Talent.com
Information Security Analyst - Application Security (Penetration Tester)
Information Security Analyst - Application Security (Penetration Tester)UHS • Wayne, PA, US
Information Security Analyst - Application Security (Penetration Tester)

Information Security Analyst - Application Security (Penetration Tester)

UHS • Wayne, PA, US
10 days ago
Job type
  • Full-time
Job description

One of the nation's largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. (NYSE : UHS) has built an impressive record of achievement and performance. Growing steadily since its inception into an esteemed Fortune 300 corporation, annual revenues were $15.8 billion in 2024. During the year, UHS was again recognized as one of the World's Most Admired Companies by Fortune; and listed in Forbes ranking of America's Largest Public Companies. Headquartered in King of Prussia, PA, UHS has approximately 99,000 employees and continues to grow through its subsidiaries. Operating acute care hospitals, behavioral health facilities, outpatient facilities and ambulatory care access points, an insurance offering, a physician network and various related services located all over the U.S. States, Washington, D.C., Puerto Rico and the United Kingdom. www.uhs.com

The Corporate Information Services Department is seeking a dynamic and talented Information Security Analyst I-Application Security.

As a key member of our collaborative Cybersecurity team, the Information Security Analyst I – Application Security will play a critical role in safeguarding UHS and affiliates information systems. In this role, you will be responsible for identifying, assessing, and mitigating security vulnerabilities in our applications, guiding secure development practices, and collaborating with development teams to embed security throughout the software development lifecycle (SDLC).Works with technical and non-technical staff to insure that deployed technologies are effectively and efficiently providing the intended controls consistent with established policies and procedures. Where appropriate, trains and supports technical staff in UHS affiliated locations to deploy, manage and support selected technologies. May oversee the technical aspects of tasks assigned to less experienced staff or contractors on projects, systems or applications assigned.

Key Responsibilities include :

  • Maintains selected information security technologies within guidelines of policies and in keeping with good project management principles. Monitors the resolution of maintenance or enhancement issues assigned by the UHS Customer Support Center.
  • Perform in-depth security assessments of web, mobile, APIs, and cloud-based applications through code reviews, using tools such as SAST, DAST, IAST, SCA, manual techniques, and penetration testing.
  • Periodically reviews deployed security technologies to ensure that the solutions continue to provide the intended protections efficiently and effectively.
  • Work closely with DevOps and engineering teams to integrate security into CI / CD pipelines (DevSecOps).
  • Identifies gaps in protection, and recommends solutions to remediate or mitigate the risks associated with the protection gaps.
  • Document findings and assist in creating reports and metrics for technical and non-technical audiences.
  • Assists more experienced members of the Information Security Team implement and support new information security technologies or processes.
  • Works with staff at all levels in the organization, vendors and contractors to insure protections are effective, efficient and non-disruptive to the appropriate duties, rights and mission of the individuals and the organization(s) affected.

Position Requirements :

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field; or equivalent practical experience. required.
  • Minimum of 1-3 years' experience in application security, vulnerability management, or penetration testing.1-3 years of relevant experience in Application Security (SAST, SCA, DAST, WAF, ASPM), or cybersecurity with background in secure code development (DevSecOps, SSDLC) preferred.
  • Experience with security tools such as GitHub Advanced Security, Veracode, Snyk, or similar is a plus.
  • Experience managing and supporting some or all of the following or similar information security technologies or processes :
  • Anti-malware protections and analysis
  • Web filtering and security
  • Vulnerability scanning and management
  • Encryption technologies for data at rest and data in transit
  • Mobile device and removable media protection or management systems
  • Authentication – including various forms of SSO and MFA
  • Cloud application security
  • Security Information and Event Management (SIEM) systems
  • Interpreting Common Vulnerabilities and Exposures (CVE ) data
  • Device control
  • Data Loss Prevention (DLP)
  • Forensic analysis
  • OWASP Top 10
  • OWASP MASVS (Mobile AppSec Verification Standard)
  • Relevant Entry-Level Certifications (one or more required) :

  • OffSec Web Assessor (OSWA)
  • Burp Suite Certified Practitioner (BSCP)
  • TCM Security Practical Web Pentest Associate (PWPA)
  • TCM Security Practical Web Pentest Professional (PWPP)
  • TCM Security Practical Mobile Pentest Associate (PMPA)
  • SANS GIAC Web Application Penetration Tester (GWAPT)
  • SANS GIAC Web Application Defender (GWEB)
  • SANS GIAC Mobile Device Security Analyst (GMOB)
  • HTB Certified Bug Bounty Hunter (CBBH) – renamed to Certified Web Exploitation Specialist (CWES)
  • Relevant Advanced Certifications (one or more preferred) :

