{"schemaVersion":"jobsearcher.job.v1","id":"6232e2fba14e2ecaa7f874c8","url":"https://jobsearcher.com/jobs/6232e2fba14e2ecaa7f874c8","canonicalUrl":"https://jobsearcher.com/jobs/6232e2fba14e2ecaa7f874c8","title":"Application Security Analyst Lead","description":"UNIVERSAL Technologies is seeking an Application Security Analyst Lead for an onsite role in Brooklyn, NY or within the 5 boroughs to oversee application security risk evaluation and accreditation for systems involved in large-scale data center migration initiatives. This role focuses on governance, risk acceptance, vulnerability management, and ensuring applications meet enterprise and regulatory security standards prior to production deployment.\nWHO WE ARE\nUNIVERSAL Technologies, LLC is a Women-Owned (M/WBE) IT solutions and consulting company with over 15 years of experience delivering enterprise-grade technology solutions. We partner with public sector and commercial clients to provide high-quality IT services across Development, Business Analysis, Project Management, Cyber Security, Network Engineering, and Systems Architecture. Our mission is to become an extension of our clients’ teams, delivering impactful and scalable solutions.\nWHAT WE OFFER\nCompetitive compensation\nHealth, Dental, and Vision Insurance\nGroup Life Insurance\n401(K)\nHSA/FSA options\nPre-Tax Transportation Program\nGenerous PTO and holiday package\nMANDATORY SKILLS / EXPERIENCE\nMinimum of 8 years of experience in Application Security aligned with standards such as OWASP and NIST\nMinimum of 8 years of experience in Secure Software Development Life Cycle (SSDLC)\nMinimum of 8 years of experience in Threat Modeling and Risk Assessments\nMinimum of 5 years of experience performing application vulnerability scanning (SAST, DAST)\nMinimum of 8 years of experience integrating security into CI/CD and DevSecOps environments (Azure, Jenkins)\nMinimum of 8 years of experience in API security and access control frameworks (OAuth, SAML, SSO)\nMinimum of 8 years of experience in cloud security architectures\nMinimum of 8 years of experience working with security frameworks and compliance standards (NIST, ISO 27001, PCI-DSS, SOC 2, HIPAA, GDPR, FedRAMP, HITRUST)\nMinimum of 8 years of experience in vulnerability management, penetration testing, and security operations\nMinimum of 8 years of experience in incident response and security governance processes\nMinimum of 8 years of experience in Agile environments, project coordination, and stakeholder communication\nHands-on experience with platforms including Windows Server, Linux, IIS, Apache, VMware, and Citrix\nExperience with development technologies including .NET, C#, JavaScript, Python, PowerShell, and web technologies\nHands-on experience with security tools (required): Veracode, IBM AppScan, SD Elements, Burp Suite\nExperience with additional tools (preferred): Checkmarx, Fortify, Prowler, SonarQube, Snyk, Wireshark, OWASP ZAP, Rapid7, STRIDE\nSCOPE OF SERVICES\nLead application security accreditation efforts for systems involved in data center migration initiatives\nEvaluate and analyze application vulnerability scan results to identify risks and security gaps\nDocument vulnerabilities and define mitigation strategies and SLA timelines based on severity and business impact\nAssess whether identified vulnerabilities fall within agency risk tolerance levels\nCommunicate findings and risk posture to business owners, IT leadership, and security stakeholders\nDevelop and enforce risk mitigation strategies and compensating controls\nValidate remediation efforts with development teams and support security certification for production readiness\nManage and enforce Risk Acceptance processes, including formal approval workflows with Business Owners, IT leadership, and CISO\nEnsure alignment with enterprise security policies, regulatory requirements, and compliance standards\nSupport audit readiness and continuous improvement of application security governance practices\nUNIVERSAL Technologies is an equal opportunity employer.\nPay: $80.00 per hour\nApplication Question(s):\nCan you work onsite in Brooklyn, NY?\n8+ years of experience with Security Tools — Must Have: VERACODE, IBM Appscan, SD Elements, Burp Suite?\n8+ years of experience with Technology Stack: ASP, .NET, Visual Basic.NET, Visual Basic, Cold Fusion, JavaScript, HTML, C++, C#, MS PowerApps, Python, Powershell, Shell Scripting, Selenium?\n8+ years of experience in Security Frameworks (NIST, ISO 27001, PCI-DSS, SOC 2, HIPAA, GDPR, FedRAMP, HITRUST)?\n8+ years of experience in Integration of Security in CI/CD Pipeline, DevOps, Dev SecOps (Azure, Jenkins)?\n8+ years of experience in Application Security & Industry Standards (OWASP, NIST)?\n8+ years of experience in Threat Modelling & Risk Assessments?\n8+ years of experience in Secured Software Development Life Cycle (SSDLC)?\n8+ years of experience in API Security & Access Controls (OAuth, SAML, SSO)?\n8+ years of experience in Incident Response & Security Operations?\n8+ years of experience in Security Training & Awareness?