Principal Application Security Analyst

WPS—A health solutions company•Fitchburg, WI
•$135,000 - $165,000•Hybrid

About The Position

Our Principal Application Security Analyst builds and operates WPS’s enterprise Application Security program, reducing application risk by operationalizing secure-development standards, strengthening developer secure-coding practices, running application-security testing tools, and reporting results to technical, managerial, and executive audiences. They sit within our Cyber Threat Management team and work in close partnership with Cyber Trust & Architecture, that own enterprise security standards, to translate those standards into practical developer guidance and testing criteria. This Senior Analyst is an individual-contributor position requires technical depth and will provide organizational influence to work independently with developers, interpret application security findings, and communicate risk at multiple levels of the organization. Success in this role will strengthen the security of WPS applications throughout the SDLC. This Principal Analyst manages day-to-day application-security testing, triage, and developer engagement independently, while partnering with Cyber Trust & Architecture on standards interpretation and with the Manager, Cyber Threat Management on program priorities.

Requirements

  • U.S. Citizenship is required for this position due to Department of Defense restrictions.
  • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Systems, or a related field or equivalent combination of education and relevant work experience.
  • 5 or more years of progressive experience in application security, software security, DevSecOps, or a related technical security discipline.
  • Hands-on experience with application-security testing technologies (SAST and DAST), the ability to tune tools and independently validate findings, and experience translating cybersecurity standards and technical requirements into practical developer guidance and secure-coding training.
  • Proficient knowledge of common application vulnerabilities and attack techniques, that could include: Authentication / Authorization, Injection, Session management, API security, Insecure dependencies, etc.
  • Knowledge of modern software-development methodologies, CI/CD pipelines, APIs, and cloud-based application environments, sufficient to integrate security testing into the development lifecycle.
  • Excellent analytical skills in distinguishing exploitable vulnerabilities from false positives and prioritizing remediation based on actual risk.
  • Strong communication, problem solving, and decision-making skills.
  • Wired (ethernet cable) internet connection from your router to your computer.
  • High speed cable or fiber internet connection.
  • Minimum of 10 Mbps downstream and at least 1 Mbps upstream internet connection.

Nice To Haves

  • Knowledge of OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and MITRE ATT&CK.
  • Professional certification such as CSSLP, GWAPT, GWEB, or OSWE.

Responsibilities

  • Operate, tune, and continuously improve enterprise application-security testing capabilities (SAST, DAST, SCA, API and secrets scanning), distinguishing exploitable weaknesses from false positives and integrating testing into the development and CI/CD lifecycle.
  • Partner with Cyber Trust & Architecture to translate enterprise application-security standards and secure-by-design requirements into practical developer guidance, testing criteria, and implementation practices across the software-development lifecycle.
  • Build and deliver a developer-focused secure-coding education program, using real vulnerability trends and hands-on guidance to strengthen developers’ ability to meet enterprise security standards.
  • Develop and maintain technical, managerial, and executive reporting that translates application-security findings, vulnerability trends, and standards adoption into actionable, risk-based information.
  • Coordinate the remediation of application vulnerabilities with developers and system owners, prioritizing based on actual exploitability and business risk, and validating fixes through retesting.
  • Apply current threat intelligence and attacker techniques to application-security testing and priorities, partnering with Cyber Trust & Architecture, Cyber Risk & Assurance, and development teams to strengthen security outcomes.

Benefits

  • Remote and hybrid work options available
  • Performance bonus and/or merit increase opportunities
  • 401(k) with a 100% match for the first 3% of your salary and a 50% match for the next 2% of your salary (100% vested immediately)
  • Competitive paid time off
  • Health insurance, dental insurance, and telehealth services start DAY 1
  • Professional and Leadership Development Programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service