  • Offsec Web Expert (OSWE)
  • HTB Certified Web Exploitation Expert (CWEE)
  • TCM Security Practical Web Pentest Expert (PWPE)
  • Bonus Broader Offensive Security Certifications :

  • OffSec Certified Professional (OSCP)
  • OffSec Experienced Penetration Tester (OSEP)
  • TCM Security Practical Network Penetration Tester (PNPT)
  • Hack the Box (HTB) Certified Penetration Testing Specialist (CPTS)
  • Familiarity with risk assessment and risk management concepts or processes.
  • Working knowledge of various regulatory security requirements – particularly Sarbanes-Oxley (SOX), HIPAA, and HITECH.
  • Working knowledge of common cyber security frameworks such as HITRUST, NIST, CSC20, or others.
  • Familiarity with secure coding practices in Java, Python, PowerShell, JavaScript / TypeScript, Swift / Kotlin is a plus.
  • Experience with mobile testing frameworks (MobSF, Drozer, Frida, Objection) is preferred.
  • Experience with API testing methodologies and tools (Postman, Burp Pro extensions) is preferred.
  • Experience with source control and CI / CD tools (GitHub, GitLab, Jenkins, Azure DevOps).
  • Ability to prioritize multiple tasks and be detail oriented.
  • Excellent communication, technical report writing, interpersonal and project management skills
  • Significant relevant experience in addition to professional certifications and / or an Associate's Degree (4 years) may be considered in lieu of the educational requirement.

    Travel Requirements : Up to 5% - 10% US - to field locations may be necessary to complete assigned projects.

    This opportunity provides the following :

  • Challenging and rewarding work environment
  • Growth and development opportunities within UHS and its subsidiaries
  • Competitive Compensation
  • Excellent Medical, Dental, Vision and Prescription Drug Plan
  • 401k plan with company match
  • Generous Paid Time Off
  • Create a job alert for this search

    Information Security Analyst • Wayne, PA, US

    Related jobs
    Board Certified Behavior Analyst

    Board Certified Behavior Analyst

    Pediatric Therapeutic Services, Inc. • Oley, PA, US
    Full-time
    Pediatric Therapeutic Services (PTS) is seeking a full time Board-Certified Behavior Analyst (BCBA) to provide school-based services to a local school district in Oley, PA.We offer competitive rate...Show more
    Last updated: 21 days ago • Promoted
    Quality Control Analyst

    Quality Control Analyst

    Drug Plastics and Glass Co. Inc. • Boyertown, PA, US
    Full-time
    Drug Plastics is a competitive, growing company that wants people who are eager to share their knowledge, talent, and experiences. We are the premier manufacturer of bottles and closures for medicin...Show more
    Last updated: 30+ days ago • Promoted
    Quality Analyst

    Quality Analyst

    Katalyst Healthcares & Life Sciences • Washington Crossing, PA, US
    Full-time
    This position supports quality activities within Commercial Quality, including compliance with controlled substance regulations, complaint handling, change control, documentation, and audit coordin...Show more
    Last updated: 30+ days ago • Promoted
    Data Analytics Job Training Program

    Data Analytics Job Training Program

    Year Up United • Claymont, DE, US
    Full-time
    Year Up United is a one-year or less, intensive job training program that provides young adults with in-classroom skill development, access to internships and / or job placement services, and persona...Show more
    Last updated: 18 hours ago • Promoted • New!
    Senior Manager, Customer Trust & Field Security Specialist - Capital One Software (Remote)

    Senior Manager, Customer Trust & Field Security Specialist - Capital One Software (Remote)

    Capital One • Wilmington, DE, US
    Remote
    Full-time +1
    Senior Manager - Global Payment Network Information Security Office (ISO) Consultant.At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information ...Show more
    Last updated: 25 days ago • Promoted
    Traffic Control Flagger

    Traffic Control Flagger

    AWP Safety • Pottstown, PA, US
    Full-time
    Unlock Your Career Potential in Traffic Safety with AWP Safety Americas Leading Traffic Management Company!.Overview : AWP Safety is on the lookout for motivated individuals to embark on a rewardin...Show more
    Last updated: 30+ days ago • Promoted
    Quality Analyst

    Quality Analyst

    Artech • Washington Crossing, PA, US
    Full-time
    Job Overview : This role supports commercial quality activities, including controlled substance compliance, product quality complaints, change control, documentation, and audit processes.The positio...Show more
    Last updated: 30+ days ago • Promoted
    Senior Manager, Information Security (Exton)

