International Monetary Fund

Associate Security Analyst (Application Security) Contractual -ITDSGGR

Postuler sur le site officiel
Lieu d'affectation
🇺🇸 United States
Pays / zone
United States
Région
Americas
Système ONU
Specialized Agency
Title
Associate Security Analyst (Application Security) Contractual -ITDSGGR
Organization
International Monetary Fund
Department
ITDPVPM Information Technology Department Project and Vendor Management Project Portfolio Management Section
Hiring For
A09, A10
Appointment Duration
one-year contractual appointment
Contract Renewal
renewable for up to four years of cumulative contractual service
Publiée
7/21/2026, 12:00:00 AM
Clôture
8/5/2026, 12:00:00 AM

À propos de ce poste

The Associate Security Analyst (Application Security) role supports the integration of security throughout the Software Development Lifecycle (SDLC). The incumbent collaborates with development, infrastructure, and application teams to facilitate vulnerability remediation, application security initiatives, and secure development practices. Key responsibilities include promoting secure coding standards, integrating security tools (SAST, DAST, SCA) into CI/CD pipelines, and participating in threat modeling under senior guidance. The role involves reviewing security testing results, supporting remediation for on-premises and cloud applications, and tracking vulnerability closure. Additionally, the analyst supports security awareness training and stays current with emerging threats. The ideal candidate possesses foundational application security knowledge combined with strong coordination, communication, and stakeholder engagement skills to maintain enterprise application security posture and drive continuous process improvement.

Exigences clés

  • 6+ years in AppSec/Vuln Mgmt OR advanced degree
  • Experience with OWASP Top 10 or NIST
  • Knowledge of secure architecture principles

Atouts appréciés

  • SSCP, Security+, or CISSP certification
  • Experience with ServiceNow or Azure DevOps
  • Microsoft Azure cloud technology experience

Exigences en un coup d'œil

Expérience min.
Minimum of six (6) years of relevant professional experience in Vulnerability Management, Application Security, Secure Development or related cybersecurity disciplines; OR an advanced university degree in Computer Science, Cybersecurity, or a related field.
Diplôme requis
Completion of an advanced university degree, or equivalent, in Computer Science, Cybersecurity, or a related field; OR a university degree, or equivalent, supplemented by a minimum of six (6) years of relevant professional experience.

Work for the IMF. Work for the World.

The Associate Security Analyst (Application Security) supports the integration of security throughout the Software Development Lifecycle (SDLC) by collaborating with development, infrastructure, and application teams to support vulnerability remediation efforts, application security initiatives, and secure development practices. The successful candidate combines foundational application security knowledge with strong coordination, communication, and stakeholder engagement skills to help maintain the security posture of enterprise applications while supporting continuous process improvement.

Major Duties and Responsibilities

Application Security & Secure SDLC

  • Collaborate with technical teams to promote secure coding practices and support the implementation of Secure SDLC standards, including security requirements for application design and development.
  • Assist in integrating application security tools, such as SAST, DAST, and SCA into CI/CD pipelines, and participate in threat modeling and security design reviews under the guidance of senior engineers.

Vulnerability Management & Security Controls

  • Review security testing results and support remediation efforts for identified vulnerabilities.
  • Help implement security controls for applications deployed in both on-premises and cloud environments.
  • Assist in tracking vulnerability remediation activities and supporting the timely closure of identified findings in collaboration with application and engineering teams.

Security Awareness & Continuous Improvement

  • Support training efforts and knowledge sharing on secure development practices within engineering teams.
  • Stay current with emerging security threats, vulnerabilities, and industry best practices to provide application security guidance to technical teams.

Minimum Qualifications

  • Educational development, typically acquired by the completion of an advanced university degree, or equivalent, in Computer Science, Cybersecurity, or a related field; or a university degree, or equivalent, supplemented by a minimum of six (6) years of relevant professional experience;
  • Experience in Vulnerability Management, Application Security, Secure Development or related cybersecurity disciplines.
  • Familiarity with security frameworks and standards such as OWASP Top 10, NIST and secure development practices.
  • Experience with one or more programming or scripting languages (e.g., Java, Python, .NET)
  • Understanding of secure architecture principles for web-based and cloud-based applications.
  • Exposure to security testing methodologies and tools, including static analysis, dynamic analysis, vulnerability scanning, and penetration testing.
  • Experience supporting cross-functional initiatives involving multiple stakeholders, technical teams, and business partners.
  • Strong communication, project coordination, organizational, analytical, and collaboration skills, with the ability to manage multiple priorities and track deliverables effectively.

Preferred Qualifications

  • Certifications, such SSCP, Security+, or working toward CISSP or similar.
  • Experience with ServiceNow, Azure DevOps, and Microsoft Azure cloud technologies.
  • Experience using Power BI and AI-enabled tools to support reporting, analytics, and operational efficiency.

This is a one-year contractual appointment. Contractual appointments at the IMF are renewable for up to four years of cumulative contractual service, pending incumbent's performance, budget availability, and continuous business need.

Department:

ITDPVPM Information Technology Department Project and Vendor Management Project Portfolio Management Section

Hiring For:

A09, A10

The IMF is guided by the principle that the employment, classification, promotion, and assignment of staff shall be made without discrimination against any person. We welcome requests for reasonable accommodations for disabilities during the selection process. Information on how to request accommodations will be provided during the application process.

Pourquoi ce poste pourrait vous convenir

L’AI Match de UNlockit évalue chaque poste ouvert dans le système ONU par rapport à votre CV selon quatre axes — similarité sémantique, recoupement de mots-clés, recoupement de compétences et recoupement de domaine — et identifie les exigences indispensables ainsi que les éventuelles lacunes. Connectez-vous et téléchargez un CV pour voir le verdict personnalisé pour cette offre.

Voir mon adéquation pour ce poste