Talent.com
Sound Physicians
Application Security AnalystSound Physicians • undefined null, US
Application Security Analyst

Application Security Analyst

Sound Physicians • undefined null, US
30+ days ago
Salary
$75,000.00 yearly
Job type
  • Full-time
Job description

About Sound

Founded in 2001 and headquartered in Nashville, TN, Sound Physicians is a nationally respected, physician-led medical group practicing in 400+ hospitals across 45 states. Our team of 4,000+ clinicians and 1,000+ business professionals across the country is united by one mission: to build exceptional clinical partnerships that unlock quality, affordable, dignified care for everyone – no matter who they are or where they live. With physician-led clinical teams and more than two decades of operational expertise, we’ve refined what it takes to consistently deliver exceptional care in hospital medicine, emergency medicine, critical care, anesthesia, and telemedicine.

Why join us?

  • A remote-first culture that values flexibility and collaboration
  • Opportunities to grow your career while making a real impact
  • A team that champions inclusivity, innovation, and excellence

Whether working virtually or onsite at one of our practices, you’ll be part of a purpose-driven organization shaping the future of healthcare.

Sound Physicians offers a competitive benefits package inclusive of the items below, and more:

  • Medical insurance, Dental insurance, and Vision insurance
  • Health care and dependent care flexible spending account
  • 401(k) retirement savings plan with a company match
  • Paid time off (PTO) begins accruing immediately upon start date at a rate of 15 days per year, in accordance with Sound's PTO policy
  • Ten company-paid holidays per year

About the Role

The Application Security Analyst helps embed security into the software delivery lifecycle by partnering with development, platform, cloud, and security teams to build secure-by-default processes. This role focuses on reducing risk through automation, continuous testing, secure configuration, and practical guidance that enables teams to ship software quickly and safely. The ideal candidate possesses a strong understanding of application security principles, secure coding practices, cloud security controls, vulnerability management, and modern DevSecOps methodologies.

The Details:

  • Participation in the after-hours security incident response and on-call rotation is part of the role.

Essential Duties and Responsibilities

  • Integrate security controls and automated checks into CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secret scanning, container security scanning, and Infrastructure-as-Code (IaC) validation.
  • Partner with developers and platform engineers to identify, prioritize, and remediate application, API, container, and cloud security risks early in the development lifecycle.
  • Perform application security assessments, architecture reviews, and threat modeling exercises for new and existing applications.
  • Support vulnerability management by validating findings, reducing false positives, tracking remediation, and helping define risk-based service-level expectations.
  • Conduct secure code reviews and provide guidance on secure coding practices aligned with OWASP Top 10, CWE, and industry standards.
  • Perform security reviews for application architecture, deployment patterns, third-party components, and cloud configurations.
  • Develop and maintain secure pipeline standards, reusable guardrails, and policy-as-code checks that improve consistency without creating unnecessary delivery friction.
  • Collaborate with engineering, infrastructure, and security operations teams on incident response, root cause analysis, and hardening activities related to software delivery platforms.
  • Create and maintain documentation, standards, playbooks, and training materials related to application security, secure development, and DevSecOps practices.
  • Track vulnerability trends, security metrics, and recurring issues to improve security maturity across build, release, and runtime workflows.
  • Stay current on emerging threats, attack techniques, vulnerabilities, and security technologies relevant to application and cloud security.

Values

  • Collaborative: Demonstrates the ability to work well with others to accomplish a goal and get the work done; takes opinions of others into consideration; includes others in the decision-making process.
  • Eager to Learn: Proactively seeks out information, embraces learning new things and enjoys the learning process.
  • Intellectually curious: Demonstrates a genuine interest in learning new things and wants to know the reason “why” behind the way things are done.
  • Committed: Demonstrates dedication to the job, project, organization, customer/clients and co-workers.
  • Resourceful: Proactive willingness to utilize available information and tools to figure things out.