\nWork Location: In person","company":"Universal Technologies","rawCompany":"universal technologies","city":"Brooklyn","state":"NY","isRemote":false,"isActive":false,"createdAt":"2026-07-15T15:43:27.387Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Analyst Lead","description":"UNIVERSAL Technologies is seeking an Application Security Analyst Lead for an onsite role in Brooklyn, NY or within the 5 boroughs to oversee application security risk evaluation and accreditation for systems involved in large-scale data center migration initiatives. This role focuses on governance, risk acceptance, vulnerability management, and ensuring applications meet enterprise and regulatory security standards prior to production deployment.\nWHO WE ARE\nUNIVERSAL Technologies, LLC is a Women-Owned (M/WBE) IT solutions and consulting company with over 15 years of experience delivering enterprise-grade technology solutions. We partner with public sector and commercial clients to provide high-quality IT services across Development, Business Analysis, Project Management, Cyber Security, Network Engineering, and Systems Architecture. Our mission is to become an extension of our clients’ teams, delivering impactful and scalable solutions.\nWHAT WE OFFER\nCompetitive compensation\nHealth, Dental, and Vision Insurance\nGroup Life Insurance\n401(K)\nHSA/FSA options\nPre-Tax Transportation Program\nGenerous PTO and holiday package\nMANDATORY SKILLS / EXPERIENCE\nMinimum of 8 years of experience in Application Security aligned with standards such as OWASP and NIST\nMinimum of 8 years of experience in Secure Software Development Life Cycle (SSDLC)\nMinimum of 8 years of experience in Threat Modeling and Risk Assessments\nMinimum of 5 years of experience performing application vulnerability scanning (SAST, DAST)\nMinimum of 8 years of experience integrating security into CI/CD and DevSecOps environments (Azure, Jenkins)\nMinimum of 8 years of experience in API security and access control frameworks (OAuth, SAML, SSO)\nMinimum of 8 years of experience in cloud security architectures\nMinimum of 8 years of experience working with security frameworks and compliance standards (NIST, ISO 27001, PCI-DSS, SOC 2, HIPAA, GDPR, FedRAMP, HITRUST)\nMinimum of 8 years of experience in vulnerability management, penetration testing, and security operations\nMinimum of 8 years of experience in incident response and security governance processes\nMinimum of 8 years of experience in Agile environments, project coordination, and stakeholder communication\nHands-on experience with platforms including Windows Server, Linux, IIS, Apache, VMware, and Citrix\nExperience with development technologies including .NET, C#, JavaScript, Python, PowerShell, and web technologies\nHands-on experience with security tools (required): Veracode, IBM AppScan, SD Elements, Burp Suite\nExperience with additional tools (preferred): Checkmarx, Fortify, Prowler, SonarQube, Snyk, Wireshark, OWASP ZAP, Rapid7, STRIDE\nSCOPE OF SERVICES\nLead application security accreditation efforts for systems involved in data center migration initiatives\nEvaluate and analyze application vulnerability scan results to identify risks and security gaps\nDocument vulnerabilities and define mitigation strategies and SLA timelines based on severity and business impact\nAssess whether identified vulnerabilities fall within agency risk tolerance levels\nCommunicate findings and risk posture to business owners, IT leadership, and security stakeholders\nDevelop and enforce risk mitigation strategies and compensating controls\nValidate remediation efforts with development teams and support security certification for production readiness\nManage and enforce Risk Acceptance processes, including formal approval workflows with Business Owners, IT leadership, and CISO\nEnsure alignment with enterprise security policies, regulatory requirements, and compliance standards\nSupport audit readiness and continuous improvement of application security governance practices\nUNIVERSAL Technologies is an equal opportunity employer.\nPay: $80.00 per hour\nApplication Question(s):\nCan you work onsite in Brooklyn, NY?\n8+ years of experience with Security Tools — Must Have: VERACODE, IBM Appscan, SD Elements, Burp Suite?\n8+ years of experience with Technology Stack: ASP, .NET, Visual Basic.NET, Visual Basic, Cold Fusion, JavaScript, HTML, C++, C#, MS PowerApps, Python, Powershell, Shell Scripting, Selenium?\n8+ years of experience in Security Frameworks (NIST, ISO 27001, PCI-DSS, SOC 2, HIPAA, GDPR, FedRAMP, HITRUST)?\n8+ years of experience in Integration of Security in CI/CD Pipeline, DevOps, Dev SecOps (Azure, Jenkins)?\n8+ years of experience in Application Security & Industry Standards (OWASP, NIST)?\n8+ years of experience in Threat Modelling & Risk Assessments?\n8+ years of experience in Secured Software Development Life Cycle (SSDLC)?\n8+ years of experience in API Security & Access Controls (OAuth, SAML, SSO)?\n8+ years of experience in Incident Response & Security Operations?\n8+ years of experience in Security Training & Awareness?\nWork Location: In person","datePosted":"2026-07-15T15:43:27.387Z","dateModified":"2026-07-15T15:43:27.387Z","hiringOrganization":{"@type":"Organization","name":"Universal Technologies","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Brooklyn","addressRegion":"NY","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"6232e2fba14e2ecaa7f874c8"},"url":"https://jobsearcher.com/jobs/6232e2fba14e2ecaa7f874c8"}}