[8PP] Senior Security Analyst - AI & Application Security
Remote · Costa Rica
Job Summary
Senior Security Analyst – AI & Application Security responsible for leading AppSec testing (SAST/DAST/SCA), coordinating third-party penetration tests, managing vulnerability scanning and remediation, integrating security tooling into CI/CD, conducting security architecture reviews, and overseeing AI governance and tool risk for SaaS/AI integrations. The role emphasizes security operations (threat detection, incident response, threat hunting), proactive risk management aligned with NIST CSF 2.0 and AI governance frameworks, and driving program maturity through process improvements, documentation, and collaboration with Legal and IT for vendor security and compliance. Strong communication, problem-solving, and independent/team collaboration skills are essential, along with cloud security experience (AWS/Azure) and familiarity with security standards (SOC 2 Type II, ISO 27001). Preferred certifications and AI governance experience are a plus.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent work experience
- At least 5 years of experience as a Security Analyst or similar role, with focus on AppSec, security operations, and/or AI security
- Hands-on experience with Qualys for vulnerability scanning, asset management, and remediation tracking
- Proficiency with CrowdStrike platform capabilities including Next-Gen SIEM, Data Protection, CSPM, AIDR, Falcon Shield, and Threat Intelligence
- Experience with Rapid7 or equivalent vulnerability management platform
- Cloud security experience in AWS and/or Azure including IAM, security group configurations, logging, and posture management
- Experience hardening CI/CD pipelines and integrating AppSec tooling into development workflows (SAST/DAST/SCA)
- Experience coordinating penetration tests and managing remediation lifecycle
- Demonstrated ability to implement security process improvements and drive program maturity
- Working knowledge of NIST CSF 2.0 and how to apply framework functions to operational security programs
- Knowledge of security concepts, principles, and best practices, such as threat modeling, risk assessment, encryption, and authentication
- Knowledge of common security vulnerabilities and attack vectors (phishing, ransomware, DDoS, SQL injection)
- Excellent communication, problem-solving, and analytical skills
- Ability to work independently and as part of a team
- Certifications such as CISSP, OSCP, CEH, GCIH, GCFA, CrowdStrike CCFA/CCFH, or AWS Security Specialty are preferred; AI security certifications such as AAISPM are a plus
- Knowledge of AI/ML security considerations and AI governance frameworks including ISO/IEC 42001 and NIST AI RMF 1.0
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.