Mid-Level Application Security Analyst
Listed on 2026-09-11
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Boeing, we innovate and collaborate to make the world a better place. We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.
This role is at Spirit Aero Systems, Inc. a wholly owned subsidiary of The Boeing Company, supporting Spirit’s Commercial Business Units ("Spirit Commercial"). Spirit Commercial designs and builds commercial aerostructures, including for Boeing Commercial Airplanes, one of Boeing’s three business units and the premier manufacturer of commercial jetliners for decades. Spirit Commercial’s core products include fuselages, pylons, nacelles and wing components, with a focus on innovative composite and aluminum manufacturing solutions.
PositionSummary
The Application Security Analyst III is an experienced cybersecurity professional responsible for advanced application security analysis, risk-based prioritization, remediation coordination, secure development support, reporting, and process improvement. This role works closely with security leadership, application teams, software developers, infrastructure teams, compliance teams, and business stakeholders to reduce enterprise application risk. The analyst provides technical guidance, supports program maturity, and helps ensure application security practices align with organizational risk tolerance, regulatory requirements, secure development practices, and security standards.
PositionResponsibilities
- Lead application security analysis across web applications, APIs, mobile applications, enterprise systems, cloud-based applications, and third‑party solutions.
- Evaluate application security findings based on severity, exploitability, data sensitivity, exposure, business impact, compensating controls, and threat context.
- Develop, coordinate, and validate risk‑based remediation efforts for application teams, developers, vendors, and business stakeholders.
- Support application security metrics, dashboards, executive summaries, and audit evidence.
- Contribute to application security standards, procedures, playbooks, secure development guidance, and continuous improvement efforts.
- Provide guidance and mentorship to junior analysts.
- Minimum 5 years of cybersecurity, application security, software development, vulnerability management, security operations, or related experience.
- Advanced cybersecurity, application security, secure software development, or information security certification.
A relevant degree may qualify in lieu of certification. - Strong knowledge of application security lifecycle processes, including intake, assessment, analysis, prioritization, remediation, validation, and reporting.
- Hand‑on experience administering, engineering or supporting application security platforms.
- Ability to assess risk using vulnerability data, threat context, application criticality, data sensitivity, exposure, and business impact.
- Experience preparing reports, metrics, and recommendations for technical and leadership audiences.
- Strong analytical, communication, and stakeholder management skills.
- Bachelor's degree in cybersecurity, information technology, computer science, software engineering, or a related field.
- Familiarity with NIST guidelines, CIS Controls, ISO 27002, CMMC, and/or other regulatory and security frameworks.
- Experience with secure software development lifecycle practices, application architecture review, cloud application security, API security or third‑party application risk.
- Strong understanding of web applications, APIs, authentication, authorization, secure coding, data protection, application…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).