Talent.com
Application Security Analyst
Application Security AnalystMarriott Vacations Worldwide • Orlando, Florida, US
No longer accepting applications
Application Security Analyst

Application Security Analyst

Marriott Vacations Worldwide • Orlando, Florida, US
11 days ago
Job type
  • Full-time
Job description

Find out more about the daily tasks, overall responsibilities, and required experience for this opportunity by scrolling down now.

  • Relocation Assistance Available
  • Required three (3) days in the Orlando Headquarters Office and remote two (2) days.
  • Position Summary As a member of the professional staff, contributes general knowledge and skill in a discipline area.

(e.g., Accounting, Finance, Human Resources, Information Resources, Operations Planning & Support, Sales & Marketing) to support team and / or department objectives.

Generally, works under limited supervision, but within established guidelines, producing and analyzing more.

complex business information to assist in the decision-making process.

Specific Job Summary The Application Security Analyst role is responsible for incorporating security measures into the complete DevOps lifecycle and ensuring that security is an integral aspect of all software development and deployment processes.

This position focuses on conducting comprehensive security assessments like static and dynamic analyses, code reviews, and automated vulnerability scans across various applications and environments.

It also involves enforcing secure coding standards by collaborating with development, operations, and security teams to integrate vulnerability remediation within CI / CD pipelines.

In addition to conducting hands-on offensive security testing, this role requires expertise in mapping attack scenarios to frameworks such as the MITRE ATT&CK framework to assess the organization's defense mechanisms.

The individual will be responsible for identifying weaknesses in both existing and new systems and providing detailed recommendations for improving security measures across various technology environments.

The ideal candidate is a highly skilled and collaborative security professional with a deep understanding of offensive security techniques and a passion for improving security processes through continuous testing and learning.

Expected Contributions Contributes to team, department, and / or business results by performing complex quantitative and qualitative analysis for business processes and / or projects.

Often manages small projects, business processes or parts of larger ones.

Responds to, solves, and makes decisions on more complex / non-routine business requests with limited to moderate risk.

Performs more complex quantitative and qualitative analysis for business processes and / or projects.

Often manages small projects, business processes or parts of larger ones.

Responds to, solves, and makes decisions on more complex / non-routine business requests with limited to moderate risk.

Assists more senior associates in achieving business results by : identifying opportunities to enhance the effectiveness of business processes.

participating in setting department operating plans.

achieving results against budget within scope of responsibility.

Demonstrates an awareness of personal strengths and areas for improvement and acts independently to improve and increase skills and knowledge.

Specific Expected Contributions Conducts thorough penetration testing of infrastructure, web applications, APIs, and cloud environments to identify vulnerabilities and potential attack vectors.

Collaborates with application development teams to implement security testing practices early in the software development lifecycle (SDLC), ensuring secure code and configurations.

Reviews application development processes to ensure secure coding practices are followed, identifying vulnerabilities in the development, staging, and production environments.

Leads red team exercises simulating advanced persistent threats (APTs) to assess the organization’s security resilience in real-world attack scenarios.

Collaborates closely with blue team members to provide feedback on detection and response efforts and support the development of effective defenses.

Maps offensive security test results to the MITRE ATT&CK framework to ensure comprehensive understanding of adversary tactics, techniques, and procedures (TTPs).

Executes vulnerability assessments and perform threat simulations to evaluate the effectiveness of security controls in place.

Conducts vulnerability validation, including verifying the exploitability of identified vulnerabilities and conducting follow-up testing to confirm remediation.

Leads and mentor junior security analysts, providing guidance on offensive security techniques and tools.

Develops and refines testing methodologies, including custom attack scenarios to improve the organization’s testing capabilities.

Collaborates with IT, security engineering, and development teams to ensure vulnerabilities are prioritized and remediated effectively.

Documents and communicates findings, providing clear, actionable recommendations to improve security across technology platforms.

Stays up to date with emerging threats and vulnerability trends, continuously improving security testing practices and capabilities.

Candidate Profile Successful candidates should possess knowledge, experience, and demonstrate leadership skills as follows : Generally, a professional position with specific knowledge in a discipline (e.g., Accounting, Human Resources, Information Resources).

College degree and / or relevant experience typically required.

Specific Candidate Profile Education Bachelor’s degree in computer science, Information Security, or a related field.

Equivalent work experience may be considered in lieu of a degree.

