Engine Logo Engine

Sr. Partner Acquisition Manager - Healthcare

Artificial Intelligence • Fintech • Software • Travel
Easy Apply
Remote
United States
1000 Employees
190K-225K Annually

Cloudflare Logo Cloudflare

Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
2 Locations
4400 Employees

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account