At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good.
Your impact
We are looking for a mid-level Software Security Analyst to join our security engineering team. In this role, you will be the primary point of contact for application security scanning — running static and dynamic analysis against codebases across the organization and working hands-on with developers to understand, prioritize, and remediate the vulnerabilities you find. This is a technical, team-oriented role for someone who is equally comfortable reading code and explaining security risks in plain language.
Conduct static application security testing (SAST), dynamic testing (DAST), and software composition analysis (SCA) across development teams using Qualys and related tooling
Triage, analyze, and validate scan findings,
filtering false positives and prioritizing issues by exploitability and business impact
Partner directly with software engineers to walk through vulnerabilities, explain root causes, and guide remediation — not just hand off a report
Develop and maintain remediation documentation, secure coding guidance, and knowledge base articles for common vulnerability classes
Track open findings through to closure in ServiceNow, following up with development teams to ensure timely resolution
Integrate security scanning into CI/CD pipelines and work with DevOps teams to shift security testing left
Assist in defining security acceptance criteria and contributing to secure design reviews for new features and systems
Support periodic penetration testing engagements and red team exercises as needed
Contribute to security metrics and reporting for leadership on vulnerability trends and remediation velocity