Certifications Preferred Offensive Security Certified Professional (OSCP) Certified Ethical Hacker (CEH) GIAC Penetration Tester (GPEN) Offensive Security Web Expert (OSWE) Certified Secure Software Lifecycle Professional (CSSLP) GIAC Web Application Penetration Tester (GWAPT) Experience At least 4 years of experience in offensive security roles, including penetration testing, red teaming, and application security testing.

Hands-on experience with penetration testing tools (e.g., Burp Suite, Metasploit, Kali Linux, Cobalt Strike) and custom scripting for security testing.

Proven expertise in identifying and exploiting vulnerabilities in applications, including web applications, mobile apps, APIs, and cloud platforms.

Experience working with modern development practices, including DevSecOps, CI / CD pipelines, and integrating security testing into the software development lifecycle (SDLC).

Deep knowledge of application security testing methods, including static analysis, dynamic analysis, and fuzzing.

Familiarity with security practices such as Secure Development Lifecycle (SDL), Secure Code Reviews, and application security code scanning.

Experience with cloud platforms (AWS, Azure, GCP) and container security (e.g., Docker, Kubernetes).

Ability to map attack scenarios to the MITRE ATT&CK framework and provide insights for improving security defenses.

Skills / Attributes Advanced Penetration Testing Skills : Deep knowledge of testing web and mobile applications, APIs, and cloud services for vulnerabilities, with strong experience exploiting weaknesses to simulate real-world attacks.

Application Security Expertise : Extensive experience with application security practices, secure code reviews, and vulnerability scanning tools.

Secure Development Knowledge : Strong understanding of application development methodologies (e.g., Agile, DevOps) and experience incorporating security into development processes and pipelines.

Red Team Expertise : Ability to simulate sophisticated attack techniques and scenarios, providing insight into potential attack paths and evaluating the organization’s defenses.

Cloud Security Knowledge : Solid understanding of cloud security best practices, including securing cloud environments (AWS, Azure) and containerized applications (Docker, Kubernetes).

Vulnerability Management & Exploitability : Expertise in validating vulnerabilities, assessing their risk, and verifying exploitability across a wide range of systems.

Incident Response Collaboration : Ability to work with incident response teams to translate offensive testing results into actionable intelligence for defensive improvements.

Strong Documentation and Reporting Skills : Ability to document testing methodologies, findings, and recommendations clearly and concisely, and communicate technical issues to both technical and non-technical stakeholders.

Mentorship & Leadership : Ability to lead and mentor junior security team members, promoting a culture of continuous improvement in offensive security practices.

Problem-Solving & Analytical Thinking : Strong problem-solving skills, with the ability to think like an attacker to uncover vulnerabilities and develop strategies for exploitation and risk mitigation.

Marriott Vacations Worldwide is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture.

Create a job alert for this search

Application Analyst • Orlando, Florida, US

Related jobs
Cyber Operations Specialist

Cyber Operations Specialist

United States Army • Orlando, FL, US
Full-time
As a Cyber Operations Specialist, you’ll use your cyber security skills to defend the Army’s crucial and complex weapons systems, which include satellites, navigation, and aviation systems against ...Show more
Last updated: 5 days ago • Promoted
Cyber Warfare Technician

Cyber Warfare Technician

US Navy • Orlando, Florida, US
Part-time
Languages are more than just communication-they're cultural codes that need to be analyzed and in some cases, broken.As a Cryptologic Technician Interpretive (CTI) you're more than a linguist-you'r...Show more
Last updated: 30+ days ago • Promoted
Target Security Specialist

Target Security Specialist

Target • Kissimmee, FL, US
Full-time
Starting Hourly Rate / Salario por Hora Inicial : $17.Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture.Asset...Show more
Last updated: 30+ days ago • Promoted
Information Technology Professional

Information Technology Professional

U.S. Navy • Winter Garden, FL, US
Full-time +1
To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.At any given moment, hundreds of complex networked computer systems are operating in tandem to keep ships and su...Show more
Last updated: 1 day ago • Promoted
Software Security Engineer, Experienced or Senior (Virtual)

Software Security Engineer, Experienced or Senior (Virtual)

The Boeing Company • Orlando, FL, United States
Permanent +1
At Boeing, we innovate and collaborate to make the world a better place.We're committed to fostering an environment for every teammate that's welcoming, respectful and inclusive, with great opportu...Show more
Last updated: 1 day ago • Promoted
Cognos Server Administration Manager HYBRID

