DevSecOps / Application Security Analyst
Boost your chances before you apply.
TEKsystems
Charlotte, NC, US
Summary
The analyst will manage application security findings, implement security controls in CI/CD pipelines, and administer GitHub security settings. They will also collaborate with development teams to drive vulnerability remediation and support secure coding initiatives.
Job Description
DevSecOps / Application Security Analyst
Overview
We are building a new DevSecOps and Application Security program and seeking a DevSecOps/Application Security Analyst to help establish security standards across the software development environment.
This role will work directly with security leadership to implement secure CI/CD pipelines, manage application security scanning, drive vulnerability remediation efforts, and partner closely with development teams to strengthen the organization's overall security posture.
This is an excellent opportunity for someone who enjoys building processes from the ground up and wants to have a direct impact on a growing security program.
The DevSecOps/Application Security Analyst will serve as a day-to-day operator of the DevSecOps program, responsible for application security findings management, GitHub security administration, CI/CD security controls, pull request security reviews, repository onboarding, and developer engagement. The role partners closely with security engineering and development teams to keep findings actionable, exceptions tracked, security controls operational, and program metrics current. This individual will also support the Security Champions program and contribute to secure coding initiatives.
Key Responsibilities
Scan Triage & Findings Management (50%)
- Triage daily findings from SAST, DAST, SCA, secret detection, IaC, container security, and repository security tools.
- Validate findings, classify severity, and manage false-positive disposition with documented rationale.
- Review pull requests for security findings and collaborate with developers on remediation strategies.
- Monitor CI/CD security gate results and escalate blocked builds when support or exceptions are required.
- Track and maintain the security exception register.
- Manage the security findings backlog, including:
- Ticket creation
- Prioritization
- Assignment
- SLA tracking
- Remediation validation
- Escalation of overdue items
- Closure verification
- Produce weekly findings summaries and maintain metrics including MTTR, vulnerability aging, backlog health, exception burn-down, false-positive rates, and security coverage.
Repository & Tool Operations (30%)
- Administer GitHub Enterprise security capabilities, including:
- Repository onboarding
- Security baselines
- Organization security settings
- Branch protection policies
- Code scanning
- Secret scanning
- Dependabot
- Repository governance controls
- Configure, maintain, and support GitHub Actions workflows and security-integrated CI/CD pipelines.
- Implement and maintain security gates for:
- SAST
- DAST
- SCA
- Secret scanning
- Container security
- IaC scanning
- Maintain tool configurations, scanning policies, suppression rules, and platform integrations.
- Develop and maintain operational documentation, onboarding procedures, runbooks, and knowledge articles.
Developer Engagement & Reporting (20%)
- Support the Security Champions program.
- Assist with OWASP-aligned secure coding education initiatives.
- Prepare operational and executive-level security reporting.
- Participate in remediation working sessions with development teams.
- Maintain remediation guidance, standards, and knowledge base content.
Required Skills
- DevSecOps
- Application Security
- Information Security
- CI/CD Security
- GitHub Enterprise
- Security Operations
Preferred Experience
- GitHub Advanced Security
- CodeQL
- Dependabot
- Secret Scanning
- Branch Protection Policies
- Repository Governance
- Container Security
- Infrastructure as Code (IaC) Security Scanning
- SAST, DAST, and SCA tools
- Jira, ServiceNow, or Azure DevOps
- Scripting with PowerShell, Python, or Bash
- Experience working directly with software development teams on vulnerability remediation and secure coding practices.
Job Type & Location
This is a Contract to Hire position based out of Charlotte, NC.
Pay and Benefits
The pay range for this position is $40.00 - $45.00/hr.
Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.
Eligibility requirements apply to some benefits and may depend on your job
classification and length of employment. Benefits are subject to change and may be
subject to specific elections, plan, or program terms. If eligible, the benefits
available for this temporary role may include the following:
• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in Charlotte,NC.
Application Deadline
This position is anticipated to close on Sep 25, 2026.
About TEKsystems
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We’re a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We’re strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.
We’re TEKsystems and TEKsystems Global Services. We accelerate business transformation for our customers, so they can capitalize on change and master the momentum of technology. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities.
TEKsystems and TEKsystems Global Services are Allegis Group companies.
Founded
1983
Company size
10,001+ employees
Industry
IT Services and IT Consulting
Org type
Privately Held
Headquarters
Hanover, MD
We’re TEKsystems and TEKsystems Global Services. We accelerate business transformation for our customers, so they can capitalize on change and master the momentum of technology. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities.
TEKsystems and TEKsystems Global Services are Allegis Group companies.
Founded
1983
Company size
10,001+ employees
Industry
IT Services and IT Consulting
Org type
Privately Held
Headquarters
Hanover, MD