Knowledge, Skills, and Abilities

  • Strong understanding of application security concepts, secure coding practices, and common attack vectors.
  • Strong understanding of application security concepts, secure coding practices, and common attack vectors.
  • Knowledge of security testing methodologies including SAST, DAST, SCA, penetration testing, secret scanning, and IaC security assessments.
  • Familiarity with cloud platforms such as Azure and AWS.
  • Familiarity with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab CI, or Jenkins.
  • Knowledge of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and NIST Cybersecurity Framework.
  • Experience with application security platforms such as Veracode, Checkmarx, Fortify, SonarQube, Snyk, Mend, Burp Suite, Rapid7 InsightAppSec, or similar tools.
  • Familiarity with scripting and automation using Python, Powershell, Bash, or similar languages.
  • Experience securing containerized applications and platforms (Docker, Kubernetes, OpenShift, AKS, EKS, or GKE), including container image scanning, runtime security monitoring, admission controls, and Kubernetes security best practices.
  • Knowledge of container technologies, source control workflows, and modern software delivery practices.
  • Familiarity with common static and dynamic application security tools.
  • Ability to analyze security findings, assess risk, and communicate remediation recommendations effectively to technical and non-technical stakeholders.
  • Familiarity with AI-assisted development processes and appropriate security controls.
  • Strong written and verbal communication skills.
  • Ability to translate technical issues into clear guidance and action plans
  • Knowledge of cloud-native security controls.
  • Familiarity with Kubernetes, Terraform, and similar Infrastructure-as-Code tools.
  • Familiarity with secrets management, PKI, certificate management, and cryptographic controls.
  • Knowledge of compliance frameworks such as NIST CSF, NIST 800-53, HIPAA, PCI DSS, SOC 2, ISO 27001, and HITRUST.

Education and Experience

  • Bachelor’s degree in Computer Science, Information Security, or related field, with industry-recognized certifications such as CSSLP (Certified Secure Software Lifecycle Professional), GWAPT (GIAC Web Application Penetration Tester), OSWE (Offensive Security Web Expert), CEH (Certified Ethical Hacker)
  • 4+ years of experience in application security, DevOps, cloud security, security engineering, or a related cybersecurity role.
  • Knowledge of scripting and programming languages such as Python, PowerShell, Java, JavaScript, C#, or Go is highly desirable and considered a plus.
  • Experience supporting regulated environments such as healthcare, financial services, or other compliance-driven industries.

Salary Range

  • This position offers an annual salary range of $75,000 to $110,000. Exact salary will depend on the candidate’s experience, education and geographic location.

Sound Physicians is an Equal Employment Opportunity (EEO) employer and is committed to diversity, equity, and inclusion at the bedside and in our workforce. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, gender identity, sexual orientation, age, marital status, veteran status, disability status, or any other characteristic protected by federal, state, or local laws.

This job description reflects the present requirements of the position. As duties and responsibilities change and develop, the job description will be reviewed and subject to amendment.

Create a job alert for this search

Application Security Analyst • undefined null, US

Similar jobs

Remote Platform Security Engineer: Cloud & App Security

LightbendSan Francisco, CA, United States
Remote
Full-time

A technology company is looking for a hands-on Platform Security Engineer to architect and maintain security solutions.You will work with teams to build secure services, respond to threats, and imp... Show more

 • Promoted

Manager, Enterprise Security

TuroSan Francisco, CA, United States
Full-time

Turo is searching for a highly motivated and strategic Manager, Enterprise Security to lead and mentor a team of Security Engineers in securing enterprise systems and data through the definition, e... Show more

 • Promoted

SR. Financial Analyst - Marketing

Direct Staffing IncRedwood City, CA, United States
Full-time

Senior Financial Analyst - Marketing.Located in Redwood City, CA, the Senior Financial Analyst role reports into the Manager of FP&A and will provide an excellent opportunity to be a collaborative ... Show more

 • Promoted

Enterprise Risk Analyst

True AnomalySan Francisco, CA, United States
Permanent

Denver, CO or Long Beach, CA or Washington, DC or SF Bay Area.True Anomaly seeks those with the talent and ambition to build the technology that secures it.True Anomaly delivers decisive capabiliti... Show more

 • Promoted

Remote Senior Security Engineer -- Cloud & App Security Lead

Doctor On DemandSan Francisco, CA, United States
Remote
Full-time

A leading telehealth provider is seeking a Senior Security Engineer to design and implement security controls across application stacks in cloud environments.This role focuses on AWS security, auto... Show more

