Federal Vulnerability Mgmt & App Security Engineer (US Citizen
Listed on 2026-08-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description
Title: Vulnerability Mgmt. and Application Security Manager
Location: Remote-US
Salary: $125K annually
About PSIWe are PSI Services. We power world leading tests. Delivered with trusted science and the very best test taker experience. PSI supports test-takers on their journey to pursuing dreams and gaining certifications that are important to them. They believe that their dreams are worth working for; that their dreams are worth the effort. And we believe that too. This is our core purpose, to empower people to achieve their dreams.
We do this by being the best provider of workforce solutions, which foster both technology and science to deliver the best solutions for our test takers.
We are searching for top talent to join our PSI team and help grow our products and services. We have a creative, supportive and inclusive culture where we empower people in their careers to be their authentic self and make the most of their great talent.
At PSI, we are committed to helping people meet their potential and we believe that promoting diversity, equity and inclusion is critical to our success. That’s why you’ll find these ideals are intrinsic to our company culture and applied throughout the employee lifecycle.
Learn more about what we do at:
The Threat, Vulnerability & Application Security Analyst is a dual‑focus security practitioner responsible for identifying, assessing, and reducing risk across infrastructure, cloud, and application environments. This role combines enterprise threat and vulnerability management with hands‑on application security oversight across the software development lifecycle (SDLC).
The analyst correlates threat intelligence, asset inventory, vulnerability data, and application risk to inform security priorities, guide remediation, and continuously improve the organization’s security posture. A core responsibility is partnering closely with engineering, platform, and product teams to embed security earlier in development, reduce exploitable risk, and ensure compliance with internal security standards and external regulatory requirements.
This role emphasizes automation, scalability, and pragmatism—driving measurable risk reduction through tooling, process improvements, and actionable security guidance. Success requires persistence, strong technical depth across App Sec and vulnerability domains, and the ability to translate risk into clear, prioritized actions for technical and non-technical stakeholders.
Role ResponsibilitiesDrive continuous improvements in vulnerability management processes and tools by‑leveraging industry‑leading technologies, automation, and data‑driven insights.
Stay current on industry trends, emerging threats and best practices in vulnerability management and‑adapt the program accordingly.
Evaluate and recommend vulnerability management tools and technologies, ensuring the optimal balance of effectiveness and efficiency.
Develop and deliver regular metrics, reports, KPIs and presentations to executive leadership and key stakeholders, communicating the status and effectiveness of the vulnerability management program.
Assist in building a diverse vulnerability management program that covers secure software development lifecycle, patch governance, and application security.
Perform technical threat/risk and vulnerability assessments and manage vulnerabilities throughout their lifecycle.
Provide support and maintain tools required for the vulnerability management program.
Provide consultative support to operational teams on how to fix identified vulnerabilities.
Own and evolve the Application Security program, integrating findings into the broader vulnerability management lifecycle.
Perform and oversee application security assessments, including static (SAST), dynamic (DAST), software composition analysis (SCA), and manual secure code reviews where appropriate.
Partner with development and Dev Ops teams to embed security into the SDLC, including CI/CD pipeline integrations and secure design reviews.
Define and maintain application risk prioritization that considers exploitability, business impact, data sensitivity, and threat context.
Review application…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).