AppSec Analyst
Posted 2025-08-23
Remote, USA
Full Time
Immediate Start
<b>Description</b><br><p><strong>About Us</strong></p><p><strong>Legit Security</strong> is a cybersecurity company offering an enterprise ASPM platform that secures organizations' software supply chains across both on-premises and cloud environments. Our mission is to protect businesses from emerging threats targeting software development processes, ensuring secure software is built from the ground up</p><p><strong>What You’ll Do</strong></p><ul><li>Lead or participate in deep research initiatives around SAST, SCA, secrets exposure, misconfigurations, AI security, and more</li><li>Develop detection rules and security signatures for static code analysis engines</li><li>Analyze code bases, pipelines, and development environments to map and model real-world attack vectors</li><li>Investigate new vulnerabilities, CVEs, and package-related risks</li><li>Collaborate with analysts and researchers to produce actionable security insights and detection logic</li><li>Work closely with engineering teams to transform research into scalable security features</li><li>Balance high-level threat modeling with hands-on technical deep-dives</li></ul><br> <b>Requirements</b><br><p><strong>What you’ll bring</strong></p><ul><li>Proven experience in Application Security / Product Security / Security Research roles</li><li>Strong coding skills – able to read and analyze code confidently (at least in one language such as Python, JavaScript, Go, etc.)</li><li>Hands-on experience with AppSec tools such as SAST/SCA/Secrets Scanners (e.g., CodeQL, Semgrep, TruffleHog, GitGuardian, etc.)</li><li>Deep understanding of common vulnerabilities, secure development practices, and real-world exploit scenarios</li><li>Comfortable switching between technical implementation and broader threat understanding</li><li>Bonus: Experience with bug bounty programs, vulnerability disclosures, or writing security content</li><li>Bonus: Experience using or building AI/ML models in the context of cybersecurity</li></ul><p><strong>Why Join Us?</strong></p><ul><li>Direct impact on a cutting-edge ASPM product used by security teams globally</li><li>A research-driven culture that values depth, accuracy, and creativity</li><li>Opportunities to work across the full spectrum of AppSec – from code to cloud to CI/CD</li><li>A collaborative, highly technical environment with room for growth and innovation</li></ul><br>