Hicks

AI Security Analyst / Application Security Engineer
SOFTWARE ENGINEERING
RemoteTexas Contract Sep 1, 2026

AI Security Analyst / Application Security Engineer

Remote | Chicago, IL; Peoria, IL; Dallas, TX; or Broomfield, CO | 12 Months | 2 Positions

Job Details

  • Estimated Start Date: October 1, 2026

  • Work Arrangement: 100% remote; candidates must be local to one of the designated digital hubs in Chicago, Peoria, Dallas, or Broomfield

  • Duration: 12 months

  • Travel: Up to 25% as needed

  • Interview Process: One 60-minute virtual panel interview

Job Description

We are seeking experienced AI Security Analysts / Application Security Engineers to help embed application security throughout the software development lifecycle and strengthen security across applications, APIs, cloud workloads, repositories, and supporting infrastructure.

This role combines hands-on application security and DevSecOps expertise with modern AI-assisted security practices. The ideal candidate will be comfortable performing security assessments, validating vulnerabilities, working directly with application code, driving remediation, and partnering with development and DevOps teams to improve security across multiple applications and technology stacks.

Key Responsibilities

  • Define, execute, and continuously improve application security processes, standards, workflows, and Definition of Done criteria throughout the SDLC.

  • Perform AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure.

  • Execute and manage security scanning activities, including:

    • Source code analysis

    • SAST and SCA

    • Secret scanning

    • Dependency analysis

    • Infrastructure reviews

    • AI-driven security reviews

  • Analyze, validate, prioritize, and triage security findings based on exploitability, business impact, severity, compensating controls, and remediation requirements.

  • Drive vulnerabilities through the full remediation lifecycle, including backlog creation, ownership assignment, validation testing, retesting, evidence collection, and closure verification.

  • Identify and reduce security debt, dependency vulnerabilities, outdated libraries, open-source risks, and software supply chain exposure.

  • Perform hands-on security testing using tools and techniques such as Burp Suite, browser developer tools, API testing platforms, and secure code review.

  • Apply OWASP Top 10 and API Security Top 10 principles to identify and address application security risks.

  • Review and modify application code in Java and Python to validate vulnerabilities and assist with remediation.

  • Support remediation through code fixes, configuration changes, infrastructure updates, and compensating controls.

  • Use AI-assisted development and security tools responsibly to accelerate vulnerability analysis, threat modeling, code review, documentation, and remediation guidance.

  • Develop security metrics, coverage reporting, executive dashboards, and portfolio-level security insights.

  • Partner with architects, developers, DevOps engineers, Product Owners, and business stakeholders to communicate risk, prioritize remediation, and remove blockers.

  • Maintain security-related Agile work items, user stories, tasks, and defects within Scrum delivery processes.

  • Monitor emerging threats, AI-related security risks, evolving attack techniques, and vulnerability trends.

  • Promote a security-first culture through coaching, knowledge sharing, and documented best practices.

Required Qualifications

  • Bachelor's and/or Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.

  • 5–7 years of hands-on application security and/or DevSecOps experience.

  • Strong understanding of Secure SDLC, DevSecOps, Agile, and Scrum methodologies.

  • Hands-on experience with security tools and technologies including:

    • Burp Suite

    • GitHub Advanced Security

    • CodeQL

    • SAST

    • SCA

    • Secret scanning

    • Dependency analysis

    • CI/CD security tooling

  • Ability to read, analyze, test, and modify production application code in Java and Python to validate security findings and support remediation.

  • Strong knowledge of OWASP Top 10 and API Security Top 10.

  • Experience with authentication and authorization controls, secure coding principles, and common attack techniques.

  • Understanding of cloud security, identity and access management, and modern application architectures.

  • Experience performing vulnerability triage and validation based on exploitability, business impact, severity, and compensating controls.

  • Experience developing security metrics, coverage reporting, and executive dashboards.

  • Experience safely and effectively using AI-assisted development and security tools.

Ideal Candidate

The ideal candidate is a hands-on application security professional who can do more than run security scans. This person should be able to determine whether findings are truly exploitable, understand application code, work directly with developers on remediation, and drive vulnerabilities through verified closure.

Candidates should also be comfortable operating independently across multiple applications and technology stacks while collaborating closely with engineering, DevOps, architecture, product, and business teams.

Soft Skills

  • Excellent communication and stakeholder management

  • Strong presentation and documentation skills

  • Ability to work independently across multiple applications and teams

  • Strong analytical and problem-solving skills

  • Ability to balance security requirements with usability, operational impact, and business objectives

  • Strong collaboration and influencing skills

  • Ability to negotiate priorities and remove blockers

  • Coaching and knowledge-sharing skills

  • Comfortable working in an Agile/Scrum environment