Cognos Server Administration Manager HYBRID

Rotech Healthcare Inc. • Oak Ridge, FL, United States
Full-time
We help patients lead a more comfortable and productive life by keeping them engaged in their care and empowering them to manage their health and treatment at home. Rotech provides high quality medi...Show more
Last updated: 30+ days ago • Promoted
Software Engineer-Level 3-Security Clearance Eligibility Required

Software Engineer-Level 3-Security Clearance Eligibility Required

AVT Simulation • Orlando, FL, US
Full-time
Quick Apply
Job Summary Software engineers are responsible for the design, development, maintenance, and documentation of software applications. A software engineer is expected to be able to apply industry best...Show more
Last updated: 30+ days ago
Military Intelligence Officer

Military Intelligence Officer

U.S. Navy • Gotha, FL, US
Full-time +1
To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing...Show more
Last updated: 1 day ago • Promoted
Mechanical / Hardware Engineer-Security Clearance Eligibility Required

Mechanical / Hardware Engineer-Security Clearance Eligibility Required

AVT Simulation • Orlando, FL, US
Full-time
Quick Apply
Job Summary We are seeking an experienced mechanical engineer to join our simulation industry team.In this role, you will assist in the design, development, and testing of simulation software and h...Show more
Last updated: 30+ days ago
Bomb Technical

Bomb Technical

U.S. Navy • Winter Garden, FL, US
Full-time +1
To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.Americans live for fireworks on the Fourth of July. The other 364 days of the year, Explosive Ordnance Disposal (...Show more
Last updated: 1 day ago • Promoted
Cyber Warfare Technician

Cyber Warfare Technician

U.S. Navy • Orlando, FL, US
Full-time +1
To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.As a Cryptologic Technician, you are one of the worlds greatest problem-solvers. Were looking for people with sha...Show more
Last updated: 1 day ago • Promoted
Cyber Warfare Technician

Cyber Warfare Technician

Navy • Mount Plymouth, FL, United States
Full-time
ABOUT Enlisted Sailors in the Navy Cryptology community analyze encrypted electronic communications, jam enemy radar signals, decipher information in foreign languages, and maintain state-of-the-ar...Show more
Last updated: 30+ days ago • Promoted
Software Engineer-Security Clearance Eligibility Required.

Software Engineer-Security Clearance Eligibility Required.

AVT Simulation • Orlando, FL, US
Full-time
Quick Apply
Job Summary Software engineers are responsible for the design, development, maintenance, and documentation of software applications. A software engineer is expected to be able to apply industry best...Show more
Last updated: 30+ days ago
KERNEL SOFTWARE DEVELOPER

KERNEL SOFTWARE DEVELOPER

NPA WorldWide • Apopka, Florida, USA
Full-time +1
As a Kernel Software Developer at our global client, you will design, implement, and maintain key subsystems in the kernel, working across Windows, Linux and MacOS environments.This role is ideal f...Show more
Last updated: 3 days ago • Promoted
Customs and Border Protection Officer - Experienced (GS9)

Customs and Border Protection Officer - Experienced (GS9)

U.S. Customs and Border Protection • Christmas, Florida, US
Permanent
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show more
Last updated: 30+ days ago • Promoted
Database Administrator

Database Administrator

Hard Rock Digital • Winter Garden, Florida, US
Full-time
Do you have the right skills and experience for this role Read on to find out, and make your application.Hard Rock Digital is a team focused on becoming the best online sportsbook, casino, and soci...Show more
Last updated: 7 hours ago • Promoted • New!
IT Analyst Service and Support

IT Analyst Service and Support

Fresh Express • Windermere, FL, USA
Full-time
Quick Apply
The IT Analyst, Service and Support will provide services and support to the corporate office users.This position will help maintain IT Systems and will resolve a variety of technical issues relate...Show more
Last updated: 30+ days ago
Technical Account Executive | MSP - Cyber - Cloud 150k++

Technical Account Executive | MSP - Cyber - Cloud 150k++

Living Talent • Kissimmee, FL, US
Full-time
Quick Apply
Technical Account Executive - Sales Rep for MSP supporting SMBs.Location : Southwest Orlando (Hybrid Schedule).Base Salary 75k - 100k+ (commensurate with experience and achievements).Drive sales pip...Show more
Last updated: 22 hours ago • Promoted • New!