Long Beach, CA

Salary
$108,000–$140,000from the description
Posted
Jun 28, 2026
Location
Long Beach, CA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

An early-career application security role embedded within software development teams, focused on integrating security tooling — such as SAST, DAST, and SCA — into CI/CD pipelines, triaging vulnerability findings, supporting code and design reviews, and helping developers adopt secure coding practices. The position suits someone with a background in software engineering or application security who has foundational knowledge of web security concepts, cloud environments, and DevOps workflows.

Junior level · 1+ years · Los Angeles-Long Beach-Anaheim, CA · Bachelor's required · Full-time

Must have (8)
CI/CDGitAWS, Azure or GCPDockerKubernetesSAST or DastOWASP Top 10Python, JavaScript, C# or Java
Nice to have (1)
Security+ or Ejpt

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 60 people in the Los Angeles-Long Beach-Anaheim, CA area plausibly meet what this posting asks for (information security analysts). range 25–85

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python62%Docker53%CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $129,630 (middle half $94,830–$166,780). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The role is hybrid (3 days in-office in Long Beach, CA; 2 days remote) — not fully remote.

The 1–3 years of experience requirement and 'entry-level' framing place this firmly at the Junior band despite the title carrying no explicit level.

SAST, DAST, and SCA are listed together as interchangeable exposure requirements in the qualifications; they are consolidated into one skill with alternatives. The CI/CD pipeline integration of these tools is a separate, distinct responsibility.

Cloud environment familiarity is listed as 'basic knowledge' of AWS or Azure — treated as a hard gate given its placement in the Essential Qualifications section, with Azure and GCP as alternatives.

Entry-level certifications (Security+, eJPT, or similar) are explicitly called 'a plus' in the qualifications section, so they are marked as preferred.

The programming/scripting language requirement names Python, JavaScript, C#, and Java as interchangeable options; Python is used as the primary with the others as alternatives.

The alt SOC (15-1252 Software Developers) is noted because the role involves integrating security tooling into SDLC/CI/CD and conducting code reviews, giving it a meaningful software-engineering dimension alongside the security analysis work.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