 • Promoted

Security Analyst Investigator - Youth Safety or Human Exploitation

Meta PlatformsMenlo Park, CA, United States
Full-time

Security Analyst Investigator - Youth Safety Or Human Exploitation.This is the main content of the job post.It includes the job title and description, formatted in a clean and consistent manner as ... Show more

 • Promoted

Remote Senior Application Security Engineer - Zetachain

ZetachainSan Francisco, CA, United States
Remote
Full-time

Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program.The ideal candidate will be responsibl... Show more

 • Promoted

Security Lead

Credit GenieSan Francisco, CA, United States
Full-time

CompanyCredit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future.We leverage artificial intelligence to provide personalized ins... Show more

 • Promoted

Security Lead

Metro One Loss Prevention Services Group (West Coast), Inc.San Francisco, CA, United States
Full-time

Security Lead Have a passion for service? Ready to build a career, not just find another job? M1 Global has the opportunity youve been looking for! About Us:At M1 Global, we are reshaping the secur... Show more

 • Promoted

Senior Security Engineer (Detection & Response)

ScribdSan Francisco, CA, United States
Full-time

Senior Security Engineer Focused on Detection & ResponseThe Infrastructure Security team at Scribd is responsible for protecting our applications, platforms, and users through proactive, engine... Show more

 • Promoted

Senior Compliance Analyst, Enterprise Compliance Office

MolocoMenlo Park, CA, United States
Full-time

Senior Compliance Analyst, Enterprise Compliance Office.Menlo Park, California, United States.The Senior Compliance Analyst within the Enterprise Compliance Office (ECO) supports the build-out and ... Show more

 • Promoted

Applications Analyst III - PACS, Full Time, Hybrid

Alameda Health SystemOakland, CA, United States
Full-time

SummarySummary:Implements and supports assigned applications from both the application-user and technical perspectives; provides application support for their assigned application, in addition to p... Show more

 • Promoted

Security Lead, Data Centers

FluidStackSan Francisco, CA, United States
Full-time

Security Lead, Data CentersAs the Security Lead, Data Centers, you will lead the design and implementation of physical and logical security frameworks across Fluidstack's distributed data center in... Show more

 • Promoted

Business Analyst

TradeJobsWorkforce94706 Albany, CA, US
Full-time

ESSENTIAL JOB FUNCTIONS Analyzes global markets for IT Services, servers, storage, backup, IT security, productivity software, remote monitoring services, hyperconvergence and IoT.Studies SMB and m... Show more

 • Promoted

Senior Security Analyst (Remote - U.S. only)

Lyra HealthBurlingame, CA, United States
Remote
Full-time

Pay :CompetitiveEmployment type :OtherJob DescriptionReq# :7f551dac-fa5c-40b7-b741-7a49be029aed.Employer is transforming mental health care through technology with a human touch.We work with indust... Show more

 • Promoted

Investment Banking Analyst

AQ Technology PartnersRedwood City, CA, United States
Full-time

AQ Technology Partners is a boutique investment bank focused on the software ecosystem, specializing in M&A and financial sponsor transactions.We are seeking an experienced Investment Banking Analy... Show more

 • Promoted

Application Security Engineer - SF - Hybrid Preferred, Remote O.K.

Unit21, Inc.San Francisco, CA, United States
Remote
Full-time

Application Security Engineer - SF - Hybrid Preferred, Remote O.San Francisco, United States Posted on 09 / 18 / 2025At Unit21, we believe that combating financial crime demands a united front.Thro... Show more

 • Promoted

Security Engineer, Application Security

Glean.infoSan Francisco, CA, United States
Full-time

Security Engineer, Application SecurityGlean is the Work AI platform that helps everyone work smarter with AI.What began as the industry's most advanced enterprise search has evolved into a full-sc... Show more

 • Promoted

Engineering Manager, Application Security

DiscordSan Francisco, CA, United States
Full-time

Discord is used by over 200 million people every month for many different reasons, but there's one thing that nearly everyone does on our platform:play video games.Over 90% of our users play games,... Show more

 • Promoted

Offensive Security Engineer

LiveRampSan Francisco, CA, United States
Full-time

Offensive Security EngineerThe Offensive Security Engineer is responsible for proactively identifying, validating, and helping remediate security weaknesses across the company's SaaS platform, whic... Show more