All roles

[Remote] Application Security Analyst

Remote · USA Full-time New today

Note: The job is a remote job and is open to candidates in USA. HealthStream is the leader in healthcare workforce solutions, dedicated to enhancing the quality of healthcare by empowering the people who deliver care. They are seeking an Application Security Analyst to support and execute the application security program, focusing on identifying and remediating security vulnerabilities across software products and cloud environments while collaborating with various teams to embed security practices into the software development lifecycle.

Responsibilities

  • You will be responsible for adhering to all HealthStream security policies, procedures, and assigned training
  • Operate and manage automated application security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST)
  • Triage, validate, and prioritize vulnerability findings from security scans, penetration tests, and bug reports, working with development teams to track remediation to closure
  • Conduct or support manual security assessments and penetration testing of web applications, APIs, and mobile applications
  • Produce clear, actionable vulnerability reports with risk ratings and remediation guidance for development teams
  • Manage and maintain vulnerability findings within the Snyk, Invicti and SonarQube or equivalent vulnerability management platform
  • Support the integration of security into CI/CD pipelines and DevSecOps workflows, including automated security gate checks
  • Participate in design and architecture reviews with a security lens, helping identify potential risks early in the development process
  • Assist in threat modeling exercises for new features and systems under the guidance of the AppSec Architect
  • Perform security-focused code reviews and provide developers with clear, constructive feedback and guidance
  • Contribute to the maintenance of a secure code library and reusable security patterns for development teams
  • Support the management and configuration of application security tools such as Synk, Invicti, SonarQube and DefectDojo
  • Assist in implementing and monitoring security controls for cloud-based environments, including AWS and Azure
  • Evaluate and test emerging security tools and contribute recommendations to the AppSec team
  • Support API security testing and assist in securing third-party and open-source integrations
  • Collaborate with cross-functional teams including Engineering, DevOps, and Product to promote security best practices and a shift-left mindset
  • Deliver security awareness content and assist in conducting security training sessions for development staff
  • Stay current on emerging security threats, vulnerabilities (CVEs), and attack techniques, sharing relevant intelligence with the team
  • Assist in maintaining security documentation, standards, runbooks, and internal knowledge base articles
  • Support compliance-related activities, including evidence gathering for audits related to HIPAA, SOC 2, HITRUST or other applicable frameworks. FedRAMP experience is a plus
  • Other Duties as assigned

Skills

  • Bachelor's degree in information security, Computer Science, Software Engineering, or a related field. Equivalent practical experience will be considered
  • 2 to 4 years of experience in application security, information security, or software development with a security focus
  • Working knowledge of the OWASP Top 10, common web application vulnerabilities, and secure coding principles
  • Hands-on experience with application security testing tools such as SAST, DAST, or IAST (e.g., Synk, Invicti, Checkmarx, SonarQube, Burp Suite, or similar)
  • Familiarity with cloud security concepts and hands-on exposure to AWS or Azure environments
  • Understanding of CI/CD pipelines and experience integrating security checks into DevOps workflows
  • Experience with API security testing and a solid understanding of RESTful service security
  • Proficiency in at least one scripting or programming language such as Python, JavaScript, Java, or Go for automation and security tooling purposes
  • Strong analytical and problem-solving skills with attention to detail
  • Excellent written and verbal communication skills, with the ability to explain security concepts to both technical and non-technical audiences
  • Ability to manage multiple tasks and vulnerabilities simultaneously, prioritizing effectively in a fast-paced environment
  • Relevant security certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), GWAPT, eWPT, or equivalent
  • Experience using vulnerability management platforms such as Snyk, Invicti, or similar
  • Familiarity with security frameworks and standards including OWASP SAMM, NIST, or CIS Controls
  • Exposure to healthcare industry security and privacy regulations, including HIPAA
  • Experience with secure methods of integration with third-party platforms and open-source components
  • Participation in bug bounty programs, Capture the Flag (CTF) competitions, or open-source security research
  • Awareness of AI/ML security trends and their implications for application security
  • Experience with Identity and Access Management (IAM) security concepts and OAuth/OpenID Connect

Benefits

  • Medical, Dental and Vision insurance
  • Paid Time Off
  • Parental Leave
  • 401k and Roth
  • Flexible Spending Account
  • Health Savings Account
  • Life Insurance
  • Short- and Long-Term Disability
  • Medical Bridge Insurance
  • Critical Illness Insurance
  • Accident Insurance
  • Identity Protection
  • Legal Protection
  • Pet Insurance
  • Employee Assistance Program
  • Fitness Reimbursement
  • Competitive Compensation & Bonuses
  • Comprehensive Insurance Plans
  • Mental and Physical Health Support
  • Work-from-home flexibility
  • Fitness Center Reimbursements
  • Streaming Good time off for volunteering
  • Wellness workshops
  • Buddy Program for new HealthStreamers
  • Collaborative work environment
  • Career growth opportunities
  • Continuous learning opportunities
  • Inspiring workspaces to collaborate and connect with other HealthStreamers
  • Free employee parking at our Resource Centers in Nashville and San Diego
  • Flexibility and paid time off to support work-life integration for all employees, including a hybrid work environment and Streaming Good volunteer day
  • Company-sponsored onsite social events for development, connection, and celebration

Company Overview

  • HealthStream is a HealthTech company that provides training, credentialing, and workforce management software for healthcare organisations.. It was founded in 1990, and is headquartered in Nashville, Tennessee, USA, with a workforce of 501-1000 employees. Its website is http://www.healthstream.com.
  • Company H1B Sponsorship

  • HealthStream has a track record of offering H1B sponsorships, with 1 in 2026, 35 in 2025, 28 in 2024, 18 in 2023, 49 in 2022, 22 in 2021, 23 in 2020. Please note that this does not guarantee sponsorship for this specific role.
  • Apply To This Job

    Related roles

    [Remote] Veterinary Technician Recruiter - Mission Pet Health

    Remote · USA Full-time

    [Remote] Sales Account Manager

    Remote · USA Full-time

    [Remote] Risk Control Consultant (SRT)

    Remote · USA Full-time

    [Remote] Product Management Analyst

    Remote · USA Full-time

    [Remote] Senior Sap Finance Control Principal Consultant

    Remote · USA Full-time

    [Remote] Legal Accounts Receivable Collections Specialist

    Remote · USA Full-time

    [Remote] Senior Cloud & Systems Engineer

    Remote · USA Full-time

    [Remote] Sap Materials Management Principal Consultant

    Remote · USA Full-time

    [Remote] Cloud Contact Center Engineer - Webex ( 6 Month Contract)

    Remote · USA Full-time

    [Remote] Capital Markets Associate, Structured Finance

    Remote · USA Full-time

    Electrical Engineer (Multiple Positions)

    Remote · USA Full-time

    Director, Portfolio Finance

    Remote · USA Full-time

    Need (USA) Food and Consumables Coach (Complex) - WM, Management in Morrow, GA

    Remote · USA Full-time

    Consumer Engagement Manager

    Remote · USA Full-time

    Senior Clinical Systems Specialist(IRT)

    Remote · USA Full-time

    Program Manager - eMoney

    Remote · USA Full-time

    Experienced Full Stack Customer Service Representative – Amazon Account Support

    Remote · USA Full-time

    Senior Engineering Manager - Cloud Infrastructure team

    Remote · USA Full-time

    Director of Business Development – Foodservice & On-Premise – Coca-Cola North America Operating Unit

    Remote · USA Full-time

    Academic Advising Specialist, CID/CBE Student Support Services

    Remote · USA Full-time