remote

Salary
$75,000–$95,000from the description
Posted
Aug 9, 2026
Location
—
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

An Application Security Analyst role on a small, growing InfoSec team at a health-focused e-commerce company. The position covers the full AppSec lifecycle — vulnerability assessment using SAST/SCA tools, embedding security into CI/CD pipelines (DevSecOps), threat modeling, and securing AI/ML components and APIs. It also carries broader InfoSec responsibilities including compliance readiness (PCI, HIPAA, HITRUST), incident response on-call, and tuning controls such as WAF and EDR.

Mid level · 2+ years · Remote · Full-time

Must have (5)
SCAOWASP Top 10CI/CDPython or Bashcloud security
Nice to have (4)
WAFEDRMDMML frameworks

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 8,000 people nationally plausibly meet what this posting asks for (information security analysts). range 3,400–12,100

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python51%Bash51%CI/CD45%cloud security42%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 13, 2026. It is a model, not a headcount.

Why we read it this way (7)

Python and Bash are both listed in the requirements section as scripting skills; they are presented as interchangeable options ('Python, Bash') so each is captured with the other as an alternative.

WAF, EDR, and MDM appear in the responsibilities narrative (tuning security controls) rather than in a dedicated requirements block, and WAF/API security solutions are also called out explicitly under Preferred Qualifications — treated as preferred.

Cloud security is listed in the requirements section but with no specific cloud platform named; no alternatives are populated because the posting gives no named substitutes.

AI/ML security experience (assessing risks, securing AI APIs, threat models) spans both required responsibilities and preferred qualifications; the concrete preferred items (ML frameworks, AI threat models) are marked preferred while the general AI/ML security work is captured in the overview.

The role is fully remote but restricted to US residents working Eastern Time hours.

Compensation is stated as an annual salary range of $75,000–$95,000 with up to 10% discretionary bonus eligibility.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management, AI threat modeling.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