    Senior Manager, Information Security (Exton)

    Pharmaron • Exton, PA, United States
    Full-time
    Manager, Information Security (Microsoft 365 Security SME).Exton (PA) or Waltham (MA) On-site with travel to other USA locations. The expected salary range is $140,000-$160,000 per year.Unfortunate...Show more
    Last updated: 21 days ago • Promoted
    Security Analyst

    Security Analyst

    Envestnet • Berwyn, PA, US
    Full-time
    This is a hybrid role, with in-office work required at our Berwyn, PA office location.Envestnet is transforming the way financial advice is delivered through its connected technology, advanced insi...Show more
    Last updated: 30+ days ago
    TSA Quality Compliance Coordinator

    TSA Quality Compliance Coordinator

    Thermo Fisher • Swedesboro, NJ, US
    Full-time
    The QA Engineer, II will play a crucial role in maintaining Quality oversight within all operations of the business, while continuously looking for ways to develop and improve systems.Tracks open r...Show more
    Last updated: 18 days ago • Promoted
    Information Security Analyst - Application Security (Penetration Tester)

    Information Security Analyst - Application Security (Penetration Tester)

    UHS • Wayne, PA, United States
    Full-time
    One of the nation’s largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. NYSE : UHS) has built an impressive record of achievement and performance...Show more
    Last updated: 10 days ago • Promoted
    Board Certified Behavioral Analyst

    Board Certified Behavioral Analyst

    Pediatric Therapeutic Services, Inc. • Perkasie, PA, US
    Full-time
    Pediatric Therapeutic Services (PTS) is seeking a full time Board-Certified Behavior Analyst (BCBA) to provide school-based services to a local school district. We offer competitive rates with compe...Show more
    Last updated: 19 days ago • Promoted
    Quality Control Analyst

    Quality Control Analyst

    Insight Global • Malvern, PA, United States
    Full-time
    Fully onsite role in Malvern, PA - in the laboratory.HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid ...Show more
    Last updated: 10 days ago • Promoted
    Sign Maker & Installer

    Sign Maker & Installer

    Signarama • Royersford, PA, US
    Full-time
    Are you skilled with tools and passionate about delivering professional installations? As a Sign Installer at Signarama, you'll be the backbone of our visual impact, ensuring our high-quality signs...Show more
    Last updated: 30+ days ago • Promoted
    Associate Brand Protection Analyst

    Associate Brand Protection Analyst

    CSC (Corporation Service Company) • Wilmington, DE, United States
    Full-time
    Associate Brand Protection Analyst.Monday-Friday, Standard Working Hours.Hybrid Work Model (3 days onsite / 2 days remote). Want to be part of something bigger?.If you want to contribute to a global ...Show more
    Last updated: 6 days ago • Promoted
    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

    Capital One • Wilmington, DE, US
    Remote
    Full-time +1
    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote).Ever since our first credit card customer in 1994, Capital One has recognized that technology and data...Show more
    Last updated: 20 days ago • Promoted
    Senior Manager, Information Security

    Senior Manager, Information Security

    Pharmaron • Exton, PA, United States
    Full-time
    Manager, Information Security (Microsoft 365 Security SME).Exton (PA) or Waltham (MA) – On-site with travel to other USA locations. The expected salary range is $140,000-$160,000 per year.Unfortunat...Show more
    Last updated: 26 days ago • Promoted
    Electronic Visit Verification Specialist

    Electronic Visit Verification Specialist

    365 Health Services • Downingtown, PA, US
    Full-time
    Responsible for maintaining office data in compliance with state, federal and local regulations.Properly document all manual corrections. Ensure office payroll is completed in a timely manner.Utiliz...Show more
    Last updated: 30+ days ago • Promoted
    Information Security Analyst - Application Security (Penetration Tester) (Wayne)

    Information Security Analyst - Application Security (Penetration Tester) (Wayne)

    UHS • Wayne, PA, United States
    Full-time
    One of the nations largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. NYSE : UHS) has built an impressive record of achievement and performance....Show more
    Last updated: 8 days ago • Promoted
    IT Security Architect / Engineer (Remote)

    IT Security Architect / Engineer (Remote)

    Tech Impact • Wilmington, DE, United States
    Remote
    Full-time
    IT Security Architect / Engineer (Remote).Our Mission : To Leverage Technology to Advance Social Impact.Be a part of a fast‑paced, growing team that provides a solid work‑life balance helping our no...Show more
    Last updated: 12 days ago • Promoted