DevSecOps / Application Security Analyst

TEKsystems•Charlotte, NC
•$40 - $45•Hybrid

About The Position

We are building a new DevSecOps and Application Security program and seeking a DevSecOps/Application Security Analyst to help establish security standards across the software development environment. This role will work directly with security leadership to implement secure CI/CD pipelines, manage application security scanning, drive vulnerability remediation efforts, and partner closely with development teams to strengthen the organization's overall security posture. This is an excellent opportunity for someone who enjoys building processes from the ground up and wants to have a direct impact on a growing security program. The DevSecOps/Application Security Analyst will serve as a day-to-day operator of the DevSecOps program, responsible for application security findings management, GitHub security administration, CI/CD security controls, pull request security reviews, repository onboarding, and developer engagement. The role partners closely with security engineering and development teams to keep findings actionable, exceptions tracked, security controls operational, and program metrics current. This individual will also support the Security Champions program and contribute to secure coding initiatives.

Requirements

  • DevSecOps
  • Application Security
  • Information Security
  • CI/CD Security
  • GitHub Enterprise
  • Security Operations

Nice To Haves

  • GitHub Advanced Security
  • CodeQL
  • Dependabot
  • Secret Scanning
  • Branch Protection Policies
  • Repository Governance
  • Container Security
  • Infrastructure as Code (IaC) Security Scanning
  • SAST, DAST, and SCA tools
  • Jira, ServiceNow, or Azure DevOps
  • Scripting with PowerShell, Python, or Bash
  • Experience working directly with software development teams on vulnerability remediation and secure coding practices.

Responsibilities

  • Triage daily findings from SAST, DAST, SCA, secret detection, IaC, container security, and repository security tools.
  • Validate findings, classify severity, and manage false-positive disposition with documented rationale.
  • Review pull requests for security findings and collaborate with developers on remediation strategies.
  • Monitor CI/CD security gate results and escalate blocked builds when support or exceptions are required.
  • Track and maintain the security exception register.
  • Manage the security findings backlog, including: Ticket creation, Prioritization, Assignment, SLA tracking, Remediation validation, Escalation of overdue items, Closure verification.
  • Produce weekly findings summaries and maintain metrics including MTTR, vulnerability aging, backlog health, exception burn-down, false-positive rates, and security coverage.
  • Administer GitHub Enterprise security capabilities, including: Repository onboarding, Security baselines, Organization security settings, Branch protection policies, Code scanning, Secret scanning, Dependabot, Repository governance controls.
  • Configure, maintain, and support GitHub Actions workflows and security-integrated CI/CD pipelines.
  • Implement and maintain security gates for: SAST, DAST, SCA, Secret scanning, Container security, IaC scanning.
  • Maintain tool configurations, scanning policies, suppression rules, and platform integrations.
  • Develop and maintain operational documentation, onboarding procedures, runbooks, and knowledge articles.
  • Support the Security Champions program.
  • Assist with OWASP-aligned secure coding education initiatives.
  • Prepare operational and executive-level security reporting.
  • Participate in remediation working sessions with development teams.
  • Maintain remediation guidance, standards, and knowledge base content.

Benefits

  • Medical, dental & vision
  • Critical Illness, Accident, and Hospital
  • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
  • Life Insurance (Voluntary Life & AD&D for the employee and dependents)
  • Short and long-term disability
  • Health Spending Account (HSA)
  • Transportation benefits
  • Employee Assistance Program
  • Time Off/Leave (PTO, Vacation or Sick Leave)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service