AI Summary

The analyst ensures the security of internal and third-party applications by reviewing security architecture and overseeing the security posture of cloud and AI solutions. They assess security test reports and collaborate with DevSecOps and development teams to mitigate risks and implement remediation measures.

At DHL, our people are our greatest asset! Everyone’s contribution drives us to be the world's #1 logistics company.

Certified as a Great Place to Work, we're dedicated to fostering a positive, collaborative, and supportive environment for all. Our commitment and engagement with Our People ensure we continuously build a workplace we're all proud of. Plus, with competitive compensation and exceptional perks, we make sure your personal life shines just as brightly as your career.

SUMMARY:
The Application Security Analyst is responsible for ensuring the security of homegrown and 3rd party applications. The role emphasizes analytical and advisory responsibilities rather than hands-on implementation, supporting secure architecture practices, overseeing the security posture of applications (including cloud and AI solutions), and providing transparency to IT management through status reporting and risk insights.
The Application Security Analyst assesses and advises on security architecture and configuration of systems, applications and infrastructure. The role also collaborates with the DevSecOps team on state-of-the-art procedures. The position also independently assesses the results of security test reports like static code analysis, dynamic application analysis and penetration testing and supports development teams with the mitigation of findings.
This position works within a fast paced, agile environment collaborating with business and technology teams across the Americas region to implement and support next generation security solutions.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Review and advice on security architecture of systems, applications and infrastructure throughout the lifecycle in classic and cloud environments.
  • Document and improve security and DevSecOps procedures and documentation requirements.
  • Assess the results of security test reports incl. static code analysis (SAST) reports, dynamic application analysis (DAST) reports and penetration testing reports with a focus on OWASP Top 10.
  • Document test results and remaining risks in GRC tool. Present them to Director IT Security and management. 
  • Amalgamate industry best practices and organization specifics into security solutions.
  • Assist developers with the identification, understanding and implementation of remediation measures.
  • Support the creation of application security concepts and perform security reviews.
  • Assist in review and security assessments of AI solutions and their security guardrails and compliance.
  • Support security audits and security testing.
  • Support risk management process and vulnerability management process.

REQUIREMENTS/SKILLS:

  • Knowledge of OWASP Top 10 and ASVS frameworks including best practice implementations.
  • Experience with cloud security and AI security standards (e.g. ISO 27017, CSA CCM, NIST AI RMF, ISO 42001) and best practices.
  • Ability to interpret different coding languages incl. python, Java, ReAct and JavaScript as well as further widespread languages. 
  • Excellent organizational and analytical skills.
  • Must be able to analyze data, draw conclusions, interpret results, and make recommendations with respect to various IT systems.
  • Ability to communicate effectively with all levels of management.
  • Ability to work effectively in a global environment, including awareness of and sensitivity to cultural differences.
  • Ability to produce high quality work under pressure or tight deadlines.
  • Good written, oral, and interpersonal communication skills.
  • Strong Microsoft Office skills (Word, Excel, PowerPoint).
  • Strong attention to detail.
  • Ability to multi-task.

EDUCATION/EXPERIENCE:

  • Bachelor’s degree in information technology, or related field of study preferred.
  • 3+ years of experience required in application security, DevSecOps or security architecture.
  • Experience with best practices and tools in API security, container security, modern identity frameworks and supply chain security
  • Knowledge of most common SAST, DAST and penetration testing tools and procedures.
  • Experience with CVSS, risk management and GRC tools.
  • Experience and knowledge of Microsoft Office (Word, Excel, PowerPoint).
  • Process automation experience preferred.
  • Experience working with a global organization and/or interacting with colleagues in foreign jurisdictions.
  • Security certifications such as CISSP, CISA, CEH, OSCP or CCSP are preferred.

PHYSICAL DEMANDS:

  • Available for on-call support as required.
  • Travel to remote sites as required (< 20%).
  • Regular sitting at workstation for 25 – 75% of the work shift.
  • Frequent standing and walking.
     

As a leading logistics company in one of the fastest growing industries, at DHL eCommerce, we offer our employees, and their dependents benefits and incentives to make them successful at work and home.

  • Competitive Pay
  • Bonus Programs
  • Retirement Savings - 401k with company match
  • Medical, Dental, Vision, Well-being programs
  • FSA/HSA availability
  • Tuition Reimbursement
  • Paid Time Off including vacation and sick time
  • Company Paid Holidays and Floating Holidays
  • Paid Parental Leave
  • Employee Discount Program
  • Employee Assistance & Work Life Program
  • Short Term and Long-Term Disability
  • Life Insurance

Annual Salary listed below.

$63,300-$84,400=AL, AR, AZ, ID, IN, ME, MO, MS, NE, NH, NM, OH, OK, SC, TN, WV
$69,525-$92,700=CO, CT, DC, FL, GA, IA, KS, KY, MI, MN, NC, NV, OR, PA, TX, UT, VA, WI
$72,750-$97,000=DE, IL, MD, RI, WA
$75,825-$101,100=CA, MA, NJ, NY

We are committed to equal opportunity and reject any forms of discrimination. The basis for employee selection at DHL Group is qualification, performance, skills and experience.

Equal Opportunity Employer - Veterans/Disability
 

Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Security Analyst

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified