At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good.
Your impact
We are looking for a mid-level Software Security Analyst to join our security engineering team. In this role, you will be the primary point of contact for application security scanning — running static and dynamic analysis against codebases across the organization and working hands-on with developers to understand, prioritize, and remediate the vulnerabilities you find. This is a technical, collaborative role for someone who is equally comfortable reading code and explaining security risks in plain language.
• Conduct static application security testing (SAST), dynamic testing (DAST), and software composition analysis (SCA) across development teams using Qualys and related tooling
• Triage, analyze, and validate scan findings,
filtering false positives and prioritizing issues by exploitability and business impact
• Partner directly with software engineers to walk through vulnerabilities, explain root causes, and guide remediation — not just hand off a report
• Develop and maintain remediation documentation, secure coding guidance, and knowledge base articles for common vulnerability classes
• Track open findings through to closure in ServiceNow, following up with development teams to ensure timely resolution
• Integrate security scanning into CI/CD pipelines and work with DevOps teams to shift security testing left
• Assist in defining security acceptance criteria and contributing to secure design reviews for current features and systems
• Support periodic penetration testing engagements and red team exercises as needed
• Contribute to security metrics and reporting for leadership on vulnerability trends and remediation velocity