Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Software Mind

Senior Security Analyst – Application Security, DevSecOps

Software Mind

Senior Security Analyst for Software Mind focusing on security in the software development lifecycle. Engaging with engineering teams to ensure embedding of security practices across SDLC.

Posted 6/16/2026full-timeRemote • 🇨🇷 Costa RicaSeniorWebsite

Tech Stack

Tools & technologies
AWSAzureCloudSDLC

About the role

Key responsibilities & impact
  • Partner with development teams to embed secure coding practices throughout the SDLC, shifting security from a final gate to a shared, integrated responsibility
  • Assess current development practices against Secure SDLC standards, identify gaps, and drive a phased maturity roadmap with measurable milestones
  • Lead developer enablement initiatives — secure coding guidance, threat modeling, and a security champions program — that build durable capability within engineering teams
  • Integrate and tune SAST, DAST, SCA, and secrets scanning in CI/CD pipelines (Azure DevOps, Bitbucket) to deliver fast, in-workflow feedback with minimal friction
  • Evaluate prospective products, platforms, SaaS tools, and developer tooling to confirm alignment with security best practices before adoption
  • Conduct architecture and design reviews, assessing authentication, authorization, data handling, encryption, logging, and multi-tenancy considerations
  • Review third-party and supply chain risk — dependencies, integrations, AI/ML components, and vendor security posture — and define conditions for safe use
  • Produce clear, risk-based assessments and recommendations (approve, approve-with-conditions, or reject) for engineering and security leadership
  • Partner with vendor risk and compliance functions to align product reviews with SOC 2 and broader control requirements
  • Implement policy-as-code guardrails and infrastructure-as-code security controls across Azure/M365 cloud environments
  • Drive cloud posture improvements — configuration hardening, CIS benchmark alignment, WAF, and network segmentation
  • Establish supply chain security controls including dependency governance and code signing

Requirements

What you’ll need
  • 5+ years of experience in Application Security, DevSecOps, or a similar role
  • Demonstrated experience maturing an engineering organization through Secure SDLC adoption — not just deploying tools
  • Hands-on AppSec and DevSecOps background: SAST/DAST/SCA, CI/CD pipeline security, secrets management
  • Strong product and technology security review experience — ability to assess a new platform or tool and articulate concrete risks and mitigations
  • Experience with CI/CD and source control tooling (Azure DevOps, Bitbucket, or equivalents)
  • Familiarity with secure development frameworks (NIST SSDF, OWASP SAMM/ASVS, BSIMM)
  • Cloud security experience in AWS and/or Azure
  • Strong collaboration and communication skills — able to coach developers and present risk to both technical and executive audiences
  • +90% English proficiency (written and spoken, minimum B2 level)

Benefits

Comp & perks
  • Flexible schedules
  • An authentic work-life balance
  • Payment in US Dollars

ATS Keywords

✓ Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
Secure SDLCSASTDASTSCACI/CD pipeline securitysecrets managementcloud securityconfiguration hardeningpolicy-as-codeinfrastructure-as-code
Soft Skills
collaborationcommunicationcoachingrisk assessmentleadership