Application Security Analyst at FSAStore.com
$75,000–$95,000from the description
Aug 9, 2026
—
Sep 24, 2026
What this job asks for AI summary
An Application Security Analyst role on a small, growing InfoSec team at a health-focused e-commerce company. The position covers the full AppSec lifecycle — vulnerability assessment using SAST/SCA tools, embedding security into CI/CD pipelines (DevSecOps), threat modeling, and securing AI/ML components and APIs. It also carries broader InfoSec responsibilities including compliance readiness (PCI, HIPAA, HITRUST), incident response on-call, and tuning controls such as WAF and EDR.
Mid level · 2+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 8,000 people nationally plausibly meet what this posting asks for (information security analysts). range 3,400–12,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 13, 2026. It is a model, not a headcount.
Why we read it this way (7)
Python and Bash are both listed in the requirements section as scripting skills; they are presented as interchangeable options ('Python, Bash') so each is captured with the other as an alternative.
WAF, EDR, and MDM appear in the responsibilities narrative (tuning security controls) rather than in a dedicated requirements block, and WAF/API security solutions are also called out explicitly under Preferred Qualifications — treated as preferred.
Cloud security is listed in the requirements section but with no specific cloud platform named; no alternatives are populated because the posting gives no named substitutes.
AI/ML security experience (assessing risks, securing AI APIs, threat models) spans both required responsibilities and preferred qualifications; the concrete preferred items (ML frameworks, AI threat models) are marked preferred while the general AI/ML security work is captured in the overview.
The role is fully remote but restricted to US residents working Eastern Time hours.
Compensation is stated as an annual salary range of $75,000–$95,000 with up to 10% discretionary bonus eligibility.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management, AI threat modeling.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.