Cyber Security Analyst III - App Security & Vulnerability (Remote)

First Citizens Bank

Raleigh, North Carolina(remote)

JOB DETAILS
SKILLS
(XSS) Cross Site Scripting, Amazon Web Services (AWS), Analysis Skills, Application Programming Interface (API), Applications Security, Artificial Intelligence (AI), Authentication, Automation, Bash Scripting, Cloud Computing, Communication Skills, CompTIA Security+, Compensation and Benefits, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cross-Functional, Data Management, Data Modeling, Detail Oriented, DevOps, Emerging Technology, Establish Priorities, GCP (Good Clinical Practices), GIAC - Global Information Assurance Certification, GitHub, High School Diploma, ISO (International Organization for Standardization), Information/Data Security (InfoSec), Injections, Internet Security, Java, JavaScript, Jenkins, Machine Tool, Mail Services, Metrics, Microsoft Windows Azure, Problem Solving Skills, Product Lifecycle, Python Programming/Scripting Language, Quality Assurance Methodology, Regulations, Risk, Risk Analysis, Risk Management, SSCP - Systems Security Certified Practitioner, Scripting (Scripting Languages), Secure Coding, Security Analysis, Security Software, Software Development, Software Development Lifecycle (SDLC), Test Automation, Test Scripts, Test Tools, Testing, Threat Modeling, Threat and risk analysis (TRA), Trend Analysis, U.S. National Institute of Standards and Technology (NIST), Vulnerability Scanners
LOCATION
Raleigh, North Carolina
POSTED
4 days ago
Overview:

This is aremote role in NC, AZ, and TX. 

 

We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role focuses on identifying, analyzing, and mitigating security risks across software development pipelines using SAST, DAST, and SCA tools. The ideal candidate combines hands-on technical expertise with knowledge of modern security practices and emerging technologies, including AI/ML.

Responsibilities:

Application Security & Code Analysis

  • Perform static (SAST), dynamic (DAST), and software composition analysis (SCA) to identify vulnerabilities in applications and third-party components
  • Analyze scan results, triage findings, and prioritize remediation efforts based on risk
  • Partner with development teams to remediate vulnerabilities and improve secure coding practices

Vulnerability Management

  • Conduct regular security assessments and vulnerability scans across applications and environments
  • Validate and reproduce vulnerabilities, including false positive elimination
  • Track and report vulnerability metrics, risk trends, and remediation progress

Security Tools & Automation

  • Configure, deploy, and maintain security scanning tools (e.g., Checkmarx, Veracode, Fortify, Snyk, Burp Suite, OWASP ZAP)
  • Automate security testing processes using scripting or APIs
  • Improve scanning efficiency and coverage through tuning and optimization

 

Qualifications:

Bachelor's Degree and 6 years of experience in Information Security OR High School Diploma or GED and 10 years of experience in Information Security

 

Required Qualifications

  • Hands-on experience with:
    • SAST, DAST, and SCA tools
    • Web application security testing (OWASP Top 10, API security)
  • Strong understanding of:
    • Secure software development lifecycle (SDLC / DevSecOps)
    • Common vulnerabilities (e.g., injection, XSS, authentication flaws)
  • Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)
  • Experience interpreting and prioritizing scan results and remediation plans

Preferred Qualifications

  • Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)
  • Familiarity of container and cloud security (AWS, Azure, GCP)
  • Familiarity with AI/ML concepts and security implications
  • Industry certifications such as:
    • CEH, Security+, SSCP, GIAC or comparable.

Key Skills

  • Strong analytical and problem-solving skills
  • Provide risk-based recommendations to stakeholders
  • Ability to communicate technical findings to both technical and non-technical stakeholders
  • Experience working cross-functionally with development and engineering teams
  • Attention to detail with a risk-based security mindset

Nice-to-Have Experience

  • API security testing tools (Postman, SoapUI)
  • AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)
  • Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)
  • AI/ML & Emerging Technologies
    • Leverage AI/ML-based security tools for enhanced detection and analysis
    • Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)
    • Participate in securing AI-driven applications and data pipelines
  • Threat Analysis & Risk Management
    • Assess potential threats and attack vectors relevant to applications and APIs
    • Apply threat modeling techniques (e.g., STRIDE) during development lifecycle

 

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

About the Company

F

First Citizens Bank

First Citizens Bank helps personal, business, commercial and wealth clients build financial strength that lasts. As the largest family-controlled bank in the United States, First Citizens is continuing a unique legacy of strength, stability, and long-term thinking that has spanned generations. Founded in 1898 and headquartered in Raleigh, N.C., First Citizens also operates a nationwide direct bank and a network over 550 branches in 22 states. Industry specialists bring a depth of expertise that helps businesses and individuals meet their specific goals at every stage of their financial journey. First Citizens Bank brings together personal service and powerful tools to help customers do more with their money – and make more of their future.  

Looking for a career with CIT? CIT is now a division of First Citizens Bank.

First Citizens Bank. Forever First®

COMPANY SIZE
10,000 employees or more
INDUSTRY
Banking
EMPLOYEE BENEFITS
Paid Sick Days, Prescription Drug Coverage, Professional Development, 401K, Flexible Spending Accounts, Retirement / Pension Plans, Life Insurance
FOUNDED
1898
WEBSITE
https://www.firstcitizens.com