Summary
EMCOR Group, Inc. is a Fortune 500 company providing mechanical and electrical construction, industrial and energy infrastructure, and building services. The Application Security Analyst will support the company’s Security Program by integrating application security tools into CI/CD pipelines, managing vulnerabilities, supporting security platforms, and partnering with development and IT teams to advance DevSecOps practices.
Responsibilities
- Support and monitor the enterprise information security system as directed by management
- Manage daily operations and support for Application Security products, including incident and ticket resolution
- Provide expertise during incidents, document findings and help improve protocols
- Maintain and upgrade application security related platforms
- Tune application security related policies and rulesets
- Collaborate with business and IT partners to integrate security tools (SAST, DAST, etc.) and platforms into CI/CD pipelines and workloads
- Contribute to and perform security reviews of Terraform configurations and reusable modules supporting EMCOR’s Infrastructure as Code (IaC)
- Validate Terraform changes for security, compliance and alignment with established cloud architecture standards
- Monitor code platforms and resources for security threats, investigate and respond to security incidents and findings
- Write SIEM queries and perform analysis of results
- Respond to security tool findings and collaborate with business and IT partners for remediation
- Implement, configure, manage and support Web Application Firewalls (WAFs), including the tuning of rulesets and policies
- Contribute to various application security related projects and initiatives
- Perform special projects as needed
- Support and maintain EMCOR’s Security Program
Skills
- 3+ years of hands-on experience in an Application Security, Product Security, DevOps or DevSecOps role
- Experience working in cloud platforms (Azure, AWS, GCP, OCI)
- Experience with CI/CD and developer workflow automation such as GitHub Actions, Azure DevOps Pipelines
- Experience developing or reviewing Terraform used to deploy Azure infrastructure, including reusable modules
- Experience managing and tuning Web Application Firewall (WAF) policies, specifically for Azure Front Door
- Experience triaging and remediating vulnerabilities identified by GitHub Advanced Security (GHAS) or Microsoft Defender for Cloud platforms, including CodeQL, Secret Scanning and Dependency Review
- Demonstrated proficiency in using PowerShell for administration and automation purposes
- Proven ability to communicate effectively and interact professionally at all organization levels
- Strong project management capabilities
- Ability to consistently deliver an exceptional standard of customer service
Qualifications
Must Haves
- 3+ years of hands-on experience in an Application Security, Product Security, DevOps or DevSecOps role
- Experience working in cloud platforms (Azure, AWS, GCP, OCI)
- Experience with CI/CD and developer workflow automation such as GitHub Actions, Azure DevOps Pipelines
- Experience developing or reviewing Terraform used to deploy Azure infrastructure, including reusable modules
- Experience managing and tuning Web Application Firewall (WAF) policies, specifically for Azure Front Door
- Experience triaging and remediating vulnerabilities identified by GitHub Advanced Security (GHAS) or Microsoft Defender for Cloud platforms, including CodeQL, Secret Scanning and Dependency Review
- Demonstrated proficiency in using PowerShell for administration and automation purposes
- Proven ability to communicate effectively and interact professionally at all organization levels
- Strong project management capabilities
- Ability to consistently deliver an exceptional standard of customer service
Benefits
- This position is bonus eligible.
- Medical, dental, and vision coverage
- Health savings and flexible spending accounts
- Life insurance
- Disability
- A 401(k) Savings Plan
- College Coach
- Employee